Daily briefing · October 3, 2026

WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

October 3, 2026 registers as a calm day by the numbers — no active exploitation, no weaponized exploits, no VulnCheck-ahead-of-CISA signals — but the 10 highlighted vulnerabilities span a wide and consequential surface, from NASA spacecraft command infrastructure to widely deployed WordPress plugins. With four critical-severity CVEs published in a single day and several high-severity flaws enabling privilege escalation and SQL injection, the absence of confirmed exploitation should not be read as permission to delay patching. Defenders should treat this as a catch-up window before any of these gaps are discovered and operationalized.

Today’s brief
  • NASA AIT-Core (CVE-2026-105105, CVSS 9.8): unauthenticated attackers can inject spacecraft commands or forge telemetry over the ZeroMQ bus — a critical risk for mission operations.
  • Multiple WordPress plugins carry critical or high flaws allowing arbitrary file deletion, shortcode execution, privilege escalation, and SQL injection with little or no authentication required.
  • Bouncy Castle for Java's MLS implementation (CVE-2026-71885) fails to validate X.509 credentials, breaking cryptographic trust in affected messaging deployments.
  • Brazil is under sustained ransomware pressure, with five new victims across government, agriculture, manufacturing, and other sectors confirmed in recent days.
4
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-105105CVSS 9.8affects AIT-Core
A CVSS 9.8 missing-authentication flaw in NASA-AMMOS AIT-Core's ZeroMQ message bus allows any remote, unauthenticated attacker with network access to inject spacecraft commands, forge telemetry, or disrupt the command and telemetry pipeline entirely — an extraordinary risk for mission-critical aerospace environments that must treat this as an emergency patch.
2
CVE-2026-71885CVSS 9.2affects BC-JAVA
Bouncy Castle for Java's MLS implementation stores but never validates the X.509 certificate chain against the LeafNode signature key, meaning a malicious actor could present a fraudulent credential that passes verification — any deployment using this library for MLS-based encrypted messaging should upgrade to 1.86 or later immediately.
3
CVE-2026-87115CVSS 9.1affects VikAppointments Services Booking Calendar
The VikAppointments Services Booking Calendar WordPress plugin (up to 1.2.21) allows unauthenticated attackers to delete arbitrary files on the server; deleting key files such as wp-config.php can force a site into a reinstallation state, enabling full remote code execution — this is effectively an unauthenticated RCE pathway.
4
CVE-2026-92084CVSS 9.1affects Beaver Builder Page Builder – Drag and Drop Website Builder
Beaver Builder (up to 2.11.0.5) permits unauthenticated users to trigger arbitrary shortcode execution due to missing input validation before do_shortcode is called, potentially allowing attackers to run any shortcode registered on the site and escalate impact depending on installed plugins.
5
CVE-2026-92536HIGH 8.8affects Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
ProfilePress (up to 4.17.4) exposes sensitive user data — including email addresses and other profile fields — to authenticated attackers with only subscriber-level access, making it a low-bar information disclosure risk in membership-heavy WordPress environments.
6
CVE-2026-97644HIGH 8.8affects Groundhogg — CRM, Newsletters, and Marketing Automation
Groundhogg's CRM plugin (up to 4.9) allows an authenticated attacker with contact-creation rights to rebind a contact identity to an existing administrator account via the v3 REST API, achieving full privilege escalation — the capability gate is insufficient to block this abuse.
7
CVE-2026-18443HIGH 8.8affects Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Smart Manager for WooCommerce (up to 8.97.0) is vulnerable to SQL injection via the 'access_privileges' parameter, exploitable by authenticated attackers with subscriber-level access — a significant risk for e-commerce stores where database integrity and customer data are on the line.
8
CVE-2026-88783HIGH 8.8PoCaffects Kubio AI Page Builder
Kubio AI Page Builder (before 2.9.3) expands its allowed HTML element set globally rather than restricting it to the editor context, enabling unauthenticated users to store malicious markup that the plugin's own scripts later execute in any visitor's or administrator's browser — a stored XSS with proof-of-concept already available.
9
CVE-2026-96451HIGH 8.8affects Ultimate Member
Ultimate Member (through 2.13.1) contains an authorization bypass via a user-controlled key, allowing privilege escalation — a recurring vulnerability class in this plugin that has drawn attacker interest in the past and should be patched without delay.
10
CVE-2026-105115HIGH 8.8affects OpenAM
OpenAM (before 16.1.3) exposes a legacy JAX-RPC SOAP endpoint that allows unauthenticated remote attackers to instantiate arbitrary classes, which can crash the server, probe the classpath, or potentially lead to code execution via deserialization gadget chains — organizations still running OpenAM should treat this as a high-priority remediation.
Ransomware today

