Security Digest: September 30, 2026 - 45 Critical Vulnerabilities
Today’s alert is dominated by remote code execution, authentication bypass, and command injection across enterprise middleware, AI services, SSH components, WordPress plugins, and widely used npm/PyPI packages. The most urgent risks are public-facing deserialization flaws and JWT verification bypasses that can turn a public key or misconfigured secret into full account takeover.
· 21 min read
Executive Summary
Today’s alert is dominated by remote code execution, authentication bypass, and command injection across enterprise middleware, AI services, SSH components, WordPress plugins, and widely used npm/PyPI packages. The most urgent risks are publicly exploitable deserialization flaws and JWT verification bypasses that can turn a public key or misconfigured secret into full account takeover.
Act now: patch exposed internet-facing services first, remove or isolate vulnerable components, and verify that your JWT, SSH, and archive-handling code paths do not match the affected patterns below.
Critical Vulnerabilities
- CVE-2026-102455: EasyFlow .NET insecure deserialization
- Impact: Unauthenticated attackers can execute code on the server.
- Affected Systems: Digiwin EasyFlow .NET.
- Immediate Action: Remove public access, rotate credentials, and patch or isolate the application immediately.
- Mitigation: Apply vendor fix as soon as available; block untrusted serialized content.
- CVE-2026-103041: LightLLM RPyC cache service RCE
- Impact: Remote code execution with service privileges.
- Affected Systems: LightLLM through 1.2.0 multimodal deployments exposing cache services.
- Immediate Action: Disable exposed cache/RPyC interfaces and restrict network access now.
- Mitigation: Upgrade and ensure pickle-based deserialization is not reachable.
- CVE-2026-103110: Pexip Infinity code execution
- Impact: Remote code execution as an unprivileged user.
- Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
- Immediate Action: Patch conferencing nodes and limit external exposure.
- Mitigation: Upgrade to a fixed release.
- CVE-2026-102458: EasyFlow .NET password disclosure
- Impact: Attackers can obtain plaintext passwords.
- Affected Systems: Digiwin EasyFlow .NET.
- Immediate Action: Assume credential exposure; force password resets and review API access.
- Mitigation: Patch and revoke exposed secrets.
- CVE-2026-102794: Ziroom ZHOME command injection
- Impact: Remote command execution via /api/ZRnetwork/ping.
- Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
- Immediate Action: Disconnect affected devices from untrusted networks.
- Mitigation: No vendor response reported; block the API and replace if possible.
- CVE-2026-94052: Apache MINA SSHD LDAP auth bypass
- Impact: Authentication checks can be bypassed in sshd-ldap deployments.
- Affected Systems: Apache MINA SSHD 1.2.0–2.19.0 and 3.0.0-M1 to M5 using LdapPasswordAuthenticator.
- Immediate Action: Upgrade immediately and disable sshd-ldap if not required.
- Mitigation: Move to 2.20.0 or 3.0.0-M6.
- CVE-2026-102793: Ziroom ZHOME time zone command injection
- Impact: Remote command execution through set_time_zone.
- Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
- Immediate Action: Block remote access to the management API.
- Mitigation: Replace or isolate until patched.
- CVE-2026-101894: decompress path escape
- Impact: Crafted archives can write outside the extraction directory, enabling RCE.
- Affected Systems: npm @xhmikosr/decompress and decompress.
- Immediate Action: Stop extracting untrusted archives on affected versions.
- Mitigation: Upgrade to 11.1.4 / 10.2.2 or migrate to @xhmikosr/decompress.
- CVE-2026-102268: PyJWT mixed-algorithm key confusion
- Impact: Public keys can be used to forge valid HS256 tokens.
- Affected Systems: pip PyJWT in misconfigured mixed HS*/asymmetric allow-lists.
- Immediate Action: Split symmetric and asymmetric verification paths now.
- Mitigation: Upgrade to PyJWT 2.14.0 and remove mixed algorithm allow-lists.
- CVE-2026-97196: GiveWP authentication bypass
- Impact: Attackers can bypass authentication.
- Affected Systems: GiveWP through 4.16.9.
