October 9, 2026

Early October Brought Chained Exploits and Fresh Malware to the Front Lines

Executive Summary

October opened with a relentless wave of exploitation, as attackers struck helpdesk platforms, email gateways, edge appliances and web plugins, often within hours of disclosure. CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: two chained flaws in the Zammad ticketing platform used in an AI-driven breach of the Dutch Institute for Vulnerability Disclosure (DIVD), and zero-days in Citrix NetScaler and Fortinet FortiMail.

Active exploitation also hit multiple Atlassian Data Center products, the WPC Product Bundles for WooCommerce and Ninja Forms WordPress plugins, the External Data extension for MediaWiki, and Sharp multifunction printers. Attackers moved fast, hijacking WordPress administrator sessions, dropping web shells on wikis, and abusing a printer flaw exploited since 2024.

On the malware front, ClingSTUN exploited dozens of IoT flaws to build a stealthy proxy network abusing public STUN infrastructure, while a Citrix NetScaler zero-day delivered the WHIPSHOT web shell and SLAPSHOT tunneler. UAC-0277 also turned more than 100 compromised websites into ClickFix lures delivering LUNEXSTEALER.

Key highlights of the week:

  • CISA added four vulnerabilities to its KEV catalog, covering two chained Zammad flaws and zero-days in Citrix NetScaler and Fortinet FortiMail.
  • Active exploitation hit Atlassian Data Center products, two WordPress plugins (WPC Product Bundles and Ninja Forms), MediaWiki's External Data extension and Sharp printers.
  • ClingSTUN exploited dozens of IoT flaws to build a stealthy proxy network that abused public STUN servers.
  • A Citrix NetScaler zero-day gave attackers root access, which they used to deploy the WHIPSHOT web shell and SLAPSHOT tunneler.
  • UAC-0277 turned over 100 compromised websites into ClickFix lures delivering LUNEXSTEALER.

What are the top trending or critical vulnerabilities observed this week?

Several high-impact vulnerabilities are currently trending across the cybersecurity community, demanding immediate attention and patch prioritization. Monitoring these emerging and widely discussed threats provides valuable insights, enabling organizations to make informed security decisions and strengthen their overall defense posture.

CVE-2026-21589 - Arbitrary File Access vulnerability in Atlassian multiple products

An Arbitrary File Access vulnerability in multiple Atlassian self-managed products, including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd Data Center, as well as Crucible and Fisheye, allowed unauthenticated remote attackers to read specific files within the web application root directory. Exploitation required prior knowledge of the target file's exact name and path, since the flaw did not permit directory enumeration, though the presence of sensitive files in certain configurations raised the potential impact significantly. Attackers began attempting to exploit the vulnerability just one day after Atlassian released patches, and only hours after watchTowr researchers published a technical analysis of the flaw. Atlassian addressed the issue in Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1; Confluence Data Center 9.2.26 and 10.2.19; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 and 7.2.4; Jira Software Data Center 9.12.40, 10.3.26 and 11.3.12; Jira Service Management Data Center 5.12.40, 10.3.26 and 11.3.12; Bamboo Data Center 10.2.24 and 12.1.12; and Crucible and Fisheye 4.9.15.

CVE-2026-88779 - Improper Restrictions of Operations within the Bounds of a Memory Buffer vulnerability in Citrix NetScaler

An Improper Restriction of Operations within the Bounds of Memory Buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows attackers to trigger a denial-of-service condition and was actively exploited as zero-day. The flaw affected customer-managed deployments configured as a SAML service provider (SP) or SAML identity provider (IdP), which administrators could identify through "add authentication samlAction" or "add authentication samlIDPProfile" entries in the NetScaler configuration. Repeated triggering of the condition kept the service unavailable, though Citrix reported an impact on availability only, with no effect on the integrity of customer data, and confirmed that the issue was distinct from previously disclosed NetScaler vulnerabilities. Citrix addressed the flaw in NetScaler ADC and NetScaler Gateway versions 14.1-73.41 and 13.1-64.28, including FIPS and NDcPP builds 14.1-73.41 and 13.1-37.282, and CISA added the vulnerability to its KEV catalog.

