Threat Brief — 2026-09-18 — WordPress Patches, Linux Kernel KEV Additions
Executive summary: CISA added two Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog today, both with evidence of active exploitation in the wild. WordPress has released core patches for a vulnerability dubbed Click2Shell that can force theme installation via a crafted link and potentially chain to remote code execution. Law enforcement in the UAE and Sweden dismantled a cryptocurrency money-laundering network moving $7.1 million over ten months.
Top items
- CISA adds two Linux kernel CVEs to KEV catalog — both actively exploited. CVE-2025-39964KEV (race condition) and CVE-2026-53266KEV (out-of-bounds memory access) have been added to CISA's Known Exploited Vulnerabilities catalog based on evidence of active exploitation. No public exploit URLs were provided in the finding, but KEV inclusion confirms in-the-wild exploitation. Linux kernel deployments should be treated as exposed. (src: CISA Current Activity)
- WordPress releases core patches for Click2Shell flaw chainable to RCE. WordPress has issued patches for a set of core vulnerabilities including one where a crafted web link, opened by a logged-in administrator, can install a theme from the official WordPress.org directory without consent. The flaw can chain to code execution. This appears to be a development of the critical WordPress RCE story first reported today by SecurityLab. (src: The Hacker News; first reported 2026-09-18 by SecurityLab)
- UAE and Sweden arrest seven in $7.1M cryptocurrency laundering network. Authorities traced the international network through cryptocurrency transactions, arresting seven suspects across both countries. The network reportedly laundered funds over a ten-month period. This is a law-enforcement development, not a new technical threat, but it illustrates continued abuse of cryptocurrency rails for cross-border money movement. (src: Xakep)
Themes
GitHub as attack surface continues to expand. Multiple active stories this week — Transparent Tribe's private-repo C2, fake LastPass Authenticator repos pushing Rapuncel, and WeaselBiscuit npm packages — all abuse GitHub's legitimacy and SEO visibility for malware distribution or command-and-control. Organizations should treat unsolicited GitHub repositories and packages with the same scrutiny as unknown email attachments.
