September 2026 (30)
Stored XSS in Popup Maker WordPress Plugin (CVE-2026-87915)
2 TTPs 1 CVEThe Popup Maker WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'values[Name]' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the wp-admin dashboard.
Denial of Service Vulnerability in Quarkus WebSockets Next
1 TTP 1 CVEA vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.
Stored XSS Vulnerability in Jeg Kit for Elementor
2 TTPs 1 CVEThe Jeg Kit for Elementor plugin for WordPress contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary scripts when a specific widget is rendered.
CVE-2026-89059: Denial of Service in RESTEasy IIOImageProvider
1 TTP 1 CVEAn unauthenticated remote attacker can trigger a denial of service in Red Hat RESTEasy by submitting a crafted image that causes excessive memory allocation within the JVM via the IIOImageProvider component.
WeaselBiscuit Stealer Distributed via Malicious npm Packages
4 TTPs 1 IOCWeaselBiscuit is a lightweight JavaScript stealer discovered in 13 npm packages that harvests sensitive browser extension storage and performs host profiling across Windows, macOS, and Linux.
ClickFix Campaign Activity
29 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Reflected XSS in Ourphp via ourphp_out.php
1 rule 1 TTP 1 CVEOurphp versions 7.2.0 and earlier are vulnerable to reflected cross-site scripting (XSS) via the 'out' parameter in the 'ourphp_out.php' endpoint, allowing unauthorized script execution in a victim's browser session.
CVE-2026-7473: Arista EOS Incomplete Comparison Vulnerability Leading to Incorrect Packet Forwarding
2 rules 3 TTPs 3 CVEsArista Extensible Operating System (EOS) contains CVE-2026-7473, an incomplete comparison vulnerability that allows a switch to incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the switch's configured decapsulation IP, potentially leading to unauthorized network access or bypass of security controls.
Pi-hole SSRF to RCE Vulnerability via CVE-2024-34361
1 rule 2 TTPs 1 CVEPi-hole versions 5.18.2 and earlier are vulnerable to an authenticated SSRF attack via improper URL validation, which can be chained with the Gopherus protocol to achieve remote code execution on the host system.
Authorization Bypass in Master Addons for Elementor
1 TTP 1 CVEAn authorization bypass vulnerability in the Master Addons for Elementor WordPress plugin allows authenticated contributors to modify or delete arbitrary posts.
Stored XSS Vulnerability in Complianz WordPress Plugin
2 TTPs 1 CVEThe Complianz GDPR/CCPA Cookie Consent Banner plugin is vulnerable to Stored Cross-Site Scripting (XSS) via the Elementor Cookie Blocker, allowing attackers to execute arbitrary JavaScript in the context of an administrator-approved comment.
SQL Injection in Location Manager Plugin for WordPress
1 rule 1 TTP 1 CVEThe Location Manager plugin for WordPress is vulnerable to unauthenticated SQL injection via REST API parameters, allowing remote attackers to extract sensitive database information.
SQL Injection Vulnerability in WCFM Marketplace Plugin
1 rule 1 TTP 1 CVEThe WCFM Marketplace plugin for WordPress is vulnerable to unauthenticated SQL injection via the wcfmmp_user_location_lng parameter, allowing attackers to extract sensitive database information.
Unauthenticated SQL Injection in WP Multi Store Locator Pro
1 rule 1 TTP 1 CVEThe WP Multi Store Locator Pro plugin for WordPress is vulnerable to unauthenticated SQL injection via the 'store_locatore_search_radius' parameter due to inadequate input sanitization and a lack of prepared statements.
Directory Traversal in Printcart Web to Print Product Designer for WooCommerce
1 rule 1 TTP 1 CVEThe Printcart Web to Print Product Designer for WooCommerce plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary server files.
Arbitrary User Meta Write Vulnerability in Mapster WP Maps Plugin
1 TTP 1 CVEThe Mapster WP Maps WordPress plugin contains an arbitrary user meta write vulnerability via the my_profile_update() function, allowing authenticated users with Subscriber-level access to overwrite arbitrary user metadata.
Authorization Bypass in TECHIN2B Application
1 TTP 1 CVEAn authorization bypass vulnerability in TECHIN2B Application allows unauthenticated or low-privileged users to perform privilege abuse via user-controlled keys.
CVE-2026-58138: Unauthenticated Remote Code Execution in Orkes Conductor
1 rule 3 TTPs 2 IOCsAn unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions within inline workflow definitions to the workflow API endpoint before authentication, leveraging unsandboxed GraalVM evaluators through specific task types to invoke system commands via Java reflection or direct subprocess calls.
CVE-2026-93453 Password Reset Poisoning in SOGo
1 TTP 1 CVESOGo versions before 5.12.11 are vulnerable to password reset poisoning, allowing unauthenticated attackers to manipulate reset links by injecting malicious values into the Origin header.
Booking Calendar Plugin Privilege Escalation via AJAX Parameter Injection
1 TTP 1 CVEThe Booking Calendar plugin for WordPress is vulnerable to privilege escalation (CVE-2026-92619) allowing authenticated Editors to modify arbitrary site settings and create administrative accounts.
Authorization Bypass in WordPress Filter Gallery Plugin
1 TTP 1 CVEThe Filter Gallery WordPress plugin contains an authorization bypass vulnerability (CVE-2026-89413) allowing authenticated users with low-level privileges to delete arbitrary gallery records by omitting mandatory nonce checks.
Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability
1 CVECVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.
CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer
1 TTP 1 CVEAuthenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.
Remote Code Execution Vulnerability in Check Point Management Products
1 CVEA critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.
Command Injection in marcopiovanello yt-dlp-web-ui
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in yt-dlp-web-ui version 4 and earlier allows remote attackers to execute arbitrary system commands via the params argument.
CSRF and Stored XSS Vulnerability in django-page-cms
1 TTP 1 CVEAn improper CSRF protection flaw in django-page-cms versions up to 2.0.13 enables attackers to force authenticated editors to inject stored XSS payloads.
Use-After-Free Vulnerability in GPAC Compositor
1 CVEA use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.
Remote Code Execution in HGiga OAKlouds via Insecure Deserialization
2 TTPs 1 CVEAn insecure deserialization vulnerability in the HGiga OAKlouds platform allows unauthenticated attackers to execute arbitrary code via malicious serialized payloads.
Google Security Updates - September 2026
2 CVEsRoundup of Google security advisories published in September 2026.
Denial of Service in go-openapi/swag via Stack Overflow
1 CVEThe go-openapi/swag library is vulnerable to a stack overflow in its jsonutils component, allowing remote unauthenticated attackers to cause a denial-of-service by submitting deeply nested JSON documents.