CVE-2026-93836 - Stored Cross-Site Scripting vulnerability in the WPC Product Bundles for WooCommerce plugin for WordPress

A Stored Cross-Site Scripting vulnerability in the WPC Product Bundles for WooCommerce plugin for WordPress stemmed from insufficient input sanitization and output escaping on the qty parameter, and threat actors actively exploited the flaw in the wild. The plugin's float-cast quantity validation accepted any value beginning with a number, allowing a payload such as 1<img src=x onerror=alert(1)> to pass checks through the bundle add-to-cart flow and land verbatim in WooCommerce order item metadata under the _woosb_ids key. When a store administrator or another user viewed the affected order in the WordPress dashboard or on a storefront page, the injected script executed in the viewer's session, and Patchstack observed attackers abusing this to plant malicious JavaScript and take over administrator sessions, though exploitation remained limited in scale. The flaw affected plugin versions up to and including 8.6.6, and WPClever addressed the vulnerability in version 8.6.7.

CVE-2026-94504 - Stored Cross-Site Scripting vulnerability in Ninja Forms - Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder WordPress plugin

A Stored Cross-Site Scripting vulnerability in Ninja Forms, a drag-and-drop WordPress form builder installed on more than 500,000 sites, let attackers inject malicious JavaScript into form submissions that executed once a logged-in administrator viewed the stored content. Running inside the administrator's authenticated session, the script harvested administrative nonces, created a rogue administrator account and installed a malicious plugin posing as "WP Smart Thumbnails" version 1.2.4 from "MediaPress Labs." The intrusion set up four separate routes back into the site: a visible administrator account, a hidden administrator account absent from the dashboard user list, a secret login URL tied to the oldest existing administrator, and an unauthenticated file manager for uploading further payloads. Auxiliary plugins with backdated timestamps preserved the hidden account and secret login URL even after the malicious plugin was removed. Patchstack observed the flaw under active exploitation from October 5, as part of a campaign that delivered the same payload from imgcdn1[.]com against WPC Product Bundles for WooCommerce a day earlier, and kstover addressed the vulnerability in Ninja Forms version 3.15.4, with all versions up to and including 3.15.3 affected.

CVE-2026-100382 - Remote Code Execution vulnerability in MediaWiki

A Remote Code Execution vulnerability in the External Data extension for MediaWiki allowed unauthenticated attackers to run arbitrary commands on the server as the web server user, and threat actors actively exploited the flaw within a day of public disclosure on September 25. Since version 3.0, the extension supported running local programs on the server but failed to filter commands passed through a parser function, which made exploitation possible on default setups without any account or privileges. Automated attacks followed a consistent pattern of probing the wiki API for the extension, sending bursts of POST requests, and then requesting newly written PHP files, with one administrator logging 13 attack rounds on September 26 that planted a working web shell in the skins directory. The bug report and proof-of-concept remained publicly accessible on Wikimedia Phabricator task T434961, and administrators running older versions were advised to hunt for unfamiliar PHP files named Nx_.php or NX_.php, review access logs since September 25, and rotate all database passwords, secret keys, admin passwords and API keys stored in LocalSettings.php. The flaw affected all External Data releases before 3.7, and the extension's author addressed the vulnerability in External Data version 3.7, with disabling the extension recommended as an alternative.

CVE-2026-102489 – Session Fixation vulnerability in Zammad GmbH Zammad

A Session Fixation vulnerability in Zammad, an open-source, AI-powered helpdesk and ticketing platform, allowed attackers to hijack user sessions and achieve remote code execution as the zammad user, and was exploited as a zero-day. Threat actors chained the flaw with a separate local privilege escalation vulnerability in Zammad to gain root access during the September 21, 2026 breach of the Dutch Institute for Vulnerability Disclosure (DIVD), after which the attackers reached other services and exfiltrated volunteer data. DIVD attributed the attack to an autonomous AI agent that executed the chain within seconds, and discovered the flaw in collaboration with Merlon Security before reporting it to Zammad. The vulnerability affected Zammad versions 6.3.0 through 6.5.4, and Zammad GmbH addressed the issue in version 7.2.0, while CISA added the vulnerability to its KEV catalog.

