Daily briefing · October 2, 2026

Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention3 seen before CISA

October 2 brings an ATTENTION-level day: three vulnerabilities were flagged by VulnCheck ahead of any official CISA confirmation, signaling active exploitation already underway in the wild before the broader community had time to react. While no new KEV entries were recorded for the day, the combination of two perfect CVSS 10.0 flaws, multiple weaponized-on-day-zero WordPress plugins, and a GitLab AI Gateway sandbox escape demands immediate triage. Defenders should treat VulnCheck-observed CVEs as de facto actively exploited until proven otherwise.

Today’s brief
  • VulnCheck detected exploitation of CVE-2023-54405 (H3C CVM file upload), CVE-2020-37278 (Weaver e-Bridge file read), and CVE-2014-125130 (WordPress MP3 plugin path traversal) before CISA could confirm them — treat all three as actively exploited.
  • Two CVSS 10.0 flaws published today: unauthenticated super-admin takeover in Loom for AWS (CVE-2026-103956) and a stack overflow in Tenda HG7/9/10 routers (CVE-2026-104610) with a public PoC.
  • CVE-2026-94541 and CVE-2026-14378, both WordPress plugin authentication bypasses, were weaponized on the same day they were disclosed — patch WordPress environments immediately.
  • Brazil is under heavy ransomware pressure: eight organizations claimed in recent days across manufacturing, food production, retail, government, and professional services.
30
critical
3
Actively exploited
3
Before CISA
0
Weaponized
Critical highlights
1
CVE-2023-54405◆ VulnCheckCVSS 9.3PoCaffects CVM
An unauthenticated arbitrary file upload in H3C CVM's /cas/fileUpload/upload endpoint allows remote code execution via path traversal in the token parameter; VulnCheck observed exploitation before CISA confirmed it, making this effectively an active threat requiring immediate isolation of the management interface.
2
CVE-2020-37278◆ VulnCheckHIGH 8.7affects e-Bridge
Weaver e-Bridge exposes an unauthenticated file-read endpoint that accepts file:// and http(s):// URLs, enabling attackers to exfiltrate /etc/passwd, credential files, and potentially pivot further; VulnCheck flagged it before CISA, indicating real-world exploitation is already occurring.
3
CVE-2014-125130◆ VulnCheckHIGH 8.7PoCaffects CodeArt Google MP3 Audio Player
This decade-old WordPress plugin flaw (Google MP3 Audio Player ≤1.0.11) allows unauthenticated path-traversal to download wp-config.php and other sensitive files; VulnCheck's pre-CISA detection means it is being exploited now, not just in theory — remove or update the plugin immediately.
4
CVE-2026-103956CVSS 10affects loom
A missing authentication check in Loom for AWS before 1.6.1 lets any unauthenticated remote actor seize super-admin control over the agent control plane, including registering tool servers, reading stored credentials, and rewriting IAM role policies — a CVSS 10.0 catastrophic blast radius in cloud environments where no admin account was set up.
5
CVE-2026-104610CVSS 10PoCaffects HG10
A stack-based buffer overflow in the Boa web server on Tenda HG7, HG9, and HG10 routers is remotely exploitable and has a publicly disclosed exploit; CVSS 10.0 and an already-public PoC make this an urgent patching priority for any deployment of these devices.
6
CVE-2026-93698CVSS 9.9affects cPanel
Insufficient validation in cPanel's Multilang adminbin allows arbitrary command execution by remote attackers; at CVSS 9.9, any cPanel-hosting environment is at high risk and should apply the vendor patch or restrict adminbin access immediately.
7
CVE-2026-90970CVSS 9.9affects GitLab AI Gateway
An authenticated GitLab AI Gateway user with Duo Agent Platform access can escape the prompt-template sandbox via a crafted flow configuration to execute arbitrary commands on affected versions; upgrade to 19.2.4, 19.3.2, or 19.4.1 to close this CVSS 9.9 exposure.
8
CVE-2026-97637CVSS 9.8affects JSON API Auth
The JSON API Auth WordPress plugin (≤3.1.2) leaks session cookies through cached responses keyed only on URI, allowing authentication bypass; at CVSS 9.8, any site running this plugin should treat all existing sessions as potentially compromised and update immediately.
9
CVE-2026-94541CVSS 9.8PoCsame dayaffects WPMobile.App – Android and iOS App Builder
WPMobile.App plugin (≤11.82) lets unauthenticated attackers retrieve password-reset URLs for any user including admins due to missing authorization checks; weaponized on the same day it was disclosed, this is a zero-time-to-weapon flaw requiring emergency patching across all affected WordPress installations.
10
CVE-2026-14378CVSS 9.8PoCsame dayaffects DevKit Pro
DevKit Pro plugin (≤2.3.0) trusts an attacker-controlled cookie to identify the privileged user, enabling full administrator account takeover without credentials; also weaponized day-zero, this flaw is a complete authentication bypass that should be remediated before any further business hours.
Ransomware today

