This day 02:08 06:09 10:09 14:10 18:00 22:01
⚠ exploit status: CVE-2026-85706 · KEV
Crit  2026-09-14 14:10Z · last 4h · 11 findings · glm-5.2:cloud

Threat Brief — 2026-09-14 — Flowise RCE and Trusted-Device Eavesdropping

Today's feed is light on fresh critical vulnerabilities but surfaces two notable technique developments worth attention: a practical demonstration of how Flowise AI's config-execution model turns admin-panel access into remote command execution, and a report that law enforcement can read end-to-end encrypted messages by registering a victim's machine as a trusted device — without breaking encryption. A malicious Twitch browser extension leaking OAuth tokens from roughly 31,000 users remains active and carries a usable IoC.

Top items

Themes

AI platforms as attack surface. The Flowise writeup and last week's reports of trusted AI platforms being abused to host malware both reinforce that AI-agent orchestration tools with code-execution capabilities are a growing target. Admin-panel access to such platforms should be treated as equivalent to production server access.

Endpoint trust over crypto strength. The trusted-device law-enforcement technique underscores a broader pattern: attackers and investigators increasingly bypass strong encryption by compromising the endpoint or hijacking device-trust relationships rather than attacking the protocol. This is the same class of problem seen in OAuth-token theft and malicious browser extensions like the Twitch/JeetBot case.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db