Executive assessment
Today's brief leads with Multiple vulnerabilities in lwIP. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 14 should lead today rather than the first finding because it is the only item listed with in-the-wild exploitation, and fixed WordPress releases are available. The Ubuntu container-escape issue remains urgent because a PoC exists and the impact is host-root escape, but confirmed exploitation takes priority. Themes: Active exploitation and public PoCs; Remote code execution and escape paths; Exposure reduction until patching. Patch order: Finding 14 (It has in-the-wild exploitation and fixed WordPress releases are available); Finding 10 (A PoC exists for a host-root container escape, and unaffected upstream Linux kernel releases are listed); Finding 03 (The OpenC3 COSMOS issues are critical, have a PoC, and version 7.3.0 fixes all three vulnerabilities); Finding 04 (The Moquette issue is critical, has a PoC, and fixed broker versions 0.18.1 and 0.19.0 are available); Finding 01 (The lwIP issues are critical and specific fixing commits are identified, even though no exploitation is reported).
Finding 01 — Multiple vulnerabilities in lwIP
What changed: CVE coverage: CVE-2026-91018, CVE-2026-87121. The cited advisories disclose: Double Free; Out-of-bounds Write.
Technical evidence: CVE-2026-87121; CVSS v3.1 9.8; weakness CWE-787; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Minimise network exposure for control-system devices and ensure they are not internet-accessible. Place control-system networks and remote devices behind firewalls and isolate them from business networks. CISA reports no known public exploitation targeting either vulnerability. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01))
Affected: CVE-2026-91018 affects lwIP API versions 2.0.1 through 2.2.1; CVE-2026-87121 affects lwIP MQTT Client Application versions 2.0.1 through 2.2.1. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01))
Fix: CVE-2026-91018 is fixed by commit f873b6295933e4149a2132adf3e9a2d2a676a5ec; CVE-2026-87121 is fixed by commit f89407ea711879c04d91c92b35d67be78bbaf0f1. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01))
Action: Map CVE-2026-87121 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02)
Finding 02 — plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
What changed: GitHub Advisory Database published GHSA-rr49-f9g6-c9r5 for CVE-2026-57149 (plone.app.portlets): Eval Injection, CVSS v3.1 9.9.
Technical evidence: CVE-2026-57149; CVSS v3.1 9.9; weakness CWE-95; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Remove the plone.app.portlets.ManageOwnPortlets permission from untrusted roles and limit portlet management to trusted administrators; where the Classic portlet is not needed, unregister it. SecurityOnline reports that no public proof-of-concept or in-the-wild exploitation has been confirmed. ([github.com](https://github.com/plone/plone.app.portlets/security/advisories/GHSA-rr49-f9g6-c9r5), [securityonline.info](https://securityonline.info/plone-rce-vulnerability/))
Fix: plone.app.portlets 7.0.2, 6.0.4, and 5.0.8. ([github.com](https://github.com/plone/plone.app.portlets/security/advisories/GHSA-rr49-f9g6-c9r5))
Action: Map CVE-2026-57149 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-rr49-f9g6-c9r5)
Finding 03 — Multiple vulnerabilities in OpenC3 COSMOS
What changed: CVE coverage: CVE-2026-77602, CVE-2026-77394, CVE-2026-77601. The cited advisories disclose: Authenticated remote code execution via the user-writable config overlay; Stored, cross-user XSS via Telemetry screen BUTTON widget; Authenticated OS command injection via the pypi_url setting.
Technical evidence: CVE-2026-77602; CVSS v3.1 9.9; weakness CWE-94; technical confidence Medium.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until 7.3.0 can be installed, restrict the COSMOS web/API listener to trusted operator hosts and suspend non-essential authenticated access. In permission-enforcing deployments, restrict system_set and administrator rights to essential accounts; monitor POSTs to /openc3-api/screen and /openc3-api/api, writes under targets_modified/, and plugin installations. ([github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-gvf2-2rh5-mpgf), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f))
Affected: CVE-2026-77602: 5.1.0 through 7.2.1; CVE-2026-77394: 5.0.6 through 7.2.1; CVE-2026-77601: 5.12.0 through 7.2.1. ([github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-gvf2-2rh5-mpgf), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f))
Fix: OpenC3 COSMOS 7.3.0 fixes all three vulnerabilities. ([github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-gvf2-2rh5-mpgf), [github.com](https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f))
Action: Map CVE-2026-77602 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-jjq7-m736-w977)
Finding 04 — Moquette: Incorrect Authorization
What changed: GitHub Advisory Database published GHSA-5f42-97gr-vfhq for CVE-2026-85724 (Moquette): Incorrect Authorization, CVSS v3.1 9.6; affected: Moquette Broker versions through 0.18.0 inclusive.
Technical evidence: CVE-2026-85724; CVSS v3.1 9.6; weakness CWE-863, CWE-155; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Reject client IDs or usernames containing +/# at CONNECT and expand %c/%u as literal tokens. Add resource caps for connections, queues, retained messages, aliases and interceptor queues, with bounded session expiry. The Moquette GitHub security advisory reports source-only PoCs that run on JDK 17. ([github.com](https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq))
Affected: Moquette Broker versions through 0.18.0 inclusive. ([github.com](https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq))
Fix: Moquette Broker versions 0.18.1 and 0.19.0. ([github.com](https://github.com/moquette-io/moquette/security/advisories/GHSA-5f42-97gr-vfhq))
Action: Map CVE-2026-85724 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-5f42-97gr-vfhq)
Finding 05 — gfs2-utils: Out-of-bounds Write
What changed: A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
Technical evidence: CVE-2026-71220; CVSS v3.1 7; weakness CWE-787; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Do not run gfs2_edit on untrusted or potentially compromised GFS2 filesystem images; process untrusted images only in a containerised or VM-isolated environment. Until patched, disable automatic fsck at boot for GFS2 filesystems by setting fs_passno to 0 in /etc/fstab. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2026-71220), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-71220))
Affected: Red Hat Enterprise Linux 7, 8 and 9 are affected; Debian lists gfs2-utils 3.5.0-2 in bookworm and 3.6.1-1 in forky, sid and trixie as vulnerable. ([access.redhat.com](https://access.redhat.com/security/cve/cve-2026-71220), [security-tracker.debian.org](https://security-tracker.debian.org/tracker/CVE-2026-71220))
Action: Map CVE-2026-71220 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-71220)
Finding 06 — Siemens Desigo CC family: Code Injection
What changed: A Client Code Execution (CCE) vulnerability has been identified in Desigo CC, potentially allowing malicious actors to execute arbitrary code on client devices through specially crafted graphics documents. This vulnerability leverages user-defined graphics containing embedded scripts that are executed on client application instances.
Technical evidence: CVE-2026-34223; CVSS v3.1 8.2; weakness CWE-94; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict Graphics application configuration access to required users only, using a least-privilege authorisation policy. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-330084.html), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-34223))
Affected: All versions of Desigo CC ClickOnce Client V6 and V7 and Desigo CC Installed Client V6 and V7. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-330084.html))
Fix: No fix is currently available for the affected V6 and V7 clients. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-330084.html))
Panel assessment: Treat this as a this-week mitigation priority: there is no fix for the listed V6 and V7 clients, exploitation is not reported, but successful abuse reaches the client operating system and may support lateral movement. The likely path is a crafted Desigo CC graphics document with embedded script, created or altered through Graphics application configuration, then executed by client application instances. (priority: this week)
Action: Map CVE-2026-34223 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-05)
Finding 07 — Siemens SIMOVE Fleetmanager and SIPLANT: Relative Path Traversal
What changed: SIMOVE Fleetmanager and SIPLANT contain a path traversal vulnerability that could allow an attacker to access files outside of intended scope. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Technical evidence: CVE-2026-67367; CVSS v3.1 8.6; weakness CWE-23; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Restrict network access to affected devices and restrict services' access rights to project files through appropriate user management. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-517424.html), [cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07))
Affected: SIMOVE Fleetmanager V3.1 before V3.1.13, V3.2 before V3.2.4, V3.3 before V3.3.2 and V4.0 before V4.0.1; all SIPLANT V1.7, V2.2 and V3.0 versions; and SIPLANT V3.1 before V3.1.4. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07))
Fix: SIMOVE Fleetmanager V3.1.13, V3.2.4, V3.3.2 and V4.0.1 or later; SIPLANT V3.1.4 or later. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-517424.html))
Action: Map CVE-2026-67367 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07)
Finding 08 — TOTOLINK A3002RU: Stack-based Buffer Overflow
What changed: NVD records CVE-2026-26731 (TOTOLINK A3002RU): Stack-based Buffer Overflow, CVSS v3.1 8; affected: A3002RUV2 versions up to and including V2.1.1-B20211108.1455.
Technical evidence: CVE-2026-26731; CVSS v3.1 8; weakness CWE-121; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict the router's web management interface to trusted IP addresses and disable remote management when it is not required. CISA ADP Vulnrichment reports proof-of-concept exploitation. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-26731/), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/26xxx/CVE-2026-26731.json), [github.com](https://github.com/0xmania/cve/tree/main/TOTOLINK-A3002RU-boa-formDnsv6-StackOverflow))
Affected: A3002RUV2 versions up to and including V2.1.1-B20211108.1455. ([github.com](https://github.com/0xmania/cve/tree/main/TOTOLINK-A3002RU-boa-formDnsv6-StackOverflow))
Action: Map CVE-2026-26731 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-26731)
Finding 09 — googleapis/mcp-toolbox: SQL Injection
What changed: A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via fmt.Sprintf directly into a generated AI.FORECAST table-valued SELECT statement.
Technical evidence: CVE-2026-15829; CVSS v4.0 8.6; weakness CWE-89, CWE-863; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-15829 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-15829)
Finding 10 — Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
What changed: A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.
Technical evidence: CVE-2026-80521; CVSS v3.1 7.8; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Move sensitive or untrusted workloads from shared-kernel containers to microVM isolation such as Firecracker or Kata Containers. DepthFirst reports releasing a complete container-escape exploit that successfully targets the latest Ubuntu 26.04. ([depthfirst.com](https://depthfirst.com/research/containers-are-no-longer-safe), [ubuntu.com](https://ubuntu.com/security/CVE-2026-80521), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-80521))
Affected: Ubuntu lists the linux package as vulnerable on 26.04 LTS and 24.04 LTS; on 22.04 LTS, the generic linux package is not affected but linux-hwe-6.8 is vulnerable. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-80521))
Fix: Upstream Linux kernel releases 6.12.111, 6.18.53 and 7.1.10 are listed as unaffected. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-80521))
Action: Map CVE-2026-80521 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
Finding 11 — Multiple vulnerabilities in Foxit PDF Reader
What changed: CVE coverage: CVE-2026-91801, CVE-2026-91797, CVE-2026-91795, CVE-2026-91794, CVE-2026-13128, CVE-2026-91792, CVE-2026-91791, CVE-2026-91789, CVE-2026-91788, CVE-2026-91796, CVE-2026-91793, CVE-2026-57238, CVE-2026-13129, CVE-2026-57256, CVE-2026-91790, CVE-2026-91818, CVE-2026-91817, CVE-2026-91816, CVE-2026-91815, CVE-2026-91813, CVE-2026-91812, CVE-2026-91811, CVE-2026-91810, CVE-2026-91809, CVE-2026-91808, CVE-2026-91807, CVE-2026-91806. The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-91801; CVSS v3.1 7.8; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patched, permit Foxit to open only trusted PDFs and disable JavaScript organisation-wide. Block outbound SMB from endpoints to prevent the documented external SMB-authentication path. Tenable reports no known exploits for both its pre-2026.1.2 and pre-2026.2.1 Foxit PDF Reader checks. ([foxit.com](https://www.foxit.com/support/security-advisories/), [foxit.com](https://www.foxit.com/support/security/), [foxit.com](https://www.foxit.com/support/security-bulletins.html), +2 more)
Affected: Windows: Foxit PDF Reader 2026.2.0.39747 and earlier. macOS: Foxit PDF Reader for Mac 2026.2.0.72029 and earlier. ([foxit.com](https://www.foxit.com/support/security-bulletins.html))
Fix: Foxit PDF Reader 2026.2.1 for Windows and macOS. ([foxit.com](https://www.foxit.com/support/security-bulletins.html))
Action: Map CVE-2026-91801 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-734/)
Finding 12 — Multiple vulnerabilities in Klever-Go
What changed: CVE coverage: CVE-2026-82407, CVE-2026-82409, CVE-2026-82406, CVE-2026-86065, CVE-2026-86064. The cited advisories disclose: Validator registration accepts an unvalidated BLS public key: consensus liveness DoS; Elasticsearch bulk / painless injection via on-chain account name: explorer/indexer data forgery; Zombie-order theft: Buy missing IsClaimed guard in native marketplace; Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin: remote node memory/goroutine exhaustion; /log controls global node logging.
Technical evidence: CVE-2026-82407; CVSS v4.0 7; weakness CWE-20; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patched, remove /log from the default open routes and require authentication before the WebSocket upgrade. For /subscribe, enforce message-size limits, global and per-source-IP connection caps, and a trusted-origin allowlist. ([github.com](https://github.com/advisories/GHSA-9v8p-frvj-2pcm), [github.com](https://github.com/advisories/GHSA-4fwh-wrm6-97xm), [github.com](https://github.com/advisories/GHSA-9wh6-9hq7-9688), +2 more)
Affected: All five vulnerabilities affect Klever-Go versions through 1.7.19. ([github.com](https://github.com/advisories/GHSA-9wh6-9hq7-9688), [github.com](https://github.com/advisories/GHSA-7c7c-373r-gfjj), [github.com](https://github.com/advisories/GHSA-26r5-4mm2-px5c), +2 more)
Fix: Klever-Go 1.7.20 fixes all five vulnerabilities. ([github.com](https://github.com/advisories/GHSA-9wh6-9hq7-9688), [github.com](https://github.com/advisories/GHSA-7c7c-373r-gfjj), [github.com](https://github.com/advisories/GHSA-26r5-4mm2-px5c), +2 more)
Panel assessment: Patch now: all five issues are fixed in 1.7.20, PoCs are documented for the unauthenticated WebSocket path, and the combined blast radius spans node availability, consensus liveness, indexed data integrity, and marketplace asset theft. The likely attack path is direct exposure of /subscribe or /log for remote resource exhaustion or logging control, plus malicious on-chain inputs or marketplace transactions that reach explorer/indexer data and native marketplace assets. (priority: patch now)
Action: Map CVE-2026-82407 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-9wh6-9hq7-9688)
Finding 13 — Microsoft Outlook Remote Code Execution Vulnerability
What changed: This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only.
Technical evidence: CVE-2026-70125; CVSS v3.1 8.8; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Until patching, block or quarantine Office file attachments from untrusted senders at the email gateway. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70125), [learn.microsoft.com](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates))
Affected: Microsoft 365 Apps for Enterprise, Microsoft Office LTSC 2021 and Microsoft Office LTSC 2024, each in 32-bit and 64-bit editions. ([msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70125))
Fix: September 2026 builds: Current Channel 2608 (20326.20144); Monthly Enterprise Channel 2608 (20326.20142), 2607 (20228.20226) and 2606 (20131.20260). ([learn.microsoft.com](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates))
Action: Map CVE-2026-70125 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70125)
Finding 14 — Still active: Hackers start exploiting critical WordPress flaw for code execution
Coverage status: First reported 2026-09-22; ongoing coverage.
What changed: Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
Technical evidence: CVE-2026-87902; CVSS v3.1 8.1; weakness CWE-98; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Reject traversal sequences in the pagename parameter and disable PHP register_argc_argv to interrupt the observed pearcmd.php execution chain. Monitor requests for encoded traversal in pagename, pearcmd, +config-show or +config-create, and inspect /tmp and /var/tmp for unexpected PHP files. Patchstack reports attackers exploiting the flaw to write PHP files to disk, including files that execute shell commands. ([patchstack.com](https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/), [patchstack.com](https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/))
Affected: WordPress Core 4.7.0 to 7.1.1. ([patchstack.com](https://patchstack.com/articles/wordpress-7-1-2-security-release-unauthenticated-lfi-to-rce/))
Fix: 7.1.2, 7.0.6, 6.9.9, 6.8.10, with branch backports through 4.7.37. ([patchstack.com](https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/))
Panel assessment: Patch now for any internet-reachable WordPress instance: exploitation is already in the wild, the affected core range is broad, and successful abuse turns a web request into command execution on the host. The likely path is pagename traversal into pearcmd.php, then writing PHP into writable locations such as /tmp or /var/tmp, which can expose site data, configuration secrets, and any downstream systems reachable with the web-server account's privileges. (priority: patch now)
Action: Map CVE-2026-87902 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/)
Finding 15 — Siemens WTV676 and WTV776: Improper Validation of Specified Type of Input
What changed: The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices.
Technical evidence: CVE-2026-89207; CVSS v3.1 6.5; weakness CWE-1287; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Analyst note: Keep these devices off the internet, minimise their network exposure, and place control-system networks and remote devices behind firewalls, isolated from business networks. CISA ADP Vulnrichment records exploitation as 'none'. ([cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08), [cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-823812.html), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89207.json))
Affected: WTV676-HB6035 Web Interface: all versions before V3.94; WTV776-HB6035 Web Interface: all versions before V4.17. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-823812.html))
Fix: WTV676-HB6035 Web Interface: V3.94 or later; WTV776-HB6035 Web Interface: V4.17 or later. ([cert-portal.siemens.com](https://cert-portal.siemens.com/productcert/html/ssa-823812.html))
Action: Map CVE-2026-89207 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08)