> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
Warlock Ransomware Crew Keeps Breaking In Through SharePoint, Hits Water and Telecom Operators
Symantec ties the China-linked Storm-2603 (Longlegs) crew to new Warlock ransomware intrusions at a water utility and a telecom, using SharePoint access, a vulnerable K7 driver, VS Code tunnels and SYSVOL deployment.
FortiMail CVE-2026-104286: Unauthenticated Path Traversal Exploited as Zero-Day
Fortinet confirms in-the-wild exploitation of CVE-2026-104286, a CVSS 9.8 path traversal in FortiMail that lets unauthenticated attackers write arbitrary files. Patches are not yet released; CISA set a October 4 deadline.
TeamViewer Patches Five High-Severity Flaws, Including Remote Session Access Control Bypass to RCE
TeamViewer bulletin TV-2026-1010 fixes five high-severity client and host flaws, led by CVE-2026-92370, a remote-session access control bypass that can lead to code execution. Update to 15.82.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Exploited
Cisco confirms in-the-wild exploitation of CVE-2026-76504, a CVSS 9.8 URL-encoding auth bypass that hands unauthenticated attackers admin API access on Catalyst SD-WAN Manager. No workaround; CISA added it to KEV.
CVE-2026-89775: KVM/arm64 Nested-Virtualization Bug Gives Guests Read-Write Access to Host Kernel Memory
A type-truncation bug in KVM/arm64's stage-1 page-table walk lets a guest keep a writable mapping to a freed host kernel page, enabling guest-to-host escape on ARM64 hosts with nested virtualization enabled.
Branch Target Reuse: New Spectre v2 Variant Leaks Linux Root Password Hash Through the cBPF JIT
VUSec's Branch Target Reuse abuses stale indirect-branch predictions over freed JIT memory to leak a root password hash from Linux in 3-5 minutes; kernel fixes for CVE-2026-64507 and CVE-2026-64508 are merged.
MemTensor MemOS Packages Backdoored with sckit, a Go Credential-Stealing Worm, on npm and PyPI
Malicious releases of MemTensor's MemOS OpenClaw plugin (npm) and MemoryOS (PyPI) deliver sckit, a cross-platform Go implant that steals 13 credential types and carries worm templates for npm, PyPI and GitHub Actions.
Cloudflare Containers Bug Let One Tenant Read Another Tenant's Disk Data
A misconfigured Linux dm-thin storage pool let any Cloudflare Workers Paid customer recover unzeroed residual disk blocks from other tenants' Containers, Sandboxes, and Browser Rendering instances — exposing SQLite databases, .env files, and credentials.
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
Two Malicious CPAN Modules Smuggle a Python Backdoor Inside a Fake Certificate File
Crypt::SelfCertificate and IO::Socket::SSL::SelfCertificate, two CPAN distributions for generating self-signed certs, shipped versions that hide obfuscated Python code inside a sample cert.pem and execute it as a remote-fetch loader.
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-86708: ManageEngine Shipped a Live GCP Service-Account Key Inside Its Public Installer
CVE-2026-86708 (CVSS 10.0): Zoho's ManageEngine Applications Manager Linux installer shipped a hard-coded, over-privileged Google Cloud service-account key that anyone who downloaded the installer could extract and use to impersonate the account.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-80521: Unpatched Ubuntu AF_UNIX Race Lets Containers Escape to Host Root
A public exploit for CVE-2026-80521, a use-after-free race in the Linux kernel's AF_UNIX socket garbage collector, lets an unprivileged process inside a default Docker or Kubernetes container break out to root on the host — and Ubuntu still hasn't shipped the fix.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
Verification Theater: The One-Week Pattern Behind BragJack, Plugin4Shell, and WSO2's JWT Bypass
Three unrelated disclosures landed between September 13 and 19, 2026 — a browser AI agent hijack, a Git SHA-pinning bypass in every major coding agent, and a JWT auth bypass under active exploitation. All three share one root cause: a check that confirms a label matches instead of verifying the object it names.