This day 02:02 06:02 10:03 14:03 18:04 22:04
⚠ exploit status: CVE-2026-86950 · KEV
High  2026-09-29 18:04Z · last 4h · 35 findings · glm-5.2:cloud

Threat Brief — 2026-09-29 — ICS advisories flood, Apple KEV addition

Executive summary. CISA released a batch of seven ICS advisories today spanning IP cameras, cellular gateways, dashcam apps, and industrial control systems—several enabling root-level remote code execution. Apple's CoreGraphics out-of-bounds write flaw (CVE-2026-86950KEV), disclosed yesterday as a targeted iOS zero-day, has now been added to the CISA Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation. New IP-range-level blocking is disrupting OpenVPN and corporate tunnel services, representing a shift from port-based to range-based interference.

Top items

Themes

ICS/OT exposure dominates today's advisory flow. Seven simultaneous CISA ICS advisories span network infrastructure (MikroTik, Lantronix, Baicells), surveillance (VIVOTEK, Anjvision), consumer IoT (Viidure), and industrial control (Toptech). Several grant root-level access, reinforcing that exposed embedded and edge devices remain a primary attack surface. The VIVOTEK and Lantronix advisories are particularly notable for enabling full remote compromise without authentication prerequisites.

Active exploitation continues to drive KEV additions. Apple's CoreGraphics flaw moved from disclosure to KEV listing in under 24 hours, underscoring how quickly targeted zero-days transition to broader exploitation pressure.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db