Security Digest: September 28, 2026 - 23 Critical Vulnerabilities
Today’s threat picture is urgent: 23 critical vulnerabilities are now public, including multiple remote code execution, command injection, SSRF, SQL injection, authentication bypass, and XXE flaws. Several have public exploits, and multiple vendors have not responded, which raises the risk of active abuse.
· 13 min read
Executive Summary
Today’s threat picture is urgent: 23 critical vulnerabilities are now public, including multiple remote code execution, command injection, SSRF, SQL injection, authentication bypass, and XXE flaws. Several have public exploits, and multiple vendors have not responded, which raises the risk of active abuse.
Action required now: prioritize internet-facing appliances and web apps first, patch Apache Roller immediately, and isolate or disable exposed management interfaces until updates are confirmed.
Critical Vulnerabilities
- CVE-2026-100886: Seetong Debug Service improper authentication
- Impact: Remote attacker may gain unauthorized access; exploit is publicly available.
- Affected Systems: Seetong T8108, T8108P, T8116, T8232 4.6.1.4-build202604241011
- Immediate Action: Remove internet exposure, restrict access to trusted networks only, and treat devices as high risk.
- Mitigation: Apply vendor patch if/when available; if no fix exists, isolate or replace the device.
- CVE-2026-101001: Netcore NBR200V2 command injection in Web Management Interface
- Impact: Remote code execution via crafted requests.
- Affected Systems: Netcore NBR200V2 1.3.241127.071246
- Immediate Action: Disable WAN access to the admin UI and block the affected endpoint at the perimeter.
- Mitigation: Patch from vendor when available; until then, segment and restrict management traffic.
- CVE-2026-101000: Netcore NBR100V2 missing authorization in ACL handler
- Impact: Unauthenticated remote access to restricted functions.
- Affected Systems: Netcore NBR100V2 1.3.240614.030928
- Immediate Action: Remove public access and review for unauthorized configuration changes.
- Mitigation: Apply vendor remediation if released; otherwise isolate the device.
- CVE-2026-100896: TOTOLINK N150RT command injection
- Impact: Remote command execution through the web interface.
- Affected Systems: TOTOLINK N150RT 3.4.0-B20201030
- Immediate Action: Take the router off the internet and disable remote management.
- Mitigation: Replace or patch; assume compromise if exposed.
- CVE-2026-101002: Netcore NBR200V2 command injection in Ping handler
- Impact: Remote command execution.
- Affected Systems: Netcore NBR200V2 1.3.241127.071246
- Immediate Action: Block access to network tools and admin interfaces immediately.
- Mitigation: Vendor update required; use network isolation until fixed.
- CVE-2026-82377: Apache Roller missing authorization in XML-RPC APIs
- Impact: Authenticated users can read, modify, or delete other weblog content.
- Affected Systems: Apache Roller 6.1.5 with global XML-RPC enabled
- Immediate Action: Disable XML-RPC now if enabled.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82384: Apache Roller XML-RPC deserialization leading to RCE
- Impact: Unauthenticated remote code execution.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Treat as emergency; disable exposure and patch immediately.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later; block XML-RPC traffic at the edge.
- CVE-2026-101008: aaPanel BaoTa file merge command injection
- Impact: Remote command execution.
- Affected Systems: aaPanel BaoTa up to 11.8.0
- Immediate Action: Restrict panel access to trusted IPs only.
- Mitigation: Apply vendor fix when available; otherwise isolate the panel.
- CVE-2026-82378: Apache Roller OAuth token binding flaw
- Impact: Attackers can bind a request token to an arbitrary account, including admin.
- Affected Systems: Apache Roller 6.1.5 with site-wide OAuth 1.0a consumer enabled
- Immediate Action: Disable site-wide OAuth consumers unless required.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-85134: Bimser EBA Plus dangerous file upload
- Impact: Web shell upload and potential full server compromise.
- Affected Systems: eBA Plus Document and Workflow Management System 6.7.141 through before 10.0.11
- Immediate Action: Block upload paths and review for suspicious files.
- Mitigation: Upgrade to 10.0.11 or later.
