Daily briefing · September 30, 2026

Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate Attention

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention5 seen before CISA

September 30, 2026 closes with an ATTENTION-level verdict: six vulnerabilities are confirmed under active exploitation, five of which were observed by VulnCheck before any CISA KEV listing — a strong early-warning signal that attackers moved fast. Leading the charge is CVE-2026-76504, a CVSS 9.8 flaw in Cisco Catalyst SD-WAN Manager weaponized on the same day it was disclosed, granting unauthenticated remote attackers full admin-level access. With 594 new CVEs published and 53 rated critical, defenders have a dense patch surface to navigate.

Today’s brief
  • CVE-2026-76504 (Cisco SD-WAN Manager, CVSS 9.8): weaponized day-zero, in CISA KEV — patch or isolate immediately.
  • Five additional CVEs already in active exploitation spotted by VulnCheck before CISA confirmation — the threat is ahead of official alerts.
  • Four CVSS 10.0 flaws published today (kobako, OrdaSoft Joomla CCK, JCTables, SiteSkite) — unauthenticated RCE and SQL injection with PoCs available.
  • Brazil hit by six ransomware groups in recent days across manufacturing, retail, tech, and services sectors.
53
critical
6
Actively exploited
5
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-76504KEVCVSS 9.8PoCsame dayaffects Cisco Catalyst SD-WAN Manager
A CVSS 9.8 authentication bypass in Cisco Catalyst SD-WAN Manager allows unauthenticated remote attackers to gain full admin privileges via malformed URI encoding; confirmed in CISA KEV, observed by VulnCheck independently, and weaponized on disclosure day — this is the top priority patch of the week.
2
CVE-2023-54403◆ VulnCheckHIGH 8.7PoCaffects U8 CRM
An unauthenticated arbitrary file read in Yonyou U8 CRM (via the DontCheckLogin=1 parameter bypass) exposes sensitive configuration files to remote attackers; VulnCheck observed exploitation before CISA listed it, meaning real-world abuse preceded official acknowledgment.
3
CVE-2024-58387◆ VulnCheckHIGH 8.7PoCaffects Haiyue HCM Cloud
Inspur Haiyue HCM Cloud exposes an unauthenticated file-download endpoint (/api/model_report/file/download) to path traversal attacks, allowing attackers to read /etc/passwd and other critical OS files without any credentials; VulnCheck flagged exploitation before CISA.
4
CVE-2023-54402◆ VulnCheckHIGH 8.7PoCaffects iDocView
iDocView's /doc/upload endpoint accepts a hardcoded default token to bypass authentication and then performs unrestricted SSRF — including file:// URI access — enabling unauthenticated attackers to read arbitrary local files; already under active exploitation per VulnCheck ahead of CISA.
5
CVE-2026-102489◆ VulnCheckHIGH 8.7affects Zammad
Zammad versions 6.3.0–6.5.4 carry a session-hijack flaw that escalates to remote code execution as the zammad user; VulnCheck confirmed exploitation in the wild before CISA, making this a high-urgency update for organizations running helpdesk or ticketing workflows on Zammad.
6
CVE-2026-102490◆ VulnCheckHIGH 8.5affects Zammad
A companion privilege-escalation flaw in all Zammad versions allows the local zammad user to reach root, compounding the risk from CVE-2026-102489 into a full system compromise chain; also flagged by VulnCheck prior to CISA listing.
7
CVE-2026-55107CVSS 10affects kobako
The kobako Ruby gem's Wasm-isolated mruby sandbox can be escaped by a crafted guest script in versions 0.1.0 through 0.9.0, granting untrusted code — including LLM-generated scripts and third-party plugins — access to host memory, files, and credentials; CVSS 10.0 with no authentication required.
8
CVE-2026-102427CVSS 10PoCsame dayaffects OrdaSoft Joomla CCK
OrdaSoft Joomla CCK before 8.3.16 exposes a frontend file-upload handler with no authentication or ACL check, and its extension allow-list is bypassable, enabling unauthenticated remote code execution; a PoC was published and weaponized on disclosure day — Joomla site operators should treat this as critical.
9
CVE-2026-76570CVSS 10PoCsame dayaffects JCTables extension for Joomla
JCTables 1.21.1 for Joomla performs zero token validation or authentication on its front-end CRUD API, injecting raw request parameters directly into SQL queries for both read and write operations; CVSS 10.0, weaponized on day zero, making data exfiltration and database manipulation trivially achievable.
10
CVE-2026-96349CVSS 10affects SiteSkite
SiteSkite versions up to 2.1.8 are vulnerable to unauthenticated remote code execution with a CVSS score of 10.0, representing a complete pre-auth takeover risk for any internet-facing installation running an unpatched build.
Ransomware today

Six Brazilian organizations were confirmed as ransomware victims in recent days, spanning manufacturing, retail, professional services, and technology sectors. Engefitas and Pantaneiro Capas were hit by Vexy Ransomware and arcusmedia respectively, while BrainCipher targeted latitudesubro.com, lockbit5 claimed camorim.com.br, m3rx hit somasolucoes.com, and emperador compromised Amazon Informatica. Over the past 30 days, thegentlemen leads activity with seven victims — all in Brazil — followed by lockbit5, Vexy Ransomware, akira, and emperador, confirming that Brazilian organizations remain a primary target across multiple active groups.

Engefitas BRVexy Ransomware · Manufacturing
latitudesubro.com BRBrainCipher · Manufacturing
somasolucoes.com BRm3rx · Professional Services
camorim.com.br BRlockbit5 · Retail & E-Commerce
Amazon Informatica BRemperador · Technology
Pantaneiro Capas BRarcusmedia · Manufacturing
thegentlemen 7lockbit5 4Vexy Ransomware 3akira 3emperador 3BrainCipher 2
Active groups & APTs

Several threat actors and APT groups have been flagged as recently active or updated: ransomhouse, sinobi, spacebears, thegentlemen, funksec, and North Korea-linked APT38. While no specific new victims are attributed to these groups in the current window, their operational status warrants heightened monitoring — APT38 in particular is known for financially motivated intrusions targeting financial and technology sectors globally.

Brazil focus

Brazil continues to absorb disproportionate ransomware pressure, with eight domestic victims identified across the last 30 days including ANP Health in the healthcare sector (thegentlemen) and anery.com.br in agriculture (lockbit5). The concentration of attacks across such diverse sectors — from manufacturing and retail to healthcare and agribusiness — signals that Brazilian organizations of all sizes and verticals are being systematically targeted rather than opportunistically hit.

EngefitasVexy Ransomware · Manufacturing
camorim.com.brlockbit5 · Retail & E-Commerce
somasolucoes.comm3rx · Professional Services
latitudesubro.comBrainCipher · Manufacturing
Amazon Informaticaemperador · Technology
Pantaneiro Capasarcusmedia · Manufacturing
ANP Healththegentlemen · Healthcare
anery.com.brlockbit5 · Agriculture and Food Production
Today’s recommendation: Organizations running Cisco Catalyst SD-WAN Manager must apply the vendor patch immediately or implement network-level access controls to block unauthenticated API access, as CVE-2026-76504 is already being actively exploited with no authentication required. Teams should also audit Zammad deployments, Joomla extensions (OrdaSoft CCK, JCTables), and any use of the kobako Ruby gem as a priority given the concentration of critical, unauthenticated attack vectors published today.
With six vulnerabilities already under active exploitation and five flagged by threat intelligence before official advisories, now is the time to validate whether your own attack surface includes any of these products — because attackers are not waiting for patch cycles.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share