Security Digest: September 30, 2026 - 45 Critical Vulnerabilities

Today’s alert is dominated by remote code execution, authentication bypass, and command injection across enterprise middleware, AI services, SSH components, WordPress plugins, and widely used npm/PyPI packages. The most urgent risks are public-facing deserialization flaws and JWT verification bypasses that can turn a public key or misconfigured secret into full account takeover.

· 21 min read

Executive Summary

Today’s alert is dominated by remote code execution, authentication bypass, and command injection across enterprise middleware, AI services, SSH components, WordPress plugins, and widely used npm/PyPI packages. The most urgent risks are publicly exploitable deserialization flaws and JWT verification bypasses that can turn a public key or misconfigured secret into full account takeover.

Act now: patch exposed internet-facing services first, remove or isolate vulnerable components, and verify that your JWT, SSH, and archive-handling code paths do not match the affected patterns below.

Critical Vulnerabilities

  • CVE-2026-102455: EasyFlow .NET insecure deserialization
    • Impact: Unauthenticated attackers can execute code on the server.
    • Affected Systems: Digiwin EasyFlow .NET.
    • Immediate Action: Remove public access, rotate credentials, and patch or isolate the application immediately.
    • Mitigation: Apply vendor fix as soon as available; block untrusted serialized content.
  • CVE-2026-103041: LightLLM RPyC cache service RCE
    • Impact: Remote code execution with service privileges.
    • Affected Systems: LightLLM through 1.2.0 multimodal deployments exposing cache services.
    • Immediate Action: Disable exposed cache/RPyC interfaces and restrict network access now.
    • Mitigation: Upgrade and ensure pickle-based deserialization is not reachable.
  • CVE-2026-103110: Pexip Infinity code execution
    • Impact: Remote code execution as an unprivileged user.
    • Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
    • Immediate Action: Patch conferencing nodes and limit external exposure.
    • Mitigation: Upgrade to a fixed release.
  • CVE-2026-102458: EasyFlow .NET password disclosure
    • Impact: Attackers can obtain plaintext passwords.
    • Affected Systems: Digiwin EasyFlow .NET.
    • Immediate Action: Assume credential exposure; force password resets and review API access.
    • Mitigation: Patch and revoke exposed secrets.
  • CVE-2026-102794: Ziroom ZHOME command injection
    • Impact: Remote command execution via /api/ZRnetwork/ping.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Disconnect affected devices from untrusted networks.
    • Mitigation: No vendor response reported; block the API and replace if possible.
  • CVE-2026-94052: Apache MINA SSHD LDAP auth bypass
    • Impact: Authentication checks can be bypassed in sshd-ldap deployments.
    • Affected Systems: Apache MINA SSHD 1.2.0–2.19.0 and 3.0.0-M1 to M5 using LdapPasswordAuthenticator.
    • Immediate Action: Upgrade immediately and disable sshd-ldap if not required.
    • Mitigation: Move to 2.20.0 or 3.0.0-M6.
  • CVE-2026-102793: Ziroom ZHOME time zone command injection
    • Impact: Remote command execution through set_time_zone.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Block remote access to the management API.
    • Mitigation: Replace or isolate until patched.
  • CVE-2026-101894: decompress path escape
    • Impact: Crafted archives can write outside the extraction directory, enabling RCE.
    • Affected Systems: npm @xhmikosr/decompress and decompress.
    • Immediate Action: Stop extracting untrusted archives on affected versions.
    • Mitigation: Upgrade to 11.1.4 / 10.2.2 or migrate to @xhmikosr/decompress.
  • CVE-2026-102268: PyJWT mixed-algorithm key confusion
    • Impact: Public keys can be used to forge valid HS256 tokens.
    • Affected Systems: pip PyJWT in misconfigured mixed HS*/asymmetric allow-lists.
    • Immediate Action: Split symmetric and asymmetric verification paths now.
    • Mitigation: Upgrade to PyJWT 2.14.0 and remove mixed algorithm allow-lists.
  • CVE-2026-97196: GiveWP authentication bypass
    • Impact: Attackers can bypass authentication.
    • Affected Systems: GiveWP through 4.16.9.
    • Immediate Action: Update the plugin and review admin access logs.
    • Mitigation: Apply vendor patch and rotate privileged credentials.
  • CVE-2026-77185: Apache MINA SSHD asynchronous auth bypass
    • Impact: Public-key or hostbased authentication can be skipped in rare server implementations.
    • Affected Systems: Apache MINA SSHD 2.0.0–2.19.0 and 3.0.0-M1 to M5 using async auth.
    • Immediate Action: Disable asynchronous authentication paths and upgrade.
    • Mitigation: Move to 2.20.0 or 3.0.0-M6.
  • CVE-2026-94053: Apache MINA SSHD LDAP injection auth bypass
