Security Digest: October 1, 2026 - 36 Critical Vulnerabilities
Today’s alert is urgent: 36 critical and high-severity flaws span WordPress plugins, enterprise software, Git tooling, industrial systems, and developer infrastructure. The biggest immediate risks are unauthenticated takeover, arbitrary file read/write, stored XSS leading to admin compromise, and remote code execution or destructive deletion.
· 19 min read
Executive Summary
Today’s alert is urgent: 36 critical and high-severity flaws span WordPress plugins, enterprise software, Git tooling, industrial systems, and developer infrastructure. The biggest immediate risks are unauthenticated takeover, arbitrary file read/write, stored XSS leading to admin compromise, and remote code execution or destructive deletion.
Act now: patch exposed internet-facing systems first, disable vulnerable modules where you cannot patch immediately, and assume any unpatched WordPress, GitPython-based service, or Hitachi Coding Software Suite deployment is at elevated risk.
Critical Vulnerabilities
- CVE-2026-82829: Hitachi Coding Software Suite hidden accounts / hard-coded credentials
- Impact: Unauthorized access to affected systems.
- Affected Systems: Hitachi Coding Software Suite through 3.3.0.
- Immediate Action: Remove exposure from untrusted networks and rotate any credentials tied to the suite.
- Mitigation: Apply vendor updates as soon as available; audit for hidden accounts and hard-coded secrets.
- CVE-2025-41753: BACnet file object path traversal
- Impact: Remote attackers can read or overwrite files and may reach full compromise.
- Affected Systems: BACnet device implementations using vulnerable file object handling.
- Immediate Action: Isolate affected devices and block unauthenticated network access.
- Mitigation: Patch firmware/software; restrict BACnet access to trusted management networks.
- CVE-2026-15989: Super Forms privilege escalation
- Impact: Unauthenticated attackers can create administrator accounts.
- Affected Systems: Super Forms – Drag & Drop Form Builder up to 6.3.316.
- Immediate Action: Disable public registration forms using Super Forms until patched.
- Mitigation: Update immediately; review new admin accounts and recent registrations.
- CVE-2026-75957: Ultimate Multisite authentication bypass
- Impact: Attackers can log in as existing users, including admins.
- Affected Systems: Ultimate Multisite plugin up to 2.15.0.
- Immediate Action: Treat any exposed checkout/login flow as compromised risk.
- Mitigation: Patch now; review active sessions and reset credentials for privileged users.
- CVE-2026-82825: Hitachi Coding Software Suite missing authentication
- Impact: Unauthenticated access to critical API functions.
- Affected Systems: Hitachi Coding Software Suite through 3.3.0.
- Immediate Action: Restrict API access immediately.
- Mitigation: Apply vendor patch; audit API logs for unauthorized calls.
- CVE-2026-82827: Hitachi Coding Software Suite hard-coded JWT key
- Impact: Attackers can forge bearer tokens and abuse admin functions.
- Affected Systems: Hitachi Coding Software Suite through 3.3.0.
- Immediate Action: Rotate tokens and secrets now.
- Mitigation: Patch immediately; invalidate all existing JWTs.
- CVE-2026-92966: LatePoint arbitrary shortcode execution
- Impact: Unauthenticated code execution via malicious shortcodes.
- Affected Systems: LatePoint up to 5.7.0.
- Immediate Action: Disable public booking flows if you cannot patch quickly.
- Mitigation: Update and review site content for injected payloads.
- CVE-2026-19807: ByteCoreStack MCP privilege escalation
- Impact: Subscriber-level users can become administrators.
- Affected Systems: ByteCoreStack – MCP Connector for AI Tools up to 1.2.3.
- Immediate Action: Restrict MCP access and review all low-privilege accounts.
- Mitigation: Patch and verify user meta for unauthorized capability changes.
- CVE-2026-82828: Hitachi Coding Software Suite incorrect authorization
- Impact: Unprivileged users can perform admin-level actions.
- Affected Systems: Hitachi Coding Software Suite through 3.3.0.
- Immediate Action: Limit access to trusted users only.
- Mitigation: Patch and review authorization rules and logs.
- CVE-2026-80275: Comelit Multi-User Gateway password change abuse
- Impact: Authenticated users can overwrite installer/admin passwords.
- Affected Systems: VIP System model 1456B firmware 2.9.1 and 2.10.0.
- Immediate Action: Remove from exposed networks and audit admin credentials.
- Mitigation: Apply firmware update; reset credentials after patching.
- CVE-2026-87817: GitPython repository-root hook execution
- Impact: Opening or cloning a malicious repo can lead to command execution and file disclosure.
- Affected Systems: GitPython 3.1.59 via pip.
