ZeroHour

Search: “US”

6 stories in the last 24h

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Attackers actively exploit CVE-2026-89026, a hard-coded JWT key flaw enabling unauthenticated OS command execution on Issabel PBX systems.

VulnCheck reported active exploitation of CVE-2026-89026 (CVSS v3.1 9.8) in Issabel Framework, the web framework for the open-source Issabel unified communications PBX. A hard-coded HS256 JWT signing key identical across every installation lets unauthenticated attackers forge bearer tokens and abuse the /pbxapi/manager/originate endpoint, causing Asterisk to execute arbitrary OS commands as the Asterisk user. A patch replacing the hard-coded key with one stored in /etc/issabel.conf shipped August 1, 2026, and the Shadowserver Foundation first observed exploitation on September 9, 2026. Details on real-world abuse, attribution, and scale remain unknown.

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google's September Pixel update patches CVE-2026-58704, a high-severity cellular modem privilege escalation flaw showing signs of limited targeted exploitation.

Google disclosed CVE-2026-58704 (CVSS 8.0), a privilege escalation flaw in the Pixel Cellular Modem caused by a logic error permitting proximal/adjacent privilege escalation with no user interaction or extra privileges needed. Google acknowledged indications the flaw may be under limited, targeted exploitation but did not identify the threat actor. The September 2026 Pixel update fixes 109 additional flaws, including 46 critical-severity issues in components such as BigOcean, Bootloader, IMS, and Trusted Execution Environment, plus two high-severity kernel privilege escalation bugs (CVE-2026-56914, CVE-2026-58773). Security patch level 2026-09-05 or later resolves all identified flaws.

The Hacker Newsupdated · 2h agofirst · 6h agoExploit / PoC in the wild 7 sourcesCVE-2026-58704CVE-2026-56914CVE-2026-58773+1 CVEs

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis warns CVE-2026-87886, a local privilege escalation flaw in its cPanel/WHM and Plesk backup plugins, is exploited in targeted attacks.

Acronis disclosed CVE-2026-87886 (CVSS 7.8), a high-severity local privilege escalation caused by insecure file permissions in its Backup plugin for cPanel & WHM and Backup extension for Plesk on Linux. Affected versions include cPanel & WHM plugin builds before 1.9.3.1021 (fixed in 1.9.3 HF3) and Plesk extension builds before 1.8.11.638. A low-privileged attacker could escalate permissions and potentially run arbitrary code, impacting confidentiality and integrity of the application. Acronis says exploitation has been detected in the wild in limited, targeted attacks, but has not identified the attackers, timing, or objectives.

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells; Wordfence blocked 100,000+ attempts since June 2026.

Wordfence reports active exploitation of CVE-2026-27540 (CVSS 9.8), an unauthenticated arbitrary file upload in the wwlc_file_upload_handler AJAX action of the WooCommerce Wholesale Lead Capture plugin (versions through 2.0.3.1, 6,000+ installs), enabling remote code execution via uploaded PHP web shells. Over 100,000 exploit attempts were blocked since June 2026, including 99 in the last 24 hours, traced to ten listed IP addresses. Separately, two critical flaws (CVE-2026-78159 and CVE-2026-78006) in The Events Calendar, installed on 600,000+ sites, allow unauthenticated RCE and full site takeover via PHP object injection chains. StellarWP patched the affected plugin versions 6.17.3 and 6.17.4 in releases 6.17.3.1 and 6.17.4.1.

The Hacker Newsupdated · 2h agofirst · 11h agoExploit / PoC in the wild 6 sourcesCVE-2026-27540CVE-2026-78159CVE-2026-78006

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

watchTowr observed active exploitation of CVE-2026-5430, a WSO2 API Manager JWT bypass using forged admin tokens, risking credential theft and account takeover.

CVE-2026-5430 (CVSS 9.8-10.0), an improper cryptographic signature verification flaw in WSO2 API Manager, lets JWT authentication be bypassed with unsupported algorithms, enabling administrative account takeover. watchTowr honeypots captured forged JWT tokens with baked-in administrator privileges on September 13, 2026, which could expose API credentials, consumer keys, and secrets for every registered application. Affected products include WSO2 API Manager 4.1.0-4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Fixes are available via GitHub pull requests and subscription update levels, and users are urged to patch immediately.

The Hacker Newsupdated · 2h agofirst · 12h agoExploit / PoC in the wild 3 sourcesCVE-2026-5430

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 lets crafted emails trigger SQL injection and root command execution; CISA added it to KEV.

Cisco released emergency patches for CVE-2026-76461, a critical SQL injection in Secure Email Gateway (physical and virtual) caused by insufficient validation in email parsing. Sending a crafted email with malicious SQL statements can yield arbitrary command execution with root privileges. Cisco was aware of active exploitation before the fixes, and CISA added the flaw to its KEV catalog; patched AsyncOS releases are 15.5.5-0141, 16.0.4-3021, and 16.5.0-780. Because successful exploits grant root, Cisco warns logs may be tampered with and advises checking external firewall/network logs and rebuilding virtual appliances with rotated credentials.

CSO Onlineupdated · 3h agofirst · 21h agoExploit / PoC in the wild 17 sourcesCVE-2026-76461CVE-2025-20393