Security Digest: October 7, 2026 - 13 Critical Vulnerabilities

Today’s alert is dominated by remote code execution, authorization bypasses, and multiple injection flaws affecting AI workflow software, virtualization platforms, embedded networking stacks, and WordPress plugins. The most urgent items are the two critical IBM Langflow flaws, VMware Workstation/Fusion host compromise risk, and several internet-reachable or unauthenticated web app issues that can be exploited quickly if exposed.

· 10 min read

Executive Summary

Today’s alert is dominated by remote code execution, authorization bypasses, and multiple injection flaws affecting AI workflow software, virtualization platforms, embedded networking stacks, and WordPress plugins. The most urgent items are the two critical IBM Langflow flaws, VMware Workstation/Fusion host compromise risk, and several internet-reachable or unauthenticated web app issues that can be exploited quickly if exposed.

Action now: patch or isolate affected systems, restrict internet exposure, and verify whether any of these products are deployed in production, lab, or plugin-heavy web environments. If you run Langflow, VMware desktop virtualization, Zephyr/embedded wireless stacks, or the listed WordPress plugins, treat this as a same-day response.

Critical Vulnerabilities

CVE-2026-104334: IBM Langflow code-generation RCE

  • Impact: Remote attackers can execute arbitrary code.
  • Affected Systems: IBM Langflow OSS 1.0.0 through 1.12.2.
  • Immediate Action: Remove public access, disable untrusted workflow/code-generation features, and patch immediately.
  • Mitigation: Upgrade to a fixed IBM release as soon as available; isolate the service behind authentication and network controls until then.

CVE-2026-93674: IBM Langflow OS command injection

  • Impact: Remote attackers can run OS commands on the server.
  • Affected Systems: IBM Langflow OSS 1.0.0 through 1.12.2.
  • Immediate Action: Assume compromise risk if Langflow is exposed; patch and review for suspicious process execution.
  • Mitigation: Upgrade to the vendor-fixed version; restrict command-capable integrations and user input paths.

CVE-2026-59346: VMware Workstation/Fusion host escape via VMXNET3

  • Impact: A malicious VM admin can execute code on the host.
  • Affected Systems: VMware Workstation 25H2, 26H1; VMware Fusion 25H2, 26H1.
  • Immediate Action: Patch hosts now, especially developer laptops and test systems running untrusted VMs.
  • Mitigation: Upgrade to 26H1u1; avoid granting local admin inside untrusted guest VMs.

CVE-2026-15894: Bluetooth Mesh On-Demand Private Proxy stack overwrite

  • Impact: Nearby attackers can trigger memory corruption, likely causing denial of service and possibly code execution.
  • Affected Systems: Devices with CONFIG_BT_MESH_OD_PRIV_PROXY_SRV enabled and eligible for solicitation.
  • Immediate Action: Disable the feature where possible and deploy the vendor fix on all affected devices.
  • Mitigation: Update firmware; reduce radio exposure until patched.

CVE-2026-19186: IEEE 802.15.4 security frame length underflow

  • Impact: Crafted short frames can corrupt memory and crash the device.
  • Affected Systems: Configurations using experimental CONFIG_NET_L2_IEEE802154_SECURITY with a crypto device and active security session.
  • Immediate Action: Patch immediately and disable IEEE 802.15.4 security if not required.
  • Mitigation: Apply the vendor fix that rejects undersized frames before decryption.

CVE-2026-103360: IBM Langflow sensitive data exposure via path restriction bypass

  • Impact: Remote authenticated attackers can access sensitive files or data.
  • Affected Systems: IBM Langflow OSS 1.0.0 through 1.12.2.
  • Immediate Action: Limit access to trusted users only and patch promptly.
  • Mitigation: Upgrade to the fixed release; review file-access controls and logs for unusual reads.

CVE-2026-106471: Candlepin authorization bypass across objects

  • Impact: Low-privilege users may read or modify data they should not access, including across organizations.
  • Affected Systems: Candlepin deployments using the affected central authorization filter.
  • Immediate Action: Restrict access, review exposed APIs, and apply the vendor patch immediately.
  • Mitigation: Update Candlepin; verify authorization behavior on multi-object endpoints.

