VYPR
AI Brief2026-10-02· generated Oct 2, 2026

What you need to know today.

CISA adds actively exploited cPanel and Cisco SD-WAN flaws to KEV; critical vulnerabilities disclosed in Apple, WordPress, and Netcore devices.

CISA has added a critical authentication bypass vulnerability in cPanel and WHM (CVE-2026-41940) to its Known Exploited Vulnerabilities catalog. This flaw allows unauthenticated remote attackers to gain unauthorized access to the control panel, potentially leading to server compromise. Multiple news outlets have reported on active exploitation campaigns, with some campaigns deploying backdoors and malware like Mirai. The vulnerability has been actively exploited since at least May 2026, with attackers leveraging GitHub Actions runners to target affected servers. As The Hacker News reported, exploitation has been observed in campaigns deploying the Filemanager backdoor. cPanel has released patches for versions after 11.40.

A critical vulnerability in Cisco Catalyst SD-WAN Manager (CVE-2026-76504) is also being actively exploited in the wild and has been added to the CISA KEV catalog. This flaw allows an unauthenticated, remote attacker to gain administrative privileges by exploiting a vulnerability in the API session-based authentication management. Several security publications, including GovInfoSecurity, have highlighted the active exploitation of this zero-day vulnerability. Cisco has released patches to address this issue.

Several high-severity vulnerabilities have been disclosed across Apple products, including an out-of-bounds write in Samsung Mobile's libimagecodec.quram.so (CVE-2025-21042) allowing arbitrary code execution, and a use-after-free issue in Safari, iOS, iPadOS, macOS, tvOS, and visionOS (CVE-2025-43529) fixed in recent updates. Additionally, a sandbox escape vulnerability in Google Chrome (CVE-2025-6558), affecting Chromium, has been detailed. While these vulnerabilities are rated high, they have not been added to the CISA KEV catalog at this time.

A critical arbitrary file upload vulnerability has been discovered in FlowiseAI Flowise v2.2.6 (CVE-2025-26319), allowing unauthenticated attackers to upload malicious files to the server. Separately, multiple critical vulnerabilities have been disclosed in WordPress plugins, including an arbitrary file upload flaw in the Scraper Plugin (CVE-2025-69129) and an unrestricted upload vulnerability in the Support Ticket System for WooCommerce (CVE-2025-60235). These WordPress vulnerabilities could allow attackers to execute arbitrary code or gain unauthorized access.

Critical command injection vulnerabilities have been identified in Netcore devices, including Netcore NR289-GE (CVE-2026-101076) and Netcore NBR100V2 (CVE-2026-101000). These flaws allow remote attackers to execute arbitrary operating system commands by manipulating specific parameters. Additionally, a critical vulnerability in Joomla Extension - ordasoft.com (CVE-2026-102427) allows for unauthenticated remote code execution via a file in the component's frontend routing. These vulnerabilities highlight ongoing risks in embedded devices and web application components.

Hitachi Coding Software Suite is affected by multiple critical vulnerabilities, including hidden functionality (CVE-2026-82829), use of hard-coded cryptographic keys (CVE-2026-82827), and missing authentication for critical functions (CVE-2026-82825). These flaws could allow attackers to gain unauthorized access, generate fraudulent tokens, or alter data. Separately, a critical vulnerability in BoKS keytab management (CVE-2026-79901) involves predictable password generation, potentially allowing attackers to compromise service accounts. These vulnerabilities underscore the importance of secure credential management and access controls.

Synthesized by Vypr AI
KEV Additions: cPanel, Cisco SD-WAN Exploited · VYPR