- CVE-2026-82383: Apache Roller missing authentication for global configuration change
- Impact: Unauthenticated attacker can alter site-global frontpage settings.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Restrict access to setup actions immediately.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82380: Apache Roller CSRF
- Impact: Logged-in users can be tricked into unintended state changes.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Force re-authentication for privileged users and limit admin browsing.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82379: Apache Roller WSSE replay authentication bypass
- Impact: Captured auth headers can be replayed to gain AtomPub access.
- Affected Systems: Apache Roller 6.1.5 with non-default WSSE AtomPub auth
- Immediate Action: Disable WSSE authentication now.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82376: Apache Roller XXE in trackback parser
- Impact: File disclosure from the server and possible internal recon.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Restrict weblog editing rights and monitor for XML parsing activity.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82348: Apache Roller authorization bypass via user-controlled key
- Impact: Cross-weblog data tampering and possible template overwrite leading to code execution.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Audit weblog isolation and template integrity now.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82386: Apache Roller XXE in OPML import
- Impact: File disclosure and potential internal network access.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Disable OPML import until patched.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-82375: Apache Roller SSRF via Trackback/enclosure handling
- Impact: Outbound requests to attacker-chosen destinations, including loopback/private IPs.
- Affected Systems: Apache Roller 6.1.5
- Immediate Action: Block server egress to internal ranges where possible.
- Mitigation: Upgrade to Apache Roller 6.1.6 or later.
- CVE-2026-101012: CloudClassroom SQL injection in makeresult.php
- Impact: Remote database compromise.
- Affected Systems: CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be
- Immediate Action: WAF block suspicious queries and review database access logs.
- Mitigation: Apply vendor fix if available; otherwise remove from public exposure.
- CVE-2026-100885: Krayin laravel-crm authorization bypass
- Impact: Remote unauthorized access to admin-config setup.
- Affected Systems: Krayin laravel-crm up to 2.2.4
- Immediate Action: Upgrade immediately and restrict admin setup endpoints.
- Mitigation: Update to 2.2.5.
- CVE-2026-100893: VoceChat SSRF in open_graphic_parse
- Impact: Server-side request forgery to internal or external targets.
- Affected Systems: Privoce VoceChat Server up to 0.5.36
- Immediate Action: Restrict outbound access and disable the endpoint if possible.
- Mitigation: Patch to a fixed release when provided.
- CVE-2026-101013: CloudClassroom SQL injection in updateresultdetails.php
- Impact: Remote database compromise.
- Affected Systems: CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be
- Immediate Action: Treat as active risk; inspect for tampered records.
- Mitigation: Apply vendor remediation; no versioned release guidance is available.
- CVE-2026-100901: youtube-downloader SSRF in public/stream.php
- Impact: Remote requests to attacker-chosen destinations.
- Affected Systems: athlon1600 youtube-downloader up to 4.0.1
- Immediate Action: Restrict outbound connectivity and block public access to stream.php.
- Mitigation: Update if a fixed version is released; current hardening is insufficient.
- CVE-2026-100909: OctoberCMS SSRF in image resize path
- Impact: Remote request forgery through image processing.
- Affected Systems: OctoberCMS up to 4.1.19 / 4.2.25 / 4.3.4
- Immediate Action: Upgrade immediately; block untrusted image URLs.
- Mitigation: Move to 4.3.5 or 4.4.0.
Previously Alerted
- CVE-2026-101037: Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch Apache Roller first across every instance. If you run 6.1.5, assume exposure until 6.1.6 or later is installed.
- Disable or restrict internet-facing admin panels for routers, panels, and CMS platforms listed above.
- Block risky endpoints at the edge such as XML-RPC, upload handlers, stream/proxy functions, and setup actions.
- Review logs for exploitation including command execution, unusual outbound requests, anonymous admin actions, and unexpected file uploads.
- Isolate any unpatched system that cannot be updated today.
Verification steps:
- Confirm installed versions against the affected ranges.
- Check whether XML-RPC, WSSE, OAuth 1.0a, OPML import, Trackback, and remote management are enabled.
- Validate that WAF and firewall rules block the affected URLs and outbound destinations.
Monitoring recommendations:
- Watch for new admin users, config changes, and template edits.
- Alert on outbound connections to private IP ranges and localhost.
- Look for web shells, suspicious uploads, and repeated failed authentication attempts.
Related Resources
- Internal blog posts: planned coverage on Apache Roller, router appliance exposure, and SSRF detection.
- Official vendor advisories: check vendor security pages and release notes for each product listed above.