    • Impact: Successful authentication with crafted username/password values.
    • Affected Systems: sshd-ldap in Apache MINA SSHD 1.2.0–2.19.0 and 3.0.0-M1 to M5.
    • Immediate Action: Patch and restrict LDAP-backed SSH auth.
    • Mitigation: Upgrade to 2.20.0 or 3.0.0-M6.
  • CVE-2026-102792: Ziroom ZHOME syslog command injection
    • Impact: Remote command execution via set_syslog.
    • Affected Systems: Ziroom ZHOME A0101 1.0.1.0.
    • Immediate Action: Block access and monitor for abuse.
    • Mitigation: No confirmed vendor fix; isolate affected systems.
  • CVE-2026-103056: AiSOC CrowdStrike RTR command injection
    • Impact: Authenticated users can run arbitrary commands on managed endpoints.
    • Affected Systems: AiSOC 7.2.0 through before 12.0.0.
    • Immediate Action: Restrict privileged users and disable vulnerable action paths.
    • Mitigation: Upgrade to 12.0.0 or later.
  • CVE-2026-103105: Pexip internal API code execution
    • Impact: Local attackers can execute arbitrary code on another node.
    • Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
    • Immediate Action: Limit node-to-node access and patch.
    • Mitigation: Upgrade to a fixed release.
  • CVE-2026-103101: Pexip web server denial of service
    • Impact: A node can be rendered inaccessible.
    • Affected Systems: Pexip Infinity 30.0 through 40.x before 41.0.
    • Immediate Action: Patch and monitor node health.
    • Mitigation: Upgrade to 41.0.
  • CVE-2026-103102: Pexip signaling DoS
    • Impact: Remote attacker can trigger a software abort.
    • Affected Systems: Pexip Infinity before 41.0, via WebRTC/API gateway calls.
    • Immediate Action: Restrict gateway exposure and patch.
    • Mitigation: Upgrade to 41.0.
  • CVE-2026-93994: Apache MINA SSHD duplicate-key auth bypass
    • Impact: Users can satisfy two-key auth with one key twice.
    • Affected Systems: Apache MINA SSHD up to 2.19.0 and 3.0.0-M1 to M5.
    • Immediate Action: Upgrade and review multi-factor SSH policy.
    • Mitigation: Move to 2.20.0 or 3.0.0-M6.
  • CVE-2026-103106: Pexip privilege escalation
    • Impact: Local privilege escalation to root.
    • Affected Systems: Pexip Infinity before 38.2, plus 39.0, 39.1, 40.0.
    • Immediate Action: Treat any node compromise as full environment compromise.
    • Mitigation: Upgrade and reimage compromised nodes.
  • CVE-2026-103111: PCRE2 out-of-bounds write
    • Impact: Memory corruption when attacker controls regex and JIT usage.
    • Affected Systems: PCRE2 before 10.49.
    • Immediate Action: Disable attacker-controlled regex/JIT paths or upgrade.
    • Mitigation: Patch to 10.49.
  • CVE-2026-6806: Motors WordPress SQL injection
    • Impact: Database extraction via unauthenticated SQL injection.
    • Affected Systems: Motors plugin up to 1.4.109.
    • Immediate Action: Update plugin and review database access.
    • Mitigation: Apply vendor patch immediately.
  • CVE-2026-103043: anchorme regex DoS
    • Impact: Event-loop blocking denial of service.
    • Affected Systems: anchorme through 3.0.8.
    • Immediate Action: Sanitize untrusted input and patch.
    • Mitigation: Upgrade to a fixed release.
  • CVE-2026-102278: brace-expansion stack exhaustion
    • Impact: Remote unauthenticated denial of service.
    • Affected Systems: npm brace-expansion and downstream consumers.
    • Immediate Action: Block untrusted glob patterns and upgrade dependencies.
    • Mitigation: Apply package updates that add depth limits.
  • CVE-2026-102599: Engine.IO transport upgrade crash
    • Impact: Process crash via protocol mismatch.
    • Affected Systems: engine.io 6.6.0 through 6.6.9.
    • Immediate Action: Upgrade and consider disabling transport upgrades temporarily.
    • Mitigation: Upgrade to 6.6.10 or later.
  • CVE-2026-102281: NestJS microservices crash
    • Impact: TCP/RabbitMQ messages can terminate the service.
    • Affected Systems: @nestjs/microservices 12.0.0–12.0.1 and earlier than 11.2.4.
    • Immediate Action: Restrict broker/port access immediately.
    • Mitigation: Upgrade to 12.0.3 or 11.2.5.
  • CVE-2026-102276: brace-expansion parser crash
    • Impact: Stack exhaustion denial of service.
    • Affected Systems: npm brace-expansion across multiple lines.
    • Immediate Action: Patch and avoid untrusted brace patterns.
    • Mitigation: Upgrade to the fixed release.
  • CVE-2026-103055: AiSOC hard-coded JWT secret
    • Impact: Unauthenticated attackers can forge realtime subscription tickets.
    • Affected Systems: AiSOC 7.5.0 through before 12.0.0 when env secret is unset.
    • Immediate Action: Set a unique secret immediately and rotate tickets.
    • Mitigation: Upgrade and enforce secret provisioning.
  • CVE-2026-103088: Handlebars.java path traversal
    • Impact: File read outside template base; possible code execution in Spring MVC deployments.
