This day 02:05 06:05 10:06 14:06 18:07 22:08
⚠ exploit status: CVE-2026-76504 · KEV
Info  2026-09-30 18:07Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-09-30 — Zero-days and AI Trust Erosion

Executive summary: A critical Cisco SD-WAN Manager zero-day is under active exploitation, granting attackers admin-level access via authentication bypass. Separately, a WordPress core flaw dubbed "Click2Shell" enables forced theme installation as a stepping stone to remote code execution. On the identity front, Microsoft is preparing automatic Entra ID script-injection protections for October. Two analytical pieces—Mandiant's AI-era vulnerability trends and a warning about persistent AI "coworkers" breaking existing identity models—underscore that the attack surface is expanding faster than controls are maturing.

Top items

Themes

AI as both weapon and victim. Three of today's items involve AI-adjacent risk: malicious ChatGPT Custom GPTs weaponising the platform for malware delivery, AI "coworkers" creating unmodelled identity risks, and Mandiant's analysis of AI's effect on vulnerability discovery. The common thread is that AI tooling is expanding the attack surface faster than defensive controls are adapting.

Active exploitation dominates priority. The Cisco SD-WAN zero-day and the WordPress Click2Shell flaw both involve live or near-live exploitation paths. The MikroTik RouterOS vulnerability (CISA-advised since early September) continues to circulate but has no new development today.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db