This day 02:05 06:05 10:06 14:06 18:07 22:08
⚠ exploit status: CVE-2026-86950 · KEV
Info  2026-09-30 02:05Z · last 4h · 3 findings · glm-5.2:cloud

Threat Brief — 2026-09-30 — Apple zero-day exploitation detail deepens

Apple's CVE-2026-86950KEV, already known to be exploited and listed in CISA's Known Exploited Vulnerabilities catalog, is now described as being weaponised in "extremely sophisticated" targeted attacks, adding context to the threat picture first reported on 28 September. The Unsloth Studio model-inspection RCE resurfaced in feeds but carries no new development beyond yesterday's initial disclosure. Microsoft's general availability of Linux container support in WSL is a platform update with no direct threat-intelligence implication.

Top items

Themes

Targeted exploitation of known-nipped vulnerabilities. CVE-2026-86950KEV illustrates the pattern of a vendor-patched, KEV-listed flaw continuing to generate intelligence as the nature of in-the-wild exploitation becomes clearer — the vulnerability itself is not new, but the threat-actor tradecraft detail is.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db