- Immediate Action: Update the plugin and review admin access logs.
- Mitigation: Apply vendor patch and rotate privileged credentials.
- CVE-2026-77185: Apache MINA SSHD asynchronous auth bypass
- Impact: Public-key or hostbased authentication can be skipped in rare server implementations.
- Affected Systems: Apache MINA SSHD 2.0.0–2.19.0 and 3.0.0-M1 to M5 using async auth.
- Immediate Action: Disable asynchronous authentication paths and upgrade.
- Mitigation: Move to 2.20.0 or 3.0.0-M6.
- CVE-2026-94053: Apache MINA SSHD LDAP injection auth bypass
- Impact: Successful authentication with crafted username/password values.
- Affected Systems: sshd-ldap in Apache MINA SSHD 1.2.0–2.19.0 and 3.0.0-M1 to M5.
- Immediate Action: Patch and restrict LDAP-backed SSH auth.
- Mitigation: Upgrade to 2.20.0 or 3.0.0-M6.
- CVE-2026-102792: Ziroom ZHOME syslog command injection
- Impact: Remote command execution via set_syslog.
- Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
- Immediate Action: Block access and monitor for abuse.
- Mitigation: No confirmed vendor fix; isolate affected systems.
- CVE-2026-103056: AiSOC CrowdStrike RTR command injection
- Impact: Authenticated users can run arbitrary commands on managed endpoints.
- Affected Systems: AiSOC 7.2.0 through before 12.0.0.
- Immediate Action: Restrict privileged users and disable vulnerable action paths.
- Mitigation: Upgrade to 12.0.0 or later.
- CVE-2026-103105: Pexip internal API code execution
- Impact: Local attackers can execute arbitrary code on another node.
- Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
- Immediate Action: Limit node-to-node access and patch.
- Mitigation: Upgrade to a fixed release.
- CVE-2026-103101: Pexip web server denial of service
- Impact: A node can be rendered inaccessible.
- Affected Systems: Pexip Infinity 30.0 through 40.x before 41.0.
- Immediate Action: Patch and monitor node health.
- Mitigation: Upgrade to 41.0.
- CVE-2026-103102: Pexip signaling DoS
- Impact: Remote attacker can trigger a software abort.
- Affected Systems: Pexip Infinity before 41.0, via WebRTC/API gateway calls.
- Immediate Action: Restrict gateway exposure and patch.
- Mitigation: Upgrade to 41.0.
- CVE-2026-93994: Apache MINA SSHD duplicate-key auth bypass
- Impact: Users can satisfy two-key auth with one key twice.
- Affected Systems: Apache MINA SSHD up to 2.19.0 and 3.0.0-M1 to M5.
- Immediate Action: Upgrade and review multi-factor SSH policy.
- Mitigation: Move to 2.20.0 or 3.0.0-M6.
- CVE-2026-103106: Pexip privilege escalation
- Impact: Local privilege escalation to root.
- Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
- Immediate Action: Treat any node compromise as full environment compromise.
- Mitigation: Upgrade and reimage compromised nodes.
- CVE-2026-103111: PCRE2 out-of-bounds write
- Impact: Memory corruption when attacker controls regex and JIT usage.
- Affected Systems: PCRE2 before 10.49.
- Immediate Action: Disable attacker-controlled regex/JIT paths or upgrade.
- Mitigation: Patch to 10.49.
- CVE-2026-6806: Motors WordPress SQL injection
- Impact: Database extraction via unauthenticated SQL injection.
- Affected Systems: Motors plugin up to 1.4.109.
- Immediate Action: Update plugin and review database access.
- Mitigation: Apply vendor patch immediately.
- CVE-2026-103043: anchorme regex DoS
- Impact: Event-loop blocking denial of service.
- Affected Systems: anchorme through 3.0.8.
- Immediate Action: Sanitize untrusted input and patch.
- Mitigation: Upgrade to a fixed release.
- CVE-2026-102278: brace-expansion stack exhaustion
- Impact: Remote unauthenticated denial of service.
- Affected Systems: npm brace-expansion and downstream consumers.
- Immediate Action: Block untrusted glob patterns and upgrade dependencies.
