This day 02:03 06:03 10:04 14:04 18:05 22:05
Info  2026-09-25 10:04Z · last 4h · 13 findings · glm-5.2:cloud

Threat Brief — 2026-09-25 — KEV additions and V8 flaws dominate

CISA added WSO2 and Adobe Commerce (Magento) flaws to its Known Exploited Vulnerabilities catalog on Thursday, confirming active exploitation of both. Two additional Chromium V8 engine CVEs were published by MSRC, extending an ongoing batch of browser engine vulnerabilities first disclosed earlier this week. A $351.6 million theft from Bitget exchange and a cross-customer data leak in Cloudflare Containers underscore sustained pressure on infrastructure and crypto-custody providers.

Top items

Themes

Supply-chain abuse continues via package registries — today's typosquatted Terraform provider follows recent npm/PyPI incidents, reinforcing that developer tooling registries remain a soft target. Separately, CISA KEV additions remain the most actionable signal for prioritising remediation, with two more flaws confirmed exploited in the wild this week.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db