CVE-2026-102490 - Improper Privilege Management vulnerability in Zammad GmbH Zammad

An Improper Privilege Management vulnerability in Zammad, an open-source, AI-powered helpdesk and ticketing platform, allowed the local zammad user to escalate privileges to root and was exploited as a zero-day. Threat actors chained the flaw with a separate session hijacking and remote code execution vulnerability in Zammad to breach the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21, 2026, gaining root access before reaching other services and exfiltrating volunteer data. DIVD attributed the intrusion to an autonomous AI agent that completed the chain in seconds, and the organization discovered the flaw in collaboration with Merlon Security before reporting it to Zammad. The vulnerability affected Zammad versions 1.5.0 before 7.1.0-alpha and remained unpatched pending vendor verification, with DIVD advising users to upgrade to version 7 or take vulnerable instances offline, and CISA added the vulnerability to its KEV catalog.

CVE-2026-104286 - Path Traversal vulnerability in Fortinet FortiMail

A Path Traversal vulnerability in Fortinet FortiMail, a secure email gateway deployed at the network edge to filter corporate mail, gave unauthenticated attackers the ability to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests, and threat actors exploited the flaw as a zero-day. Improper handling of file paths and null bytes in the web management interface let attackers place files outside the intended directory, opening a route to command execution and full takeover of the mail gateway. A compromised appliance put stored mail, credentials and connected systems at risk, while also allowing attackers to bypass email filtering and potentially intercept or spoof internal communications. Neither exploit details nor information on the threat actors surfaced publicly. The flaw affected FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9, and Fortinet released fixes in versions 8.0.2, 7.6.7 and 7.4.9, with CISA adding the vulnerability to its KEV catalog.

CVE-2024-58388 - Local File Inclusion vulnerability in Sharp multifunctional printers

A Local File Inclusion vulnerability in Sharp Multifunctional printers, including models rebranded by Toshiba Tec, enabled unauthenticated remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint of the web management interface. By inserting directory traversal sequences, attackers broke out of the electronic manual directory and retrieved sensitive data such as /etc/passwd, system configuration files and core dumps containing credentials, which provided a stepping stone for deeper network access. Researcher Pierre Kim publicly documented the technique in June 2024, and the Shadowserver Foundation recorded exploitation in the wild from July 30, 2024, yet a CVE identifier arrived only on October 1, 2026, more than two years later. A long-available proof-of-concept and a ready-made Nuclei template made mass scanning straightforward, so internet-facing units warranted treatment as potentially compromised. No firmware version specifically addressing the flaw appeared in the CVE record, and Sharp and Toshiba Tec users were advised to upgrade to the latest available firmware and restrict internet exposure of the web management interface.

What did Cytellite sensors detect this week?

Cytellite telemetry captured active exploit attempts and mass scanning campaigns against exposed services globally. The data highlights which vulnerabilities are under attack and provides source IPs and payloads to authorized teams for detailed threat analysis and validation.

Vulnerabilities Product Severity Title Exploited in the-wild CISA KEV
CVE-2026-63030 WordPress Core Critical Interpretation Conflict vulnerability in WordPress Core Yes True
CVE-2025-5777 Citrix NetScaler ADC and Gateway Critical Out-of-Bounds Read vulnerability in Citrix NetScaler ADC and Gateway Yes True
CVE-2025-55182 Meta React Server Components Critical Remote Code Execution vulnerability in Meta React Server Components Yes True
CVE-2025-34037 Linksys E-Series Routers Critical OS Command Injection Vulnerability in Linksys E-Series Routers Yes False
CVE-2025-31324 SAP NetWeaver Critical Unrestricted File Upload vulnerability in SAP NetWeaver Yes True
CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA Gateway Critical Stack-Based Buffer Overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways Yes True
CVE-2024-47176 OpenPrinting CUPS Medium Improper Input Validation vulnerability in OpenPrinting CUPS No False
CVE-2024-4577 PHP Group Critical OS Command Injection vulnerability in PHP-CGI Yes True
CVE-2024-3400 Palo Alto Networks PAN-OS Critical Command Injection vulnerability in Palo Alto Networks PAN-OS Yes True
CVE-2024-3273 D-Link NAS devices High Command Injection vulnerability in D-Link NAS devices Yes True

Which vulnerabilities were abused by malware this week?