CVE-2026-42720: Dynamic User Directory blind SQL injection

  • Impact: Attackers may extract or manipulate database data.
  • Affected Systems: Dynamic User Directory through 2.4.
  • Immediate Action: Remove public exposure and patch now.
  • Mitigation: Upgrade to a fixed version; monitor database error patterns and suspicious parameterized requests.

CVE-2026-93678: IBM Langflow authorization flaw

  • Impact: Authenticated attackers can access sensitive information.
  • Affected Systems: IBM Langflow OSS 1.0.0 through 1.12.2.
  • Immediate Action: Treat as a data exposure issue and patch immediately.
  • Mitigation: Upgrade, tighten role-based access, and audit access logs.

CVE-2026-42721: affiliate-toolkit-starter blind SQL injection

  • Impact: Database compromise or data extraction may be possible.
  • Affected Systems: affiliate-toolkit-starter through 3.9.1.
  • Immediate Action: Disable the plugin if not essential and update immediately.
  • Mitigation: Apply the vendor fix; review database credentials and logs.

CVE-2026-93447: IBM Langflow deserialization leading to code execution

  • Impact: Attackers with server secret and Redis write access can execute code as the service.
  • Affected Systems: IBM Langflow OSS 1.0.0 through 1.12.2.
  • Immediate Action: Rotate secrets, restrict Redis access, and patch immediately.
  • Mitigation: Upgrade, lock down Redis, and invalidate any untrusted cache data.

CVE-2026-89417: OMGF stored XSS via comments-atom feed

  • Impact: Unauthenticated attackers can inject scripts that run in visitors’ browsers.
  • Affected Systems: OMGF plugin up to and including 6.3.10.
  • Immediate Action: Update or disable the plugin and check whether tmp files are being served without protective headers.
  • Mitigation: Patch immediately; add X-Content-Type-Options: nosniff and verify web server behavior.

CVE-2026-102173: Kirki stored XSS via registration metadata

  • Impact: Unauthenticated attackers can inject scripts into pages that render affected user collections.
  • Affected Systems: Kirki plugin up to and including 6.3.1, especially with public registration enabled.
  • Immediate Action: Disable public registration or the affected page component until patched.
  • Mitigation: Upgrade to the fixed release and review any pages using registration meta fields.

Previously Alerted

What to Do Now

  1. Patch first: Prioritize IBM Langflow, VMware Workstation/Fusion, Candlepin, and all exposed WordPress plugins listed above.
  2. Reduce exposure: Remove internet access, disable unused features, and restrict admin interfaces to VPN or trusted networks.
  3. Rotate secrets and credentials: Especially for Langflow, Redis, and any systems that may have been exposed before patching.
  4. Check for signs of abuse: Review logs for unexpected command execution, SQL errors, unusual file reads, and suspicious web requests.
  5. Contain risky environments: Isolate developer laptops, VMs, and embedded devices that cannot be patched immediately.

Verification steps:

  • Inventory all instances of the listed products and plugins.
  • Confirm exact versions against the affected ranges.
  • Validate that patched builds are deployed, not just downloaded.
  • Test whether public registration, Redis write access, and VM/admin privileges are unnecessarily enabled.

Monitoring recommendations:

  • Watch for new child processes, shell launches, and unexpected outbound connections from Langflow and web servers.
  • Alert on SQL errors, unusual parameter values, and repeated 4xx/5xx bursts.
  • Track browser-side reports of script injection or odd feed content on WordPress sites.
  • Monitor wireless and IoT logs for crashes, reboots, or radio-triggered instability.

Related Resources

  • Internal: Upcoming analysis on AI workflow platform exposure and plugin-driven web app risk.
  • Official vendor advisories: IBM security advisories for Langflow, VMware security advisories, Candlepin project notices, and plugin maintainer release notes.

Keep reading