Five Brazilian organizations have been confirmed as ransomware victims in recent days, spanning sectors from government to food production: Jampac Alimentos was claimed by Akira, FUNAP (a São Paulo state prison rehabilitation foundation) by the Booba Project group, Engefitas (manufacturing) by Vexy Ransomware, and Paessolucoes and Terca by Panzer and RansomHouse respectively. Looking at the 30-day window, thegentlemen, lockbit5, Akira, Vexy Ransomware, and emperador are the most active groups, with thegentlemen and lockbit5 showing particular concentration of activity in Brazil. The breadth of targeted sectors — government, agriculture, manufacturing, and professional services — signals that Brazilian organizations of all sizes remain high-value targets regardless of industry vertical.

Paessolucoes BRPanzer · Other
Jampac Alimentos BRakira · Agriculture and Food Production
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" BRBooba Project · Government & Defense
Terca BRransomhouse · Other
Engefitas BRVexy Ransomware · Manufacturing
thegentlemen 7lockbit5 4akira 4Vexy Ransomware 3emperador 3settra 2
Active groups & APTs

Several threat groups and APT actors are currently tracked as active or recently updated, including ransomhouse, sinobi, spacebears, thegentlemen, funksec, and North Korea-linked APT38. APT38, historically associated with financially motivated intrusions targeting financial institutions and cryptocurrency platforms, warrants close monitoring given its technical sophistication and the ongoing geopolitical context surrounding North Korean cyber operations. The presence of multiple active ransomware-as-a-service operators alongside nation-state actors in the current threat landscape underscores the layered nature of risk that defenders must account for simultaneously.

Brazil focus

Brazil continues to absorb a disproportionate share of ransomware activity relative to regional peers, with at least eight Brazilian victims identified across the past 30 days spanning retail, professional services, manufacturing, government, and agriculture. Recent victims include camorim.com.br (claimed by LockBit 5), somasolucoes.com (m3rx), latitudesubro.com (BrainCipher), and FUNAP — a government-linked foundation — claimed by Booba Project, demonstrating that public-sector and critical-sector entities are not being spared. Organizations operating in Brazil should ensure that patch cycles, backup integrity, and network segmentation controls are current, particularly given the concentration of active groups targeting the region.

Jampac Alimentosakira · Agriculture and Food Production
PaessolucoesPanzer · Other
Tercaransomhouse · Other
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel"Booba Project · Government & Defense
EngefitasVexy Ransomware · Manufacturing
camorim.com.brlockbit5 · Retail & E-Commerce
somasolucoes.comm3rx · Professional Services
latitudesubro.comBrainCipher · Manufacturing
Today’s recommendation: Prioritize patching CVE-2026-105105 in any NASA-AMMOS AIT-Core deployment and CVE-2026-105115 in OpenAM, as both expose unauthenticated remote attack surfaces with high code-execution potential; simultaneously audit all WordPress installations for the plugin versions listed today, as the combination of no-auth file deletion, shortcode execution, and privilege escalation flaws makes an unpatched WordPress stack a compounded risk.
Even on a calm day with no confirmed active exploitation, the real question is whether your own asset inventory would surface these exposures before an attacker does — validating your external and internal attack surface against today's CVEs is the only way to answer that with confidence.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
October 5, 2026 — Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source ToolsOctober 4, 2026 — ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy DayOctober 3, 2026 — WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy DayOctober 2, 2026 — Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert DayOctober 1, 2026 — FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 BulletinSeptember 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flawsview full archive →
Share