- Mitigation: Apply package updates that add depth limits.
- CVE-2026-102599: Engine.IO transport upgrade crash
- Impact: Process crash via protocol mismatch.
- Affected Systems: engine.io 6.6.0 through 6.6.9.
- Immediate Action: Upgrade and consider disabling transport upgrades temporarily.
- Mitigation: Upgrade to 6.6.10 or later.
- CVE-2026-102281: NestJS microservices crash
- Impact: TCP/RabbitMQ messages can terminate the service.
- Affected Systems: @nestjs/microservices 12.0.0–12.0.1 and earlier than 11.2.4.
- Immediate Action: Restrict broker/port access immediately.
- Mitigation: Upgrade to 12.0.3 or 11.2.5.
- CVE-2026-102276: brace-expansion parser crash
- Impact: Stack exhaustion denial of service.
- Affected Systems: npm brace-expansion across multiple lines.
- Immediate Action: Patch and avoid untrusted brace patterns.
- Mitigation: Upgrade to the fixed release.
- CVE-2026-103055: AiSOC hard-coded JWT secret
- Impact: Unauthenticated attackers can forge realtime subscription tickets.
- Affected Systems: AiSOC 7.5.0 through before 12.0.0 when env secret is unset.
- Immediate Action: Set a unique secret immediately and rotate tickets.
- Mitigation: Upgrade and enforce secret provisioning.
- CVE-2026-103088: Handlebars.java path traversal
- Impact: File read outside template base; possible code execution in Spring MVC deployments.
- Affected Systems: handlebars-springmvc 4.5.3 and 4.5.4.
- Immediate Action: Block request-derived view names and patch.
- Mitigation: Upgrade to Handlebars.java 4.5.5 or later.
- CVE-2026-89294: Simply Schedule Appointments LFI
- Impact: Arbitrary PHP file inclusion and possible code execution.
- Affected Systems: WordPress plugin up to 1.6.12.27.
- Immediate Action: Remove public exposure and update plugin.
- Mitigation: Apply vendor patch and audit uploads.
- CVE-2026-75098: Product Designer App directory traversal
- Impact: Arbitrary file read.
- Affected Systems: WordPress plugin up to 1.1.3.
- Immediate Action: Disable the shortcode and patch.
- Mitigation: Update and rotate any exposed secrets.
- CVE-2026-94002: Apache MINA SSHD SFTP memory exhaustion
- Impact: Malicious servers can exhaust client memory.
- Affected Systems: sshd-sftp 0.9.0–2.19.0 and 3.0.0-M1 to M5.
- Immediate Action: Avoid connecting to untrusted SFTP servers.
- Mitigation: Upgrade to 2.20.0 or 3.0.0-M6.
- CVE-2026-102267: PyJWT JWKS redirect trust poisoning
- Impact: JWKS fetches can be redirected to an untrusted host.
- Affected Systems: pip PyJWT up to 2.13.0.
- Immediate Action: Pin JWKS endpoints and upgrade.
- Mitigation: Use PyJWT 2.14.0 and restrict redirects.
- CVE-2026-102266: PyJWT empty oct JWK acceptance
- Impact: HS256 tokens can be forged if an empty symmetric JWK is loaded.
- Affected Systems: pip PyJWT with empty oct JWKs.
- Immediate Action: Search for empty JWK secrets and replace them now.
- Mitigation: Upgrade to 2.14.0 and reject empty keys.
- CVE-2026-102271: PyJWT DER public key confusion
- Impact: Public DER keys can be used as HMAC secrets in mixed-algorithm configs.
- Affected Systems: pip pyjwt.
- Immediate Action: Stop passing raw public keys as bytes to JWT verification.
- Mitigation: Upgrade to 2.14.0 and separate algorithm families.
- CVE-2026-102272: PyJWT BOM-prefixed JWK bypass
- Impact: Algorithm confusion patch bypass can allow token forgery.
- Affected Systems: pip PyJWT 2.13.0.
- Immediate Action: Upgrade immediately and test all JWT call sites.
- Mitigation: Move to 2.14.0.
