ZeroHour

Search: “container”

5 stories in the last 24h

Scans Targeting Hospitality Applications, (Wed, Sep 16th)

Scans from a bulletproof-hosting IP target the abandoned PIAF-HMS hospitality application, which contains numerous unpatched SQL injection flaws.

SANS ISC observed requests for /PIAF-HMS/ using the unusual user-agent Farez-Sorter/1.0, along with paths like /admin/, /ucp/, /hms/, and /hotel/, starting September 15 from the single source IP 94.102.49.125 (IP Volume, AS202425, a bulletproof hoster). PIAF-HMS, a PBX in a Flash Hospitality Management System, was last updated 10 years ago and a SQL injection vulnerability was reported recently; the code shows many injection flaws and lacks authentication and access control. The handler notes hotels are soft targets for personal data theft and guest MitM attacks, and asks for community insight on the campaign.

Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild

Unauthenticated attackers exploit CVE-2026-89026 in Issabel PBX via forged JWT tokens to run OS commands; exploitation observed since September 9.

CVE-2026-89026 (CVSS v4 9.3) stems from a hard-coded HS256 JWT signing key in Issabel Framework's pbxapi/index.php, letting unauthenticated attackers forge bearer tokens and execute OS commands through the Asterisk Manager Interface originate endpoint. Issabel Framework versions before commit b97dbaf0b71c1c36f841e672b664afbeb02773bd are affected. Shadowserver Foundation first observed exploitation on September 9, 2026, and VulnCheck added the flaw to its Known Exploited Vulnerabilities database.

Cyber Security Newsupdated · 6h agofirst · 8h agoExploit / PoC in the wild 2 sourcesCVE-2026-890261

Critical ScreenConnect flaw now actively exploited in attacks

CISA confirms active exploitation of critical ConnectWise ScreenConnect flaw CVE-2026-84869, ordering federal agencies to mitigate within three days.

ConnectWise's ScreenConnect flaw CVE-2026-84869, an improper privilege management and missing authorization bug, lets attackers with basic privileges transfer or execute files through active remote sessions in low-complexity attacks without user interaction. It is patched in ScreenConnect 26.6.5; CISA added it to the KEV catalog and ordered US federal agencies to secure systems within three days. Shadowserver tracks over 1,000 unpatched exposed instances, mostly in North America (758) and Europe (180). This is the fourth actively exploited ScreenConnect flaw since 2024; earlier issues were abused by Kimsuky and ransomware gangs.

BleepingComputerupdated · 6h agofirst · 10h agoExploit / PoC in the wild 4 sourcesCVE-2026-84869CVE-2024-1709CVE-2025-3935+1 CVEs1

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis warns CVE-2026-87886, a local privilege escalation flaw in its cPanel/WHM and Plesk backup plugins, is exploited in targeted attacks.

Acronis disclosed CVE-2026-87886 (CVSS 7.8), a high-severity local privilege escalation caused by insecure file permissions in its Backup plugin for cPanel & WHM and Backup extension for Plesk on Linux. Affected versions include cPanel & WHM plugin builds before 1.9.3.1021 (fixed in 1.9.3 HF3) and Plesk extension builds before 1.8.11.638. A low-privileged attacker could escalate permissions and potentially run arbitrary code, impacting confidentiality and integrity of the application. Acronis says exploitation has been detected in the wild in limited, targeted attacks, but has not identified the attackers, timing, or objectives.

Apache Superset SQL Injection Flaw Gets Public PoC Exploit

A public Python proof-of-concept exploit was released for CVE-2026-23980, an authenticated error-based SQL injection flaw in Apache Superset before 6.0.0.

A public proof-of-concept exploit repository now targets CVE-2026-23980, an error-based SQL injection affecting Apache Superset versions from 0.0.0 up to but not including 6.0.0. An authenticated user with read access can inject SQL through the sqlExpression or where parameters, potentially reaching business, customer, and security data depending on database configuration and privileges. Apache disclosed the flaw in February and urges upgrading to Superset 6.0.0; compensating controls include least-privilege database accounts, network restrictions, and log monitoring.