Published: 09/24/26
Thursday’s brief opens on the public web’s soft underbelly: attackers moved from probing to writing PHP on unpatched WordPress hosts in under a day. Also on the desk — Tomcat’s WebSocket lock you can walk around, Palo Alto’s highest-urgency firewall bug that still needs a deliberate upgrade pass, and SAP’s OVERPASS kernel flaw now shipping with public proof-of-concept code.
Lead Story
WordPress under active attack — patch Core before Friday
CVE-2026-87902 lets an unauthenticated attacker include a local PHP file via page-template resolution. Patchstack watched reconnaissance start hours after 7.1.2 shipped on September 22; by September 23 operators were using pearcmd to drop shell tags and Nuclei templates were public. Fixed releases go back to 4.7.37 — verify the version on disk today.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Mass scanning plus a huge installed base is how “conditional RCE” becomes everyone’s problem. That forgotten marketing site is still production to an attacker.
Also Worth Your Attention
Tomcat WebSocket lock can be walked around
CVE-2026-76183 (disclosed September 23) lets attackers evade security constraints on WebSocket endpoints via an alternate name. Upgrade to 11.0.26, 10.1.60, or 9.0.122; migrate off end-of-support 8.5/7.
Why it matters: Live consoles and admin UIs often put their real trust in that constraint.
Palo Alto says HIGHEST urgency — root risk on PA-Series
CVE-2026-0310 is an unauthenticated XML buffer overflow with vendor urgency HIGHEST. PA-Series faces root RCE; VM-Series mostly denial of service; Panorama is in scope. No known exploitation yet — use the window. Restrict management to a jump box and take the exact fixed builds.
Why it matters: Root on the firewall is policy, VPN, and the trust fabric.
SAP’s CVSS 10 kernel bug now has public PoCs
CVE-2026-44756 (Note 3747649) is pre-auth RCE via Extended Passport processing across HTTP, GUI, and RFC. S4GET (CVE-2026-58240) hits Message Server registration. The SAPMAP toolkit now includes proof-of-concept exploits — patch Internet-facing SAP first, then every internal app server.
Why it matters: Shared kernel code means the ERP estate inherits one bug many ways. Role checks will not save you — this runs before login.
Slack paste: Patch WP Core today; inventory Tomcat WS; lock PAN-OS mgmt; OVERPASS on Internet-facing SAP.
Go Deeper
Related reading: Cybersecurity Tools · Cyber Attacks on Critical Infrastructure · Get the Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.