Daily briefing · October 5, 2026

Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source Tools

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

October 5, 2026 registers as a calm day in terms of active exploitation, with no vulnerabilities confirmed weaponized or under active attack. Nevertheless, the publication batch for the day is dense with critical-severity flaws spanning embedded networking hardware, AI workflow platforms, and open-source productivity tools — all warranting prompt attention from defenders. The absence of confirmed in-the-wild exploitation should not be mistaken for a low-risk window, as several of these CVEs carry proof-of-concept code or involve trivially exploitable conditions.

Today’s brief
  • No active exploitation (KEV) recorded today, but 23 critical CVEs published — a patch-heavy day for defenders.
  • Totolink routers (A3002MU, X6000R) hit with three CVSS 10.0 flaws including stack overflow, auth bypass, and OS command injection.
  • Langflow and Penpot carry authenticated RCE paths requiring only normal user access — high risk in multi-tenant or SaaS deployments.
  • Brazil remains a ransomware hotspot: at least five organizations hit recently by groups including akira, medusalocker, and direwolf.
23
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-105285CVSS 10PoCaffects A3002MU
A stack-based buffer overflow in Totolink A3002MU's QoS Rule Handler (/boafrm/formIpQoS) allows remote unauthenticated attackers to execute arbitrary code — a proof-of-concept is publicly available, making this immediately actionable for threat actors targeting exposed routers.
2
CVE-2026-105284CVSS 10PoCaffects A3002MU
An improper authorization flaw in Totolink A3002MU's Authentication Check component allows remote attackers to bypass authentication entirely; with a public exploit in circulation, any internet-exposed device running firmware 1.0.0-B20230403.1455 should be considered compromised until patched or isolated.
3
CVE-2026-100103CVSS 10affects P4 (Helix Core)
Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default, granting unauthenticated network attackers the highest application privilege and a potential path to arbitrary code execution on the connected P4 Server — a critical risk for software development pipelines.
4
CVE-2026-105484CVSS 10affects X6000R
OS command injection in TOTOLINK X6000R's firmware upload handler (/cgi-bin/cstecgi.cgi) can be triggered remotely by manipulating the file_name argument, allowing full device compromise without authentication — isolate or replace affected units immediately.
5
CVE-2026-105740CVSS 9.9affects langflow
Any authenticated Langflow user can achieve server-side RCE by adding an MCP server with Stdio transport, as the user-supplied command is passed directly to bash with no validation or sandboxing — organizations running Langflow below 1.9.0 in shared or multi-user environments face a severe lateral movement risk.
6
CVE-2026-105697CVSS 9.9affects langflow
A second Langflow RCE path (pre-1.10.3) allows users with access to MCP server settings to execute arbitrary commands via the command/args fields, wrapped in bash -c with no allowlist — upgrade to 1.10.3 or later and audit MCP server configurations immediately.
7
CVE-2026-105691CVSS 9.9affects penpot
Penpot's SVG exporter (pre-2.18.0) injects attacker-controlled fill-color values into a shell command string, enabling any file editor to trigger OS command execution with the exporter service's privileges — a classic unsanitized input-to-shell pattern that is straightforward to exploit.
8
CVE-2026-105636CVSS 9.9affects plane
Plane's webhook delivery task (pre-1.4.0) follows HTTP redirects without validating the final destination, bypassing the private-address blocklist and enabling Server-Side Request Forgery (SSRF) to internal network resources — a significant risk in cloud-hosted or containerized deployments.
9
CVE-2026-105641CVSS 9.8affects plane
Plane deployments using the AIO or CLI community manifests (pre-1.4.0) ship with fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults, allowing attackers with network access to forge session tokens and fully compromise the application.
10
CVE-2026-105639CVSS 9.8affects plane
Plane's signup flow (pre-1.4.0) creates authenticated user records for any submitted email without ownership verification, and a serializer information leak allows the newly created account to enumerate workspace invitations tied to that email — enabling account pre-hijacking and invitation harvesting.
Ransomware today

Ransomware activity targeting Brazil remains intense: recently confirmed victims include Millensys (Technology, medusalocker), Jampac Alimentos (Agriculture and Food Production, akira — listed twice, indicating confirmed double-posting), Softruck (Technology, direwolf), and Paessolucoes (Other, Panzer). Over the past 30 days, thegentlemen leads activity with 7 attacks, followed by akira (5), lockbit5 (4), and emperador (3) — all with exclusive or heavy focus on Brazilian targets.

Millensys BRmedusalocker · Technology
Jampac Alimentos BRakira · Agriculture and Food Production
Softruck BRdirewolf · Technology
Jampac Alimentos BRakira · Agriculture and Food Production
Paessolucoes BRPanzer · Other
thegentlemen 7akira 5lockbit5 4emperador 3Vexy Ransomware 2Panzer 2
Active groups & APTs

Several threat actor groups are currently being tracked for activity updates, including funksec, handala, linkc, the Iranian-linked mosesstaff, spacebears, and apt73 — none have publicly claimed new victims in the current reporting window, but their active monitoring status suggests ongoing reconnaissance or preparation phases that defenders should not dismiss.

Brazil focus

Brazil's threat landscape over the past 30 days shows a broad targeting pattern across sectors: FUNAP - Fundação Prof. Dr. Manoel Pedro Pimentel (Government & Defense) was claimed by Booba Project, Terca (Other) by ransomhouse, Engefitas (Manufacturing) by Vexy Ransomware, and multiple technology and food sector companies by akira and medusalocker. The concentration of attacks from groups like thegentlemen and akira, with all known victims located in Brazil, points to deliberate regional targeting rather than opportunistic campaigns.

Millensysmedusalocker · Technology
Jampac Alimentosakira · Agriculture and Food Production
Softruckdirewolf · Technology
PaessolucoesPanzer · Other
Jampac Alimentosakira · Agriculture and Food Production
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel"Booba Project · Government & Defense
Tercaransomhouse · Other
EngefitasVexy Ransomware · Manufacturing
Today’s recommendation: Prioritize patching or isolating Totolink A3002MU and X6000R devices exposed to the internet, and upgrade Langflow to 1.10.3+ and Penpot to 2.18.0+ immediately, especially in any multi-user deployment. For Plane and Perforce P4 Search, verify that default secrets and authentication tokens have been explicitly overridden before any public-facing deployment.
Even when a day shows no confirmed active exploitation, the publication of a dozen critical CVEs with proof-of-concept code is a strong reminder that understanding which of these assets exist in your own environment — and whether they are exposed — is the only way to know your real level of risk.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
October 5, 2026 — Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source ToolsOctober 4, 2026 — ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy DayOctober 3, 2026 — WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy DayOctober 2, 2026 — Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert DayOctober 1, 2026 — FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 BulletinSeptember 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flawsview full archive →
Share