- CVE-2026-102273: PyJWT JWK container confusion
- Impact: Public JWK material in containers can be accepted as an HMAC secret.
- Affected Systems: pip PyJWT 2.13.0.
- Immediate Action: Audit raw JWK/JWKS handling and mixed algorithm use.
- Mitigation: Upgrade to 2.14.0.
- CVE-2026-102908: SourceCodester Online Reviewer SQL injection
- Impact: Remote SQL injection, possible data theft and code execution.
- Affected Systems: Online Reviewer Management System 1.0.
- Immediate Action: Remove public access and patch or replace.
- Mitigation: Apply vendor or community fix.
- CVE-2026-92873: Pgpool-II watchdog leader promotion flaw
- Impact: Unauthenticated attacker can promote an arbitrary watchdog node to leader.
- Affected Systems: Pgpool-II.
- Immediate Action: Restrict cluster access and patch immediately.
- Mitigation: Apply vendor update.
- CVE-2026-102910: SourceCodester exam delete SQL injection
- Impact: Remote SQL injection.
- Affected Systems: Online Reviewer Management System 1.0.
- Immediate Action: Disable exposed admin endpoints.
- Mitigation: Patch or retire the application.
- CVE-2026-102913: Car Driving School SQL injection
- Impact: Remote SQL injection.
- Affected Systems: Car Driving School Management System 1.0.
- Immediate Action: Restrict access and patch.
- Mitigation: Apply available fix.
- CVE-2026-102909: SourceCodester access_code SQL injection
- Impact: Remote SQL injection.
- Affected Systems: Online Reviewer Management System 1.0.
- Immediate Action: Block public access and review database permissions.
- Mitigation: Patch immediately.
- CVE-2026-96649: Frontend Post Submission Manager Lite XSS
- Impact: Stored script execution in visitors’ browsers.
- Affected Systems: WordPress plugin up to 1.3.4.
- Immediate Action: Disable guest submissions if enabled and patch.
- Mitigation: Update plugin and clear cached content.
- CVE-2026-97347: Post Views Stats Counter XSS
- Impact: Stored XSS via User-Agent header.
- Affected Systems: WordPress plugin up to 1.1.7.
- Immediate Action: Patch and inspect logs for malicious User-Agent strings.
- Mitigation: Update plugin immediately.
- CVE-2026-103054: AiSOC tenant authorization bypass
- Impact: Authenticated users can add arbitrary tenants and read their data.
- Affected Systems: AiSOC before 12.0.0.
- Immediate Action: Review tenant membership changes and restrict endpoint access.
- Mitigation: Upgrade and audit portfolios.
Previously Alerted
What to Do Now
- Patch internet-facing systems first: Pexip, Apache MINA SSHD deployments, PyJWT consumers, LightLLM, EasyFlow .NET, Ziroom ZHOME, AiSOC, and vulnerable WordPress plugins.
- Disable or isolate risky interfaces: RPyC/pickle services, LDAP-backed SSH auth, transport upgrades, public archive extraction, and exposed admin/API endpoints.
- Assume credential exposure where password disclosure or JWT bypass is possible; rotate secrets, API keys, and admin passwords immediately.
- Review logs for exploitation: unexpected deserialization errors, forged JWTs, command-injection payloads, LDAP wildcard auth, and repeated SQLi/XSS probes.
- Verify package versions in CI/CD and production lockfiles; upgrade vulnerable npm and PyPI dependencies before the next deploy.
Verification steps: confirm patched versions, remove mixed HS*/asymmetric JWT verification, test that archive extraction rejects symlink escapes, and validate SSH/LDAP and microservice transports are not exposed to untrusted networks.
Monitoring recommendations: alert on new admin sessions, unusual outbound callbacks from AI and conferencing nodes, abrupt Node.js process exits, and any use of public-key material in HMAC verification paths.
Related Resources
- Internal blog post on JWT hardening and key separation — planned.
- Internal blog post on safe archive extraction and symlink defenses — planned.
- Official vendor advisories for PyJWT, Apache MINA SSHD, Pexip, Engine.IO, NestJS, and WordPress plugins.