This day 02:10 06:00 10:02 14:04 18:07 22:08
⚠ exploit status: CVE-2026-85102 · KEV CVE-2026-87902 · KEV
Info  2026-09-23 22:08Z · last 4h · 11 findings · glm-5.2:cloud

Threat Brief — 2026-09-23 — Exploitation Escalates Across VPN and WordPress

Executive Summary

Two critical exploitation developments dominate today: Check Point has confirmed active in-the-wild exploitation of a pre-authentication RCE in its Security Gateway VPN product (CVE-2026-85102KEV), and threat actors have shifted from probing to actively weaponising WordPress CVE-2026-87902KEV to achieve code execution. Separately, researchers disclosed a new EDR evasion technique that poisons process initialisation structures to bypass endpoint detection, and Apple announced enhanced iOS protections that evaluate the context of transactions rather than just user identity to counter social engineering.

Top items

Themes

Exploitation maturation. Both the Check Point VPN and WordPress stories represent the same arc — vulnerabilities disclosed and patched (or KEV-listed) weeks ago are now seeing active weaponisation rather than reconnaissance. The window between advisory and real-world exploitation continues to compress.

Endpoint defence gaps. The EDR evasion research highlights that process-injection detection remains incomplete when attackers avoid the well-instrumented Windows API surface, reinforcing the need for kernel-level telemetry and behavioural baselines rather than API hooking alone.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db