Daily briefing · October 4, 2026

ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

October 4, 2026 brought no active exploitation or weaponized exploits, marking a calm day by threat-intelligence metrics — yet the vulnerability list is dense with critical-severity issues. ZITADEL dominates with four critical authentication and authorization flaws, while AhsayCBS and MindSearch each carry CVSS 10.0 scores demanding prompt attention. Defenders should not mistake the absence of in-the-wild activity for low urgency, as high-CVSS issues without active exploitation can be weaponized quickly.

Today’s brief
  • ZITADEL has four critical vulnerabilities (auth bypass, passkey misuse, IdP account takeover) — patch to 3.4.15/4.17.3 urgently
  • AhsayCBS and MindSearch each score CVSS 10.0 with published exploits — remote code execution risk is real
  • WordPress plugin 'Unlimited Elements for Elementor' carries a blind SQL injection armored on day zero — patch or disable immediately
  • Brazil faces a wave of ransomware hits across government, food production, and technology sectors
16
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-105134CVSS 10affects AhsayCBS
AhsayCBS up to 10.3.2 allows unauthenticated remote OS command injection via the Replication Receiver API endpoint — a CVSS 10.0 flaw with a published exploit, making this a drop-everything patching priority; upgrade to 10.3.4.
2
CVE-2026-105135CVSS 10PoCaffects MindSearch
MindSearch 0.1.0's Planner Agent is vulnerable to remote code injection through unsanitized inputs — CVSS 10.0 with a public proof-of-concept means any internet-exposed instance should be treated as compromised until patched.
3
CVE-2026-103355CVSS 9.3PoCsame dayaffects Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
The 'Unlimited Elements for Elementor' WordPress plugin through 2.0.20 is vulnerable to blind SQL injection and was weaponized on the same day it was disclosed — WordPress administrators should update or deactivate the plugin immediately.
4
CVE-2026-105086CVSS 9.3affects AVideo
AVideo 12.4 through 29.2.0 allows authenticated uploaders to inject stored HTML via doubly-encoded entities in video titles, affecting trending, gallery, embed, and playlist pages — any site accepting untrusted video uploads is at risk.
5
CVE-2026-105089CVSS 9.3affects AVideo
A second stored XSS in AVideo through 29.2.0 lets users with upload permission inject JavaScript via a malicious trailer URL, breaking out of onclick or iframe attributes — the attack surface is broad across YouPHPFlix2 templates and channel playlists.
6
CVE-2026-105215CVSS 9.3affects zitadel
ZITADEL before 3.4.14 and 4.x before 4.16.2 allows unauthenticated attackers to pre-create accounts bound to a victim's external IdP identity by forging unvalidated registration fields — this effectively enables account pre-hijacking before the victim ever logs in.
7
CVE-2026-105209CVSS 9.3affects zitadel
ZITADEL 3.x and 4.x before their respective patches allow a user-write privileged attacker in one organization to obtain a passkey enrollment code for a user in a different organization on the same instance, enabling cross-tenant account takeover.
8
CVE-2026-105207CVSS 9.3affects zitadel
ZITADEL links external IdP identities to user accounts without verifying the caller's identity or a primary factor — an unauthenticated attacker who knows a victim's login name can bind their own IdP to the victim's account across multiple vulnerable versions.
9
CVE-2026-105293CVSS 9.2affects Legcord
Legcord 1.1.0–1.3.0's theme IPC handlers fail to validate theme IDs, allowing script running in the Discord page (e.g., via XSS) to traverse paths, launch local executables, delete directories, or write arbitrary files on the host system.
10
CVE-2026-105211CVSS 9.2affects zitadel
ZITADEL before 4.17.1 exposes OTP codes (Email and SMS) in server-action responses via the returnCode delivery type, letting an unauthenticated attacker who knows a victim's login name bypass MFA and take over accounts, including administrator accounts.
Ransomware today

Several Brazilian organizations were recently listed as ransomware victims across diverse sectors: Softruck (Technology) was claimed by direwolf, Paessolucoes by Panzer, Jampac Alimentos (Agriculture and Food Production) by akira, and FUNAP — Fundação Prof. Dr. Manoel Pedro Pimentel, a government entity — by Booba Project, with Terca attributed to ransomhouse. Looking at the past 30 days, thegentlemen, lockbit5, and akira are the most active groups, each with a heavy focus on Brazilian targets.

Softruck BRdirewolf · Technology
Paessolucoes BRPanzer · Other
Jampac Alimentos BRakira · Agriculture and Food Production
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" BRBooba Project · Government & Defense
Terca BRransomhouse · Other
thegentlemen 7lockbit5 4akira 4emperador 3Vexy Ransomware 2Panzer 2
Active groups & APTs

Several threat actor groups are currently being tracked as active or updated, including funksec, handala, linkc, mosesstaff (Iran-linked), spacebears, and apt73 — none have newly confirmed victims in this reporting cycle, but their operational readiness warrants continued monitoring.

Brazil focus

Brazil continues to be disproportionately targeted by ransomware in recent weeks, with victims spanning government and defense (FUNAP), food production (Jampac Alimentos), technology (Softruck), manufacturing (Engefitas, latitudesubro.com), and professional services (somasolucoes.com). Groups such as thegentlemen, akira, BrainCipher, and Vexy Ransomware have all claimed Brazilian victims in the last 30 days, underscoring the broad sectoral exposure of Brazilian organizations to extortion campaigns.

Softruckdirewolf · Technology
PaessolucoesPanzer · Other
Jampac Alimentosakira · Agriculture and Food Production
Tercaransomhouse · Other
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel"Booba Project · Government & Defense
EngefitasVexy Ransomware · Manufacturing
somasolucoes.comm3rx · Professional Services
latitudesubro.comBrainCipher · Manufacturing
Today’s recommendation: Prioritize patching ZITADEL across all affected versions (3.x and 4.x) and update AhsayCBS to 10.3.4 and MindSearch immediately; also deactivate or update the Unlimited Elements for Elementor plugin given its same-day weaponization. Review IdP linkage configurations and MFA delivery settings in identity platforms as a systemic hardening measure.
Even on a calm day with no confirmed active exploitation, the density of critical authentication and injection flaws published today makes it essential to continuously validate which of these vulnerable components are actually reachable within your own environment.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
October 5, 2026 — Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source ToolsOctober 4, 2026 — ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy DayOctober 3, 2026 — WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy DayOctober 2, 2026 — Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert DayOctober 1, 2026 — FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 BulletinSeptember 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flawsview full archive →
Share