Skip to dossier
Archived issue·09-25-2026
View latest issue
←fruition.net
verified 1w ago
The Perimeter · Issue 09-25-2026

KEV pressure on edge and auth infrastructure, plus unauthenticated RCE in mainstream WordPress plugins

This week was dominated by authentication-bypass and authorization failures in infrastructure that sits at the perimeter: Cisco ISE (CVSS 10 zero-day), Citrix NetScaler, JFrog Artifactory, and Drupal's miniorange SAML module all shipped fixes for flaws that let callers skip auth or reach resources they should never see. On the PHP side, Wordfence disclosed two unauthenticated RCE chains in The Events Calendar (600k+ installs), and Magento Open Source landed on KEV for a template-injection RCE. The second thread is the maturing MCP ecosystem showing classic container-isolation failures: ToolHive's default network profile lets a containerized MCP server reach the host's localhost, echoing SSRF findings in Obot. Meanwhile Grav CMS absorbed five advisories in one drop, mostly from denylist-style validation in blueprint handling. Recalculate your patch priorities around authz and auth-bypass CVEs on internet-facing appliances and registries first; application-layer XSS and SSRF in CMS contrib modules second.
Published
Friday, September 25, 2026
Entries
12
Cadence
Weekly · Sundays
Curator
Brad Anderson
Wire
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
01

Web Application

frameworks · browsers · authentication flows

Detectify Labs: How to hack APIs in 2026

Detectify Labs published an updated API exploitation guide covering what changed in API attack surfaces since the widely-used 2021 edition, including current authentication, authorization, and parser-confusion techniques with reproducible methods. Useful as a testing checklist against in-house APIs.

Fruition take

Hand this to whoever owns API pentest scoping: the 2021-era test plan most teams still use misses the parser-confusion and authz classes this covers. Rerun it against Auth0-backed portal APIs before the next audit cycle.

Chromium V8 out-of-bounds write exploited in the wild

CVE-2026-87491 is an out-of-bounds write in Chromium's V8 engine that allows arbitrary code execution inside the renderer sandbox via a crafted HTML page. CISA added it to KEV on September 9, and the flaw affects all Chromium-based browsers including Chrome, Edge, and Opera.

CVE-2026-87491Google ChromeMicrosoft EdgeChromium
Fruition take

Force a browser update cycle for staff this week; for kiosk or managed-browser fleets, pin the patched Chromium build rather than relying on auto-update timing.

02

Supply Chain

packages · build systems · dependency attacks

github.com1wCVSS 8.8

ToolHive: containerized MCP servers reach host services via host.docker.internal

CVE-2026-58197 (CVSS 8.8): with the default network permission profile (insecure_allow_all: true), a containerized MCP server can reach host-local services through host.docker.internal, including ToolHive's own unauthenticated API and other managed MCP proxies. A compromised or malicious MCP server can move laterally without any container escape, defeating the container isolation model.

Fruition take

Any MCP infrastructure in client environments should drop the default network profile: run MCP servers with restricted egress and no route to the host's loopback, and treat the ToolHive API as untrusted until it has authentication.

03

Infrastructure

kubernetes · cloud · network · ingress

github.com1wCVSS 7.1

Capsule: tenant owners bypass forbidden namespace/service/node label enforcement

CVE-2026-61672 (CVSS 7.1): Capsule's validating webhooks fail to enforce forbiddenLabels/forbiddenAnnotations lists against a bypass path, letting tenant owners set metadata that other controllers and admission plugins key on, including Pod Security Admission labels and service annotations that grant network reach. This breaks the multi-tenant isolation Capsule exists to provide.

CVE-2026-61672Capsule (Kubernetes multi-tenancy)
Fruition take

Multi-tenant K8s clusters using Capsule should upgrade and re-audit existing namespace and service metadata for labels that should have been forbidden, especially PSA labels and LoadBalancer annotations.

Unit 42: SPIFFE/SPIRE workload identity spoofing from a compromised node

Unit 42 details a post-exploitation technique where root access on a compromised Kubernetes node allows an attacker to use SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The technique is reproducible and shows that node compromise collapses workload-identity boundaries in SPIFFE-based deployments.

SPIFFE/SPIREKubernetes
Fruition take

If SPIRE runs on shared nodes, review the attestation model: workload identities minted on a node are only as trustworthy as that node. Node isolation or dedicated node pools for high-trust identities is the mitigation.