Active malware campaigns exploited specific vulnerabilities to deliver payloads and carry out post-exploitation actions. Each targeted vulnerability is proactively monitored, manually analysed, and mapped to MITRE ATT&CK tactics and techniques. Insights are derived from the LOVI vulnerability intelligence platform, which aggregates and curates data from multiple sources, OSINT groups, blogs, and data leak sites.

ClingSTUN exploited dozens of IoT flaws to build a stealthy STUN-Powered proxy network

According to FortiGuard Labs, ClingSTUN was a Linux Backdoor that turned compromised internet-facing devices into remotely controlled proxy nodes and abused public STUN (Session Traversal Utilities for NAT) servers to discover external IP addresses and ports, maintain NAT bindings and blend malicious traffic with legitimate VoIP and WebRTC communications. The threat actor exploited unpatched vulnerabilities across a wide range of products from EnGenius, D-Link, Linear, Realtek, TP-Link, Sunhillo, Ivanti, Tenda, Hytec Inter, AVTECH, MeiG Smart and Lantronix, including CVE-2025-34035, CVE-2025-67038 and CVE-2026-36356, to run shell script downloaders that fetched ClingSTUN builds for ARM, Intel 80386, MIPS, PowerPC and x86-64 architectures. Once launched, the malware disabled the device watchdog, terminated competing malware, persisted through startup scripts, and masked its process by wiping its command-line arguments and bind-mounting the metadata of the system init process over its own /proc entry. ClingSTUN also carried hardcoded exploits for self-propagation against Realtek, MVPower, TBK, Linksys, LB-LINK, China Mobile and KGUARD devices, including CVE-2025-34037 and CVE-2026-87827, and granted operators remote command execution through specially crafted packets.

Citrix NetScaler Zero-Day Exploited to Deploy WHIPSHOT and SLAPSHOT

According to Google Threat Intelligence Group (GTIG) and Mandiant, a pre-authentication memory corruption vulnerability in Citrix NetScaler ADC and NetScaler Gateway was exploited as a zero-day since at least early September 2026, likely impacting government, financial services, technology, education, legal and professional services organizations in North America and Europe. Malformed DTLS record headers sent over UDP/443 corrupted heap memory in the NetScaler Packet Processing Engine (NSPPE), crashing the process and diverting execution to attacker-supplied shellcode with root privileges on the underlying FreeBSD platform. After exploitation, the attackers modified the appliance web server configuration to run PHP web shells disguised as .deb and .sig files, set the setuid bit on /bin/sh for persistent root execution, and scrubbed installation paths from crontab to evade detection. The toolkit included WHIPSHOT, a PHP web shell that concealed Base64-encoded command-and-control traffic in native HTTP headers, and SLAPSHOT, a Python tunneler that proxied traffic into internal networks for reconnaissance and credential theft. Citrix addressed the vulnerability in NetScaler ADC and NetScaler Gateway versions 14.1-73.37 and 13.1-64.23, with dedicated fixed builds also released for 14.1-FIPS and 13.1-FIPS/NDcPP deployments.

ClickFix Campaign by UAC-0277 Turned Compromised Websites into LUNEXSTEALER Delivery Points

According to CERT-UA, a threat cluster tracked as UAC-0277 compromised more than 100 websites in September 2026 and injected malicious JavaScript that displayed a fake Cloudflare verification page, tricking visitors into running a command that downloaded and installed an MSI package from a remote server (the ClickFix technique). The script read the fake page's domain and operating mode from a smart contract on the Polygon or Ethereum network, which let the attackers change infrastructure without re-accessing the compromised sites, and it showed the lure only to