- Immediate Action: Stop processing untrusted repositories with affected GitPython versions.
- Mitigation: Upgrade immediately; treat cloned repos as hostile until patched.
- CVE-2026-95687: WPC Shop as a Customer session takeover
- Impact: Authenticated attackers can impersonate administrators.
- Affected Systems: WPC Shop as a Customer for WooCommerce up to 2.0.0.
- Immediate Action: Disable the plugin or remove admin access paths until patched.
- Mitigation: Update and rotate sessions for all privileged users.
- CVE-2026-15983: Super Forms arbitrary file/directory deletion
- Impact: Attackers can delete critical site files and take sites offline.
- Affected Systems: Super Forms up to 6.3.316.
- Immediate Action: Disable file upload deletion features immediately.
- Mitigation: Patch and inspect for missing core files and tampered directories.
- CVE-2026-103493: JetBrains YouTrack stored XSS
- Impact: Malicious content can execute in user sessions.
- Affected Systems: YouTrack before 2026.2.19422.
- Immediate Action: Limit rich content rendering until updated.
- Mitigation: Upgrade and review stored Mermaid/LaTeX content.
- CVE-2026-84504: Fastify async schema validation issue
- Impact: Requests may be processed with attacker-controlled data.
- Affected Systems: Fastify before 5.12.2 and 6.0.0.
- Immediate Action: Disable $async request schemas in security-sensitive routes.
- Mitigation: Upgrade Fastify and move critical checks to request hooks.
- CVE-2026-80276: Comelit management interface information exposure
- Impact: Remote attackers can read sensitive configuration, including passwords.
- Affected Systems: VIP System model 1456B firmware 2.9.1 and 2.10.0.
- Immediate Action: Block network access to the management interface.
- Mitigation: Patch firmware and rotate exposed credentials.
- CVE-2026-87819: GitPython ReDoS in commit metadata parsing
- Impact: Crafted commits can freeze workers and pipelines.
- Affected Systems: GitPython 3.1.59 via pip.
- Immediate Action: Stop parsing untrusted commit metadata at scale.
- Mitigation: Upgrade and apply input-length limits where possible.
- CVE-2026-84428: Fastify header schema dependency bypass
- Impact: Header-based security checks can be skipped.
- Affected Systems: Fastify before 5.12.2 and 6.0.0.
- Immediate Action: Review routes that rely on header dependencies for auth.
- Mitigation: Patch and move enforcement to server-side hooks.
- CVE-2026-102823: russh client-side channel validation failure
- Impact: Hostile SSH servers can spoof channel events and disrupt automation.
- Affected Systems: rust russh client implementations.
- Immediate Action: Treat remote channel events as untrusted until patched.
- Mitigation: Upgrade and validate channel state in application code.
- CVE-2026-103591: DeepWiki-Open arbitrary file read
- Impact: Attackers can read files accessible to the API process.
- Affected Systems: DeepWiki-Open through commit d92819a.
- Immediate Action: Restrict or disable the exposed endpoint.
- Mitigation: Patch and verify repo_url validation.
- CVE-2026-92245: Simply Schedule Appointments data exposure
- Impact: Customer PII and deletion tokens can be stolen.
- Affected Systems: Simply Schedule Appointments up to 1.6.12.32.
- Immediate Action: Assume appointment data is exposed if the plugin is public.
- Mitigation: Patch and rotate any public tokens in use.
- CVE-2026-82826: Hitachi Coding Software Suite cleartext transmission
- Impact: Credentials and sensitive data can be intercepted in transit.
- Affected Systems: Hitachi Coding Software Suite through 3.3.0.
- Immediate Action: Enforce secure transport immediately.
- Mitigation: Patch and require TLS on all management traffic.
- CVE-2026-93882: LearnPress IDOR on public AJAX endpoint
- Impact: Unauthenticated users can access paid course materials.
- Affected Systems: LearnPress up to 4.4.8.
- Immediate Action: Disable public material endpoints where possible.
- Mitigation: Update and verify course/item authorization checks.
- CVE-2026-103536: ZongXR Supermarket missing authentication
- Impact: Remote attackers can place orders without authentication.
- Affected Systems: ZongXR Supermarket 1.0.0.0.
- Immediate Action: Restrict access to the order API.
- Mitigation: Apply vendor fix and validate userId handling.
- CVE-2026-92244: PDF Invoices & Packing Slips stored XSS
- Impact: Malicious scripts can run in admin or customer views.
- Affected Systems: PDF Invoices & Packing Slips for WooCommerce up to 5.16.1.
- Immediate Action: Review checkout and invoice fields for injected content.
- Mitigation: Update and purge malicious order metadata.