04

PHP & CMS

wordpress · drupal · plugins · php frameworks

▲ headline

Unauthenticated RCE chains in The Events Calendar WordPress plugin (600k+ installs)

Wordfence Argus identified two independent critical vulnerability chains in The Events Calendar, active on more than 600,000 WordPress sites. Both chains start in the plugin's widget-rendering pipeline and reach remote code execution without authentication via two separate methods. Patches are available in the current release.

The Events Calendar WordPress plugin
Fruition take

If any managed site runs The Events Calendar, upgrade today and check access logs for requests hitting widget-rendering endpoints from before the patch date.

▲ headline

Adobe Commerce / Magento template injection on CISA KEV

CVE-2026-75650 is an improper neutralization flaw in the template engine of Adobe Commerce and Magento Open Source that permits arbitrary code execution. CISA added it to the Known Exploited Vulnerabilities catalog as of September 8, meaning exploitation has been observed in the wild.

CVE-2026-75650Adobe CommerceMagento Open Source
Fruition take

Commerce clients: confirm your Magento/Adobe Commerce version is patched against CVE-2026-75650 this week. KEV listing implies active targeting of unpatched stores.

github.com1wCVSS 9.1

Grav CMS: five advisories including RCE via .zip upload and super-admin escalation

Grav core shipped a cluster of advisories: CVE-2026-72819 (authenticated RCE by writing a PHP file from an uploaded ZIP, CVSS 8.8), CVE-2026-75837 (admin.users operators escalate to super-admin via the Flex group blueprint, CVSS 9.1), CVE-2026-75827 (arbitrary file write through a denylist-gated dynamic-callable branch), plus stored XSS and arbitrary file deletion. The root cause across several is denylist validation and missing security@ guards in blueprint handling.

Fruition take

Running Grav anywhere in the estate? Treat this as a full-version upgrade, not a cherry-pick; the five issues share blueprint-validation roots and the escalation one (CVE-2026-75837) needs no super-admin to trigger.

05

Identity & Auth

oauth · saml · iam · session attacks

Drupal miniorange_saml module: 11 advisories, two critical

The Drupal Security Team published eleven advisories (SA-CONTRIB-2026-142 through 152) against miniorange_saml < 3.2.0 and two other contrib modules. The SAML module issues include weak cryptographic practices (non-constant-time signature comparison, predictable request IDs), authentication bypass via flexible signature-algorithm selection, SSRF via IdP metadata URLs, TLS certificate validation failures, open redirect, XSS, and replay protection gaps. Fix is miniorange_saml 3.2.0.

CVE-2026-87944CVE-2026-87945CVE-2026-87946+1 moreminiorange_saml (Drupal)
Fruition take

Any Drupal client portal using miniorange_saml needs 3.2.0 deployed and, given the crypto findings, an IdP-side review of assertion signing requirements before relying on it again.

06

Threat Intel

active exploitation · breaches · ransomware

darkreading.com1wCVSS 10.0

Cisco ISE authentication bypass zero-day, CVSS 10.0

CVE-2026-76460 is an authentication bypass in Cisco Identity Services Engine carrying a maximum 10/10 CVSS score, reported as a zero-day with issues in API endpoint authentication. Cisco ISE is widely deployed as the policy decision point for network access control, so a bypass here undermines segmentation controls that depend on it.

CVE-2026-76460Cisco Identity Services Engine
Fruition take

Inventory ISE deployments and check Cisco's advisory for patched builds; until patched, restrict management and API endpoint access to trusted management networks.

JFrog Artifactory privilege escalation on KEV

CVE-2026-42016 in JFrog Artifactory validates a token's signature and issuer but not its scope, allowing privilege escalation. It was added to CISA KEV on September 11. A companion advisory, CVE-2026-42018, returns an internal anonymous-user token to unauthenticated callers when anonymous access is disabled.

Fruition take

If Artifactory fronts your artifact supply chain, patch both CVE-2026-42016 and CVE-2026-42018 now and audit recent deploy/pull tokens for scope abuse.

Citrix NetScaler auth bypass added to KEV

CVE-2026-19490 is an authentication-bypass-via-alternate-path vulnerability in NetScaler ADC and Gateway. When configured as an AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy), an unauthenticated remote attacker may bypass authentication entirely. CISA added it to KEV on September 9.

CVE-2026-19490Citrix NetScaler ADCCitrix NetScaler Gateway
Fruition take

NetScaler gateway CVEs are the classic initial-access vector. Treat every appliance configured as AAA or Gateway as exposed until confirmed patched, and pull session logs for anomalies since the CVE's disclosure.