Supply-Chain
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
Two Malicious CPAN Modules Smuggle a Python Backdoor Inside a Fake Certificate File
Crypt::SelfCertificate and IO::Socket::SSL::SelfCertificate, two CPAN distributions for generating self-signed certs, shipped versions that hide obfuscated Python code inside a sample cert.pem and execute it as a remote-fetch loader.
Verification Theater: The One-Week Pattern Behind BragJack, Plugin4Shell, and WSO2's JWT Bypass
Three unrelated disclosures landed between September 13 and 19, 2026 — a browser AI agent hijack, a Git SHA-pinning bypass in every major coding agent, and a JWT auth bypass under active exploitation. All three share one root cause: a check that confirms a label matches instead of verifying the object it names.
Plugin4Shell: SHA-Pinning Bypass Enables Zero-Click RCE Across Claude Code, Codex, Copilot, and Gemini CLI
A Git reference-resolution flaw dubbed Plugin4Shell lets a plugin repository owner silently swap the code behind a SHA-pinned install across all four major AI coding agents, achieving zero-click RCE on developer and CI machines that trust the pin.
CVE-2026-89094: A Malicious Template Repository Gets You RCE on Forgejo — and Gitea
A crafted .forgejo/template file lets any low-privileged authenticated user turn 'create repository from template' into remote code execution as the Git-forge service account. Forgejo (CVE-2026-89094, CVSS 9.9) and upstream Gitea both shipped emergency patches.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.
Mini Shai-Hulud "Trinitite": TanStack Codegen Tool Poisoned via Hijacked GitHub OIDC Release Workflow
A new Mini Shai-Hulud wave dubbed Trinitite compromised @7nohe/openapi-react-query-codegen, a 150K-download-a-week TanStack code generator, by hijacking its GitHub Actions OIDC publish workflow rather than stealing a token.
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Fourteen npm packages disguised as calendar and streak utilities smuggle in RedC2 4.0, a commercial Linux implant whose LLM-driven operator console turns plain-English prompts into post-exploitation commands.
Poisoned arrayref, internment, and append-only-vec Crates Pull Build-Time Malware via a proc-macro2 Typosquat
A compromised maintainer account published malicious releases of three popular Rust crates that pull in a typosquatted proc-macro2 lookalike whose build.rs script downloads and runs a platform-specific payload at compile time — with infrastructure overlapping known DPRK supply-chain campaigns.
Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Breaks Guest-to-Host Isolation for AI Agent Sandboxes
A type confusion in isolated-vm's ExternalCopy transferList handling lets code running inside a V8 sandbox corrupt host memory and hijack control flow — a full guest-to-host escape in a library millions of AI agent and automation deployments trust to run untrusted code.
Supply Chain Security Vendor RapidFort Allegedly Breached in CanisterWorm Fallout — 569GB of Customer Pipeline Data Listed for Sale
A threat actor claims to be selling 569GB of RapidFort's internal pipeline data — including customer cross-account IAM templates, kubeconfigs, and plaintext AWS credentials — allegedly extracted during the March 2026 CanisterWorm/TeamPCP campaign.
CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation
CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.
BdThemes Supply Chain Attack: Poisoned JSON Feed Creates Rogue WordPress Admins Without Touching a Single Plugin File
Attackers compromised BdThemes' vendor infrastructure and poisoned a promotional-banner JSON feed served to 100,000+ WordPress sites, hijacking admin sessions to plant rogue accounts and a persistent webshell — no plugin update required.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE
CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.
Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally
A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract
A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.
Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster
Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.