- CVE-2026-96813: Form Maker stored XSS
- Impact: Script injection via map fields.
- Affected Systems: Form Maker by 10Web up to 1.15.47.
- Immediate Action: Disable public forms using map fields if possible.
- Mitigation: Patch and sanitize stored submissions.
- CVE-2026-85679: Extendify stored XSS through global-styles
- Impact: Unauthenticated requests can plant persistent scripts.
- Affected Systems: Extendify up to 3.1.6.
- Immediate Action: Block unauthenticated access to global-styles routes.
- Mitigation: Upgrade and review stored styles content.
- CVE-2026-97661: Business Essentials for Contact Form 7 stored XSS
- Impact: Script injection through payment gateway fields.
- Affected Systems: Business Essentials for Contact Form 7 up to 1.2.1.
- Immediate Action: Disable the Payments module if not required.
- Mitigation: Patch and inspect submitted gateway values.
- CVE-2026-85235: Forminator rich-text textarea stored XSS
- Impact: Stored payloads can execute in wp-admin.
- Affected Systems: Forminator up to 1.57.2.
- Immediate Action: Review entries and limit admin exposure.
- Mitigation: Update and sanitize stored submissions.
- CVE-2026-96573: Appointment Hour Booking DOM-based XSS
- Impact: Malicious content can execute in rendered booking pages.
- Affected Systems: Appointment Hour Booking up to 1.5.97.
- Immediate Action: Disable the vulnerable display mode if configured.
- Mitigation: Patch and review the readmore setting.
- CVE-2026-92144: Forminator nonce-enabled stored XSS
- Impact: Unauthenticated attackers can plant scripts in submissions.
- Affected Systems: Forminator up to 1.57.2.
- Immediate Action: Treat the nonce endpoint as publicly reachable.
- Mitigation: Patch and monitor for malicious post data.
- CVE-2026-96561: AI Engine dashboard XSS / log injection chain
- Impact: Dashboard script execution in administrator sessions.
- Affected Systems: AI Engine up to 3.8.0.
- Immediate Action: Restrict dashboard access and inspect logs.
- Mitigation: Patch and purge forged log entries and stored advisor data.
- CVE-2026-14995: Autoptimize request URI stored XSS
- Impact: Script injection via frontend requests.
- Affected Systems: Autoptimize up to 3.1.15.1.
- Immediate Action: Disable Critical CSS if you cannot patch quickly.
- Mitigation: Update and review queued CSS jobs.
- CVE-2026-103490: YouTrack privilege escalation via user group links
- Impact: Users may gain elevated access.
- Affected Systems: YouTrack before 2026.2.19422.
- Immediate Action: Review group-link permissions immediately.
- Mitigation: Upgrade and audit group membership changes.
- CVE-2026-103488: YouTrack missing authorization for project teams
- Impact: Authenticated users can access restricted issues.
- Affected Systems: YouTrack before 2026.2.19422.
- Immediate Action: Check for unauthorized team additions now.
- Mitigation: Patch and review project access logs.
- CVE-2026-96577: oc-mirror exposed local cache registry
- Impact: Nearby attackers can tamper with mirrored images or delete cache content.
- Affected Systems: oc-mirror cache registry during mirroring operations.
- Immediate Action: Bind the service to localhost or isolate the host network.
- Mitigation: Apply updates and restrict access to the cache registry.
Previously Alerted
What to Do Now
- Patch internet-facing systems first, especially WordPress plugins, Hitachi Coding Software Suite, GitPython-based services, Fastify apps, and YouTrack.
- Disable vulnerable features now if patching will take time: public booking forms, public AJAX endpoints, MCP tools, exposed management interfaces, and untrusted repository processing.
- Rotate credentials and invalidate sessions for any product with authentication bypass, hard-coded keys, or admin-session takeover risk.
- Audit for compromise: new admin accounts, unexpected group/team membership, modified config files, deleted files, and unknown tokens.
- Contain exposed services by restricting management ports to trusted networks only.
Verification: confirm installed versions against vendor advisories, check package locks and plugin inventories, and review recent auth, admin, and file-change logs. For GitPython and similar tooling, identify any workflows that open or clone untrusted repositories.
Monitoring: watch for new administrator users, unusual checkout/login activity, forged logs, outbound TLS anomalies, file deletions, and spikes in CPU usage from commit parsing or schema validation.
Related Resources
- Internal blog post: October 1, 2026 response checklist for critical web and enterprise vulnerabilities (coming soon)
- Internal blog post: How to triage WordPress plugin compromises quickly (coming soon)
- Official vendor advisories: Hitachi, WordPress plugin authors, GitPython maintainers, Fastify project, JetBrains, and OpenShift/oc-mirror release notes