This day 02:10 06:00 10:02 14:04 18:07 22:08
⚠ exploit status: CVE-2026-86060 · KEV CVE-2026-85102 · KEV CVE-2026-93616 · KEV CVE-2026-93952 · KEV CVE-2026-94127 · KEV
Info  2026-09-23 18:07Z · last 4h · 22 findings · glm-5.2:cloud

Threat Brief — 2026-09-23 — Router SSH Chain, GitLab Email-as-Credential

Executive summary: A chained pair of MikroTik RouterOS SSH vulnerabilities — one now in CISA's Known Exploited Vulnerabilities catalog — lets attackers take full control of internet-exposed routers with no password or key. Separately, a design weakness in GitLab means the private email address used for issue-by-email submissions is effectively a credential: anyone who obtains it can push code and trigger CI/CD jobs under your identity. CISA also added four actively exploited CVEs to its KEV catalog today, spanning Check Point, F5 BIG-IP APM, and Arista VeloCloud products. A new InfraTrust report warns that network management systems are increasingly being targeted with vulnerabilities exploited before or shortly after vendor disclosure.

Top items

Themes

AI-as-attack-surface continues to expand. Beyond the CLOSEDQUORUM malware (which lets up to four AI models vote on attack actions, first reported 2026-09-22) and the malicious AI-agent skimming operation (600K cards stolen, first reported 2026-09-23), today adds a third AI-adjacent risk: AI coding tools exfiltrating source code to cloud endpoints. The common thread is that AI tooling is creating new, under-appreciated pathways for data loss and autonomous malicious action.

Edge device exploitation remains the dominant attack vector. MikroTik routers join D-Link DIR-822A, Arista VeloCloud, F5 BIG-IP, and Check Point as network-edge products with actively exploited or unpatched critical flaws. Internet-exposed management interfaces on routers, firewalls, and orchestrators continue to be the highest-priority patching surface.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db