VYPR
AI Brief2026-09-08· generated Sep 7, 2026

What you need to know today.

N-able patches actively exploited RCE, while vm2 and Webbox face critical sandbox escape and buffer overflow flaws.

A critical pre-authentication remote code execution vulnerability in N-able N-central has been patched. The flaw, identified as CVE-2026-86218, affects versions prior to 2026.3.1.14. This vulnerability was reportedly exploited in the wild, prompting N-able to release multiple hotfixes. The exploitability of this vulnerability highlights the importance of timely patching for network management systems. N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

The vm2 Node.js sandbox library is affected by multiple critical vulnerabilities that could allow attackers to escape the sandbox and achieve arbitrary code execution. CVE-2026-44005, CVE-2026-43997, and CVE-2026-43999 are among the flaws, impacting versions from 3.9.6 to 3.10.5 and prior to 3.11.0. These vulnerabilities stem from issues with mutable proxies, host object access, and bypasses in the module builtin allowlist. vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution

Tobit Laboratories AG's TeamDavid Webbox application suffers from numerous critical vulnerabilities, including buffer overflows. CVE-2026-54212, CVE-2026-5411, and CVE-2026-54210 are specifically mentioned, affecting API endpoints and file upload functionalities. These flaws could allow unauthenticated attackers to execute code by submitting specially crafted data. TeamDavid Webbox: 15 Vulnerabilities Including Critical Buffer Overflows Disclosed Together

A critical deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows for code injection. Affecting versions through 07092026, this flaw (CVE-2026-7861) poses a significant risk to customer service data and operations. The vendor has been notified, and further details are pending.

The IXON VPN Client, prior to version 1.4.7, contains a critical vulnerability (CVE-2026-75925) due to improper neutralization of CRLF sequences. This could allow an attacker to execute commands as root or SYSTEM by manipulating configuration values written to a file. CISA has issued an advisory for this vulnerability. IXON VPN Client

Several critical vulnerabilities have been disclosed in various WordPress plugins. These include an Insecure Direct Object Reference in MemberDash (CVE-2026-16310), Unauthenticated Hook Injection in ComboBlocks (CVE-2024-11080), Authentication Bypass via JWT Forgery in Mstore API (CVE-2026-13447), Local File Inclusion in Divi Ajax Filter (CVE-2026-11613), PHP Object Injection in JobSearch (CVE-2026-84834), and Broken Access Control in YITH Request a Quote for WooCommerce Premium (CVE-2026-84238). These flaws collectively expose a wide range of WordPress sites to potential compromise.

A stack-based buffer overflow vulnerability in D-Link DIR-822A A_101 (CVE-2026-86296) arises from the strcpy function in serverpacket.c. This critical flaw could allow for code execution. Additionally, a critical vulnerability in Linksys RE7000 (CVE-2026-86299) affects its PingTest handler, potentially allowing for manipulation of arguments to achieve a similar outcome.

A flaw in 389 Directory Server (CVE-2026-18922) could allow a stale identity from a previous failed bind attempt to be installed on a connection, potentially leading to unauthorized access. This vulnerability affects the SASL PLAIN authentication mechanism.

Advantech WISE-6610 series devices are impacted by critical vulnerabilities CVE-2026-79698 and CVE-2026-79697. Details are limited, but these flaws indicate a significant security risk for industrial control systems and IoT devices utilizing this hardware.

Synthesized by Vypr AI
N-able RCE Patched; vm2, Webbox Face Critical Flaws · VYPR