This briefing covers critical cybersecurity developments from September 12-13, 2026. The threat landscape is dominated by severe WordPress plugin vulnerabilities with multiple CRITICAL-rated remote code execution flaws (CVE-2026-78159, CVE-2026-78006, CVE-2026-85681, CVE-2026-84171, CVE-2026-82845) affecting popular plugins including The Events Calendar and e-learning platforms. These vulnerabilities require immediate patching as they allow unauthenticated attackers to execute arbitrary code on servers.
Concurrently, significant malware distribution activity continues with 50 Mirai and Mozi botnet URLs targeting IoT devices across global infrastructure. Ransomware operations remain active with 23 new victim disclosures across multiple groups including Krybit (16 victims), Medusalocker, Rhysida, and Global ransomware gangs, impacting organizations from critical infrastructure (Egyptian Airports Company) to healthcare (Ibn Sina Trust) and government (Sutton Public Schools).
Additionally, critical Check Point VPN vulnerabilities (CVE-2026-85102, CVE-2026-85103) face imminent exploitation according to Dutch NCSC warnings, while a concerning Google privacy incident exposed identifying information of sex crime victims globally. Organizations should prioritize WordPress security updates, VPN patching, and monitoring for indicators of the widespread botnet campaigns.
Multiple critical and high-severity vulnerabilities discovered in popular WordPress plugins enabling remote code execution, privilege escalation, and SQL injection attacks.
Two critical remote code execution vulnerabilities in The Events Calendar plugin affecting versions up to 6.17.4. CVE-2026-78159 involves insufficient validation of widget 'classes' map allowing bypass of security checks. CVE-2026-78006 exploits PHP magic methods during isset() checks. Both allow unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities in WP Component (CVE-2026-85681), WP images upload on piclect (CVE-2026-84171), and DS Ad Rotator (CVE-2026-81402) plugins allow unauthenticated attackers to upload arbitrary files including PHP to execute remote code. No authentication or capability checks present.
Critical vulnerability in Masteriyo LMS plugin before 3.4.1 allows users with minimal accounts to inject arbitrary PHP objects through unsanitized metadata deserialization, potentially escalating to remote code execution via bundled library classes.
High-severity SQL injection flaws in rtMedia (CVE-2026-16482), SAMO Forms (CVE-2026-80491), and Album Cover Finder (CVE-2026-84047) plugins allow unauthenticated attackers to execute arbitrary SQL queries due to insufficient input sanitization and escaping.
High-severity local file inclusion vulnerability in GEO my WP plugin (all versions up to 4.5.5.3) allows unauthenticated attackers to include and execute arbitrary PHP files on the server through unvalidated file path parameters.
Multiple high-severity privilege escalation vulnerabilities: MemberPress Corporate Accounts (CVE-2026-15451) allows mass assignment attacks to grant administrator roles; Add User Autocomplete (CVE-2026-87759) permits subscribers to grant themselves admin on multisite; Tutor LMS (CVE-2026-78175) enables PHP object injection via AJAX handlers.
Critical vulnerabilities affecting enterprise VPN, containerization, and industrial control systems requiring immediate attention.
Dutch NCSC warns of imminent exploitation of two critical Check Point VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103). Organizations using Check Point VPN solutions should apply patches immediately to prevent compromise.
Critical stack buffer overflow in sngrep through 1.8.4 when processing SIP packets with oversized Call-ID or X-Call-ID headers exceeding 255-byte buffer limits, allowing crafted packets to cause crashes or potential code execution.
High-severity vulnerability in Flatpak before 1.18.1 allows malicious sandboxed applications to obtain arbitrary read/write access to host files, escalating to arbitrary code execution on the host system. Distinct from CVE-2026-76925.
High-severity vulnerabilities in zstd-jni (CVE-2026-90560) and snappy-java (CVE-2026-90559) involving out-of-bounds read/write due to missing validation of buffer capacity against decompressed data size, allowing memory corruption attacks.
High-severity improper certificate validation in ASE/Kalkitech ASE2000 V2 Communication Test Set (versions 2.35-2.37) IEC 60870-5-104 TLS client allows network attackers to bypass certificate validation, impacting industrial control system security.
Widespread Mirai and Mozi botnet malware distribution activity targeting IoT devices globally with 50 active malware download URLs detected.
Active Mirai botnet distribution across 30+ malware download URLs primarily targeting Asia-Pacific region IoT devices. URLs serving both shell scripts and binaries across multiple non-standard ports, indicating large-scale automated exploitation of vulnerable devices.
Continued Mozi botnet propagation with 18 active malware distribution URLs detected across compromised IoT devices. Campaign demonstrates persistent targeting of routers, DVRs, and network-attached devices primarily in Asian networks.
Twenty-three organizations victimized by ransomware groups including Krybit, Medusalocker, Rhysida, Global, and others, impacting critical infrastructure, healthcare, and government sectors.
Krybit ransomware group disclosed 16 victims spanning critical infrastructure (Egyptian Airports Company), healthcare (Ibn Sina Trust Bangladesh), luxury hospitality (La Sultana Hotels, Tiflis Palace), logistics (Capricorn Logistics India), and manufacturing (Metalware Canada, Intherpro UAE). Represents significant escalation in targeting diverse international organizations.
Medusalocker ransomware group compromised multiple organizations including Chinese elevator manufacturer Ruixiang Jidian (OEM supplier to OTIS, KONE, Hitachi), UAE metals company Abourame (25,448 emails extracted), US roofing contractor Frisby Construction, and Indian luxury safari resort Praveg Caves Jawai running IDS Fortune hotel management system.
Global ransomware gang targeted Sutton Public Schools (Massachusetts) municipal government and education system. Emperador ransomware compromised Nexbex Solutions (Indian technology consulting firm). Rhysida ransomware attacked Axdia International (German electronics company).
Securotrop ransomware group compromised Shelco Filters with 191 GB of data currently held for ransom (status: AWAITING). Industrial filtration systems company breach could expose critical infrastructure and manufacturing data.
Significant privacy breach affecting sex crime victims globally and ransomware-related data exposures across multiple sectors.
Google leaked identifying information for sex crime victims across multiple countries (not limited to Korea) who submitted removal requests for illegally obtained sexual images. Victims' private information was inadvertently posted online, creating severe privacy and safety risks for vulnerable individuals including minors.
Medusalocker ransomware attack on UAE-based Abourame Metals resulted in extraction of 25,448 corporate email accounts (domain: abourametals.com), representing significant organizational communications exposure and potential business email compromise risk.
New cybersecurity guidance issued for financial services entities focusing on risk assessment requirements.
New York State Department of Financial Services Acting Superintendent issued new cybersecurity guidance on September 10, 2026, outlining expectations for DFS-regulated financial services entities conducting risk assessments. Updated regulatory framework aims to strengthen cybersecurity posture across the financial sector.
Claude Code v2.1.270 security fix addressing permission bypass regression.
Claude Code released version 2.1.270 fixing a regression in 2.1.269 where read-only git commands in Bash unexpectedly requested permissions after extended session runtime. Security patch addresses potential privilege escalation concern in development environments.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.