Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

By George Bailey   Published: 09/24/26   Updated: 09/24/26   2 min read

Published: 09/24/26

Thursday’s brief opens on the public web’s soft underbelly: attackers moved from probing to writing PHP on unpatched WordPress hosts in under a day. Also on the desk — Tomcat’s WebSocket lock you can walk around, Palo Alto’s highest-urgency firewall bug that still needs a deliberate upgrade pass, and SAP’s OVERPASS kernel flaw now shipping with public proof-of-concept code.

Lead Story

WordPress under active attack — patch Core before Friday

CVE-2026-87902 lets an unauthenticated attacker include a local PHP file via page-template resolution. Patchstack watched reconnaissance start hours after 7.1.2 shipped on September 22; by September 23 operators were using pearcmd to drop shell tags and Nuclei templates were public. Fixed releases go back to 4.7.37 — verify the version on disk today.

Why it matters: Mass scanning plus a huge installed base is how “conditional RCE” becomes everyone’s problem. That forgotten marketing site is still production to an attacker.

See the patch list →

Also Worth Your Attention

Tomcat WebSocket lock can be walked around

CVE-2026-76183 (disclosed September 23) lets attackers evade security constraints on WebSocket endpoints via an alternate name. Upgrade to 11.0.26, 10.1.60, or 9.0.122; migrate off end-of-support 8.5/7.

Why it matters: Live consoles and admin UIs often put their real trust in that constraint.

Upgrade path →

Palo Alto says HIGHEST urgency — root risk on PA-Series

CVE-2026-0310 is an unauthenticated XML buffer overflow with vendor urgency HIGHEST. PA-Series faces root RCE; VM-Series mostly denial of service; Panorama is in scope. No known exploitation yet — use the window. Restrict management to a jump box and take the exact fixed builds.

Why it matters: Root on the firewall is policy, VPN, and the trust fabric.

Use the window →

SAP’s CVSS 10 kernel bug now has public PoCs

CVE-2026-44756 (Note 3747649) is pre-auth RCE via Extended Passport processing across HTTP, GUI, and RFC. S4GET (CVE-2026-58240) hits Message Server registration. The SAPMAP toolkit now includes proof-of-concept exploits — patch Internet-facing SAP first, then every internal app server.

Why it matters: Shared kernel code means the ERP estate inherits one bug many ways. Role checks will not save you — this runs before login.

PoC clock →

Slack paste: Patch WP Core today; inventory Tomcat WS; lock PAN-OS mgmt; OVERPASS on Internet-facing SAP.

Go Deeper

Related reading: Cybersecurity Tools · Cyber Attacks on Critical Infrastructure · Get the Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.