Ransomware activity targeting Brazil is strikingly concentrated: eight Brazilian organizations were claimed recently, spanning Jampac Alimentos (Akira), Paessolucoes (Panzer), Terca (RansomHouse), FUNAP – Fundação Prof. Dr. Manoel Pedro Pimentel (Booba Project), Engefitas (Vexy Ransomware), somasolucoes.com (m3rx), camorim.com.br (LockBit 5), and latitudesubro.com (BrainCipher). Over the past 30 days, TheGentlemen leads with seven victims all in Brazil, followed by LockBit 5 and Akira with four each, indicating Brazil is a primary targeting theater across multiple ransomware operations simultaneously.

Jampac Alimentos BRakira · Agriculture and Food Production
Paessolucoes BRPanzer · Other
Terca BRransomhouse · Other
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" BRBooba Project · Government & Defense
Engefitas BRVexy Ransomware · Manufacturing
somasolucoes.com BRm3rx · Professional Services
camorim.com.br BRlockbit5 · Retail & E-Commerce
latitudesubro.com BRBrainCipher · Manufacturing
thegentlemen 7lockbit5 4akira 4Vexy Ransomware 3emperador 3settra 2
Active groups & APTs

Several threat groups are currently active or being tracked: RansomHouse, sinobi, spacebears, TheGentlemen, and funksec are all flagged as active actors, alongside APT38 — a North Korean state-sponsored group with a well-documented history of financially motivated attacks against financial institutions and cryptocurrency infrastructure. The breadth of groups operating concurrently, from cybercriminal ransomware operators to nation-state APTs, underscores an elevated and diverse threat landscape.

Brazil focus

Brazil faces an exceptionally heavy ransomware burden this period, with victims spread across government and defense (FUNAP), manufacturing (Engefitas, latitudesubro.com), food production (Jampac Alimentos), retail and e-commerce (camorim.com.br), and professional services (somasolucoes.com). The involvement of groups such as Booba Project and Vexy Ransomware alongside established names like Akira and LockBit 5 suggests that Brazilian targets are being pursued by both emerging and established ransomware operations, raising the urgency for Brazilian organizations to review their exposure and incident-response readiness.

PaessolucoesPanzer · Other
Jampac Alimentosakira · Agriculture and Food Production
Tercaransomhouse · Other
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel"Booba Project · Government & Defense
EngefitasVexy Ransomware · Manufacturing
camorim.com.brlockbit5 · Retail & E-Commerce
latitudesubro.comBrainCipher · Manufacturing
somasolucoes.comm3rx · Professional Services
Today’s recommendation: Prioritize immediate patching or network isolation for CVE-2023-54405, CVE-2020-37278, and CVE-2026-103956 given active or pre-CISA-confirmed exploitation; for WordPress environments, treat CVE-2026-94541 and CVE-2026-14378 as zero-day-equivalent threats and apply vendor updates or deactivate affected plugins before the next business cycle.
Given the breadth of attack surfaces exposed today — from cloud management planes and routers to a dozen WordPress plugins — now is the moment to validate which of these components are actually reachable in your environment before an attacker does it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
October 5, 2026 — Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source ToolsOctober 4, 2026 — ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy DayOctober 3, 2026 — WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy DayOctober 2, 2026 — Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert DayOctober 1, 2026 — FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 BulletinSeptember 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flawsview full archive →
Share