    • Affected Systems: handlebars-springmvc 4.5.3 and 4.5.4.
    • Immediate Action: Block request-derived view names and patch.
    • Mitigation: Upgrade to Handlebars.java 4.5.5 or later.
  • CVE-2026-89294: Simply Schedule Appointments LFI
    • Impact: Arbitrary PHP file inclusion and possible code execution.
    • Affected Systems: WordPress plugin up to 1.6.12.27.
    • Immediate Action: Remove public exposure and update plugin.
    • Mitigation: Apply vendor patch and audit uploads.
  • CVE-2026-75098: Product Designer App directory traversal
    • Impact: Arbitrary file read.
    • Affected Systems: WordPress plugin up to 1.1.3.
    • Immediate Action: Disable the shortcode and patch.
    • Mitigation: Update and rotate any exposed secrets.
  • CVE-2026-94002: Apache MINA SSHD SFTP memory exhaustion
    • Impact: Malicious servers can exhaust client memory.
    • Affected Systems: sshd-sftp 0.9.0–2.19.0 and 3.0.0-M1 to M5.
    • Immediate Action: Avoid connecting to untrusted SFTP servers.
    • Mitigation: Upgrade to 2.20.0 or 3.0.0-M6.
  • CVE-2026-102267: PyJWT JWKS redirect trust poisoning
    • Impact: JWKS fetches can be redirected to an untrusted host.
    • Affected Systems: pip PyJWT up to 2.13.0.
    • Immediate Action: Pin JWKS endpoints and upgrade.
    • Mitigation: Use PyJWT 2.14.0 and restrict redirects.
  • CVE-2026-102266: PyJWT empty oct JWK acceptance
    • Impact: HS256 tokens can be forged if an empty symmetric JWK is loaded.
    • Affected Systems: pip PyJWT with empty oct JWKs.
    • Immediate Action: Search for empty JWK secrets and replace them now.
    • Mitigation: Upgrade to 2.14.0 and reject empty keys.
  • CVE-2026-102271: PyJWT DER public key confusion
    • Impact: Public DER keys can be used as HMAC secrets in mixed-algorithm configs.
    • Affected Systems: pip pyjwt.
    • Immediate Action: Stop passing raw public keys as bytes to JWT verification.
    • Mitigation: Upgrade to 2.14.0 and separate algorithm families.
  • CVE-2026-102272: PyJWT BOM-prefixed JWK bypass
    • Impact: Algorithm confusion patch bypass can allow token forgery.
    • Affected Systems: pip PyJWT 2.13.0.
    • Immediate Action: Upgrade immediately and test all JWT call sites.
    • Mitigation: Move to 2.14.0.
  • CVE-2026-102273: PyJWT JWK container confusion
    • Impact: Public JWK material in containers can be accepted as an HMAC secret.
    • Affected Systems: pip PyJWT 2.13.0.
    • Immediate Action: Audit raw JWK/JWKS handling and mixed algorithm use.
    • Mitigation: Upgrade to 2.14.0.
  • CVE-2026-102908: SourceCodester Online Reviewer SQL injection
    • Impact: Remote SQL injection, possible data theft and code execution.
    • Affected Systems: Online Reviewer Management System 1.0.
    • Immediate Action: Remove public access and patch or replace.
    • Mitigation: Apply vendor or community fix.
  • CVE-2026-92873: Pgpool-II watchdog leader promotion flaw
    • Impact: Unauthenticated attacker can promote an arbitrary watchdog node to leader.
    • Affected Systems: Pgpool-II.
    • Immediate Action: Restrict cluster access and patch immediately.
    • Mitigation: Apply vendor update.
  • CVE-2026-102910: SourceCodester exam delete SQL injection
    • Impact: Remote SQL injection.
    • Affected Systems: Online Reviewer Management System 1.0.
    • Immediate Action: Disable exposed admin endpoints.
    • Mitigation: Patch or retire the application.
  • CVE-2026-102913: Car Driving School SQL injection
    • Impact: Remote SQL injection.
    • Affected Systems: Car Driving School Management System 1.0.
    • Immediate Action: Restrict access and patch.
    • Mitigation: Apply available fix.
  • CVE-2026-102909: SourceCodester access_code SQL injection
    • Impact: Remote SQL injection.
    • Affected Systems: Online Reviewer Management System 1.0.
    • Immediate Action: Block public access and review database permissions.
    • Mitigation: Patch immediately.
  • CVE-2026-96649: Frontend Post Submission Manager Lite XSS
    • Impact: Stored script execution in visitors’ browsers.
    • Affected Systems: WordPress plugin up to 1.3.4.
    • Immediate Action: Disable guest submissions if enabled and patch.
    • Mitigation: Update plugin and clear cached content.
  • CVE-2026-97347: Post Views Stats Counter XSS
    • Impact: Stored XSS via User-Agent header.
    • Affected Systems: WordPress plugin up to 1.1.7.
    • Immediate Action: Patch and inspect logs for malicious User-Agent strings.
    • Mitigation: Update plugin immediately.
  • CVE-2026-103054: AiSOC tenant authorization bypass
    • Impact: Authenticated users can add arbitrary tenants and read their data.
    • Affected Systems: AiSOC before 12.0.0.
    • Immediate Action: Review tenant membership changes and restrict endpoint access.
    • Mitigation: Upgrade and audit portfolios.

Previously Alerted

What to Do Now

  1. Patch internet-facing systems first: Pexip, Apache MINA SSHD deployments, PyJWT consumers, LightLLM, EasyFlow .NET, Ziroom ZHOME, AiSOC, and vulnerable WordPress plugins.
  2. Disable or isolate risky interfaces: RPyC/pickle services, LDAP-backed SSH auth, transport upgrades, public archive extraction, and exposed admin/API endpoints.
  3. Assume credential exposure where password disclosure or JWT bypass is possible; rotate secrets, API keys, and admin passwords immediately.
  4. Review logs for exploitation: unexpected deserialization errors, forged JWTs, command-injection payloads, LDAP wildcard auth, and repeated SQLi/XSS probes.
  5. Verify package versions in CI/CD and production lockfiles; upgrade vulnerable npm and PyPI dependencies before the next deploy.

Verification steps: confirm patched versions, remove mixed HS*/asymmetric JWT verification, test that archive extraction rejects symlink escapes, and validate SSH/LDAP and microservice transports are not exposed to untrusted networks.

Monitoring recommendations: alert on new admin sessions, unusual outbound callbacks from AI and conferencing nodes, abrupt Node.js process exits, and any use of public-key material in HMAC verification paths.

Related Resources

  • Internal blog post on JWT hardening and key separation — planned.
  • Internal blog post on safe archive extraction and symlink defenses — planned.
  • Official vendor advisories for PyJWT, Apache MINA SSHD, Pexip, Engine.IO, NestJS, and WordPress plugins.

Keep reading