The CyberSec Intelligence team presents the daily security bulletin from September 18, 2026. We analyze recently published vulnerabilities, those under active exploitation in real-world attacks, and security breaches reported in the media, while providing practical recommendations for protecting IT infrastructure.
Actively exploited vulnerabilities
- Google Pixel (CVE-2026-58704): Logic error in the cellular modem allowing permission checks bypass and privilege escalation. Details: NVD CVE-2026-58704.
- Cisco Identity Services Engine (CVE-2026-76460): Incorrect use of privileged APIs, allowing an unauthenticated remote attacker to bypass the web administration interface. Details: NVD CVE-2026-76460.
- Acronis Backup (CVE-2026-87886): Incorrect default permissions in the plugin for cPanel / WHM and the extension for Plesk, allowing privilege escalation. Details: NVD CVE-2026-87886.
- Cisco Secure Email Gateway (CVE-2026-76461): SQL injection vulnerability in AsyncOS allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges. Details: NVD CVE-2026-76461.
- ConnectWise ScreenConnect (CVE-2026-84869): Improper privilege management and lack of authorization, allowing the transfer and execution of files through active sessions without host confirmation. Details: NVD CVE-2026-84869.
- JFrog Artifactory (CVE-2026-42016): Incorrect authorization due to faulty verification of the token signature/issuer, leading to privilege escalation. Details: NVD CVE-2026-42016.
- JFrog Artifactory (CVE-2026-42018): Faulty authentication that can return an internal anonymous user token to an unauthenticated caller, exposing sensitive resources. Details: NVD CVE-2026-42018.
- GitLab Community & Enterprise Edition (CVE-2026-85706): Path Traversal vulnerability in the repository commits API, allowing unauthenticated users to read arbitrary files. Details: NVD CVE-2026-85706.
New critical vulnerabilities
- Covenant (CVE-2026-92717): Registration of the CovenantHub SignalR hub without an authorization attribute, allowing the retrieval of a signed JWT token and full access to the operator API. Details: NVD CVE-2026-92717.
- Feast (CVE-2026-92787): Lack of validation of JWT token signatures, allowing RBAC bypass and obtaining full read and write access on the server. Details: NVD CVE-2026-92787.
- UVdesk Community Skeleton (CVE-2026-92805): Lack of authentication in the installer wizard in the controller, allowing attackers to modify the database and create super-administrator accounts. Details: NVD CVE-2026-92805.
- Multi Uploader for Gravity Forms (CVE-2026-87796): Arbitrary file upload via the move_file function during chunked upload processing, leading to potential remote code execution. Details: NVD CVE-2026-87796.
- rcourtman Pulse (CVE-2026-92860): Improper validation of the Username argument in the Quick Security Setup component, facilitating remote attacks. Details: NVD CVE-2026-92860.
- vm2 (CVE-2026-92937): Sandbox escape leading to remote code execution in the Node.js host process due to an incomplete fix. Details: NVD CVE-2026-92937.
- vm2 (CVE-2026-92938): Exposure of the sqlite module from Node.js in NodeVM, allowing execution of arbitrary native code outside the sandbox. Details: NVD CVE-2026-92938.
- vm2 (CVE-2026-92944): Sandbox escape in Node.js 26 via Promise.prototype.finally(). Details: NVD CVE-2026-92944.
- vm2 (CVE-2026-92948): Bypass of the allowlist for NodeVM in Node.js 24+ by accessing node:test, facilitating code running outside the sandbox. Details: NVD CVE-2026-92948.
- vm2 (CVE-2026-92953): Failure to protect TypedArray and ArrayBuffer prototypes against mutations in the sandbox. Details: NVD CVE-2026-92953.
- Azure Arc (CVE-2026-69399): Critical privilege escalation vulnerability. Details: NVD CVE-2026-69399.
- Microsoft Container Registry (CVE-2026-69865): Authorization bypass via a user-controlled key, allowing privilege escalation in the network. Details: NVD CVE-2026-69865.
From the security press
- Check Point (No CVE): A critical flaw in management and logging servers allows unauthenticated attackers to execute code as root over the network. Patches have been distributed via LivePatch. Details: The Hacker News.
- Docker Sandboxes (CVE-2026-77179): Malicious code inside a Docker virtual machine on macOS can escape from the shared directory and access/modify files on the host. Details: The Hacker News.
- Unbound (CVE-2026-81642): Heap buffer overflow in the DNSSEC validator in the Unbound DNS resolver, allowing RCE via compromised DNS zones. Fixed in version 1.26.1. Details: The Hacker News.
- Issabel Framework (CVE-2026-89026): Active exploitation of an OS-level command execution vulnerability, due to the use of a hardcoded password. Details: The Hacker News.
- WooCommerce Wholesale Lead Capture (No CVE): Attackers are exploiting a critical flaw in this WordPress plugin to upload arbitrary files (PHP backdoors) and obtain RCE. Details: The Hacker News.
- WSO2 API Manager (CVE-2026-5430): Active attempts to bypass JWT authentication through forged cryptographic signatures, leading to administrative account takeovers. Details: The Hacker News.
Recommendations
- Immediate patch implementation: Prioritize updating systems affected by actively exploited vulnerabilities, especially Cisco devices, GitLab instances, and Google Pixel devices.
- Auditing project libraries: Given the severe sandbox escape vulnerabilities identified in the vm2 library, it is recommended to stop using it and replace it with safe alternatives, or to immediately upgrade to the secured version 3.11.7 / 3.11.8.
- Securing administrative interfaces: Limit public exposure of management servers (such as Check Point or UVdesk-type setup assistants) through strict firewall policies and VPN access.
- File change monitoring: Implement file integrity monitoring (FIM) solutions for WordPress platforms affected by plugins with upload flaws, blocking script execution from media folders.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




