VYPR
AI Brief2026-10-11· generated Oct 10, 2026

What you need to know today.

Zammad RCE flaw added to KEV, while ISC BIND DoS vulnerability is exploited by Chinese threat actors.

Zammad versions 6.3.0 through 7.1.2 are affected by a session hijacking vulnerability that allows for remote code execution as the zammad user. This critical flaw, tracked as CVE-2026-102489, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was exploited by an AI agent to breach the Dutch Institute for Vulnerability Disclosure (DIVD), leading to the compromise of sensitive data. Proof-of-concept exploits are publicly available, and patches are expected to address the issue. CISA Alerts reported that this vulnerability is actively exploited.

ISC BIND versions 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 contain a denial-of-service vulnerability (CVE-2015-5477) triggered by specific TKEY queries. This flaw allows remote attackers to cause a REQUIRE assertion failure, leading to a daemon exit. This vulnerability is being exploited by Chinese government-linked threat actors, including the Flax Typhoon group, who are using it to steal sensitive data. The US government has taken action to disrupt these actors, as The Hacker News reported.

A critical vulnerability in the Zombify WordPress plugin (up to version 1.7.7) allows for the unrestricted upload of dangerous file types, enabling attackers to deploy web shells on servers. This flaw, CVE-2026-94503, carries a CVSS score of 10.0 and is highlighted in the latest Wordfence Intelligence report. While not yet on the CISA KEV catalog, its critical nature and potential for exploitation make it a significant concern for WordPress users.

Microsoft Partner Center is susceptible to a critical privilege escalation vulnerability (CVE-2026-96207) due to improper certificate validation. This flaw allows unauthorized attackers to gain elevated privileges over a network. The vulnerability has a CVSS score of 10.0, underscoring its severity.

Several WordPress themes are affected by critical deserialization vulnerabilities, allowing for object injection. These include Balance (up to 1.12.0), Camelia (up to 1.2.15), Convex (up to 1.16.0), Dwell (up to 1.16.0), Edema (up to 1.2.2.2), Greeny (up to 2.10.0), Hogwords (up to 1.2.7), Hygia (up to 1.21.0), IPharm (up to 1.2.4), Let's Play (up to 1.1.15), Partiso (up to 1.1.13), Rosalinda (up to 1.2.4), Smart Casa (up to 1.0.12), Smash (up to 1.12.0), and Tantra (up to 2.9.0). These vulnerabilities, tracked under CVE-2026-93945 and related IDs, all have a CVSS score of 9.8 and pose a significant risk to users of these themes.

The openapi-typescript-codegen package, through version 0.31.0, contains a code injection vulnerability (CVE-2026-108551). Attackers who can control an OpenAPI document can inject JavaScript by providing unescaped values that are interpolated into single-quoted string literals. This critical vulnerability has a CVSS score of 9.8.

Synthesized by Vypr AI