Security Highlights Of The Week [09/26-1]

SonicWall Warns of Actively Exploited SMA1000 Zero-Day Chain
Threat actors are chaining two previously unknown vulnerabilities in SonicWall SMA1000 appliances in remote code execution attacks. CVE-2026-83548 is a maximum-severity command injection issue stemming from SSRF, while CVE-2026-83549 enables command execution through the management console after administrative access is obtained.
Source: BleepingComputer

Critical JFrog Artifactory Authentication Bypass Reportedly Exploited
A critical vulnerability in JFrog Artifactory is reportedly being exploited only days after public disclosure. CVE-2026-82329 can allow an unauthenticated attacker with network access to obtain administrative privileges under default configurations, putting software artifacts, packages, containers, and development pipelines at risk.
Source: SecurityWeek

Attackers Exploit Switchvox Flaw for Unauthenticated Remote Code Execution
Threat actors are actively exploiting CVE-2026-9586 in Sangoma Switchvox SMB Edition. The critical SQL injection vulnerability can allow an unauthenticated attacker to execute arbitrary code as the PostgreSQL superuser and deploy reverse shells without valid credentials.
Source: The Hacker News

PaperCut Confirms Two Zero-Days Were Exploited
Further investigation into the PaperCut NG and MF attacks revealed that threat actors exploited two zero-day vulnerabilities rather than one. Both can be chained by unauthenticated attackers to bypass authentication and achieve remote code execution, prompting a second emergency patch and the publication of indicators of compromise.
Source: SecurityWeek

Elementor Pro RCE Draws More Than 190,000 Exploit Attempts
Attackers are actively targeting CVE-2026-32475, an unauthenticated arbitrary file upload vulnerability in Elementor Pro affecting millions of WordPress installations. Wordfence reported blocking more than 190,000 exploit attempts against the flaw, which can be used to upload executable PHP files and completely compromise vulnerable sites.
Source: Wordfence

Coder Registry Compromise Delivered Malicious Terraform Modules
Attackers compromised infrastructure used by Coder’s module registry and added unauthorized registry servers capable of serving malicious Terraform modules. The modules contained credential-stealing code, creating a software supply chain path into developer environments at organizations using the Coder platform.
Source: BleepingComputer

Critical Cisco Nexus 9000 Flaw Allows Unauthenticated Root Code Execution
Cisco patched CVE-2026-20212, a critical vulnerability affecting multiple Silicon One-based Nexus 9000 switches. An unauthenticated remote attacker can reach exposed TCP services and execute arbitrary code as root, with no workaround available for affected systems beyond applying the vendor updates.
Source: The Hacker News

HPE Fixes Critical ArubaOS-CX Remote Code Execution Vulnerability
CVE-2026-73749 is a critical buffer overflow in ArubaOS-CX that can allow an unauthenticated remote attacker to send crafted packets to a vulnerable daemon. Successful exploitation can result in code execution with elevated privileges on affected network infrastructure.
Source: BleepingComputer

Attackers Exploit Critical Ruby on Rails Flaw for Remote Code Execution
Attackers are exploiting CVE-2026-66066, also known as KindaRails2Shell, against vulnerable Ruby on Rails applications. The flaw can enable arbitrary file read, exposure of application secrets, remote code execution, and lateral movement, with exploitation following the publication of technical details and proof-of-concept code.
Source: SecurityWeek

Unit 42 Investigates Ransomware Attack Accelerated by Agentic AI
Unit 42 investigated a ransomware intrusion in which the threat actor said frontier AI models and attack-specific agents were used to automate large parts of the operation. Researchers reported that more than 50 MITRE ATT&CK techniques were executed in under 10 hours, including internal reconnaissance, source repository access, credential theft, unauthorized CI/CD activity, and compromise of cloud AI infrastructure.
Source: Unit 42

BGP Hijack Diverted Softaculous Traffic Through Attacker Infrastructure
A BGP hijack affecting a Softaculous address block diverted internet traffic to attacker-controlled infrastructure for more than a day. The attacker also obtained a valid TLS certificate for affected domains, meaning redirected users could establish apparently trusted HTTPS connections without receiving certificate warnings.
Source: Virtualizor

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
Data stolen from Manchester Airports Group has been leaked following the company’s refusal to pay a ransom. The exposed information reportedly includes email addresses and phone numbers belonging to 8.8 million people, along with booking, vehicle registration, postcode, and airport Wi-Fi data.
Source: SecurityWeek

Thomson Reuters Breach Exposes Sensitive US and Canadian Court Data
A breach of a Thomson Reuters records platform exposed sealed court information and sensitive personal data associated with courts in at least 12 US states, the US Virgin Islands, and Canada. Thomson Reuters said the compromise occurred within its own environment rather than the systems of the affected courts.
Source: The Record

Spring Ring Uses Microsoft Teams Vishing and NTLM Relay Attacks
Unit 42 documented a coordinated campaign in which attackers used external Microsoft Teams accounts to impersonate IT helpdesk personnel and call employees directly. Some attacks progressed from voice phishing and remote management tool installation to NTLM relay attempts against domain controllers, demonstrating how collaboration platforms can become an initial access channel.
Source: Unit 42

Fire Ant Expands From Hypervisors Into Trusted Network Infrastructure
The Fire Ant threat actor has expanded from hypervisor compromise into routers, authentication infrastructure, and other trusted systems that connect high-value environments. Sygnia observed compromised routers being used for covert connectivity and traffic collection, while attacks against TACACS infrastructure enabled credential interception and weakened the reliability of administrative audit trails.
Source: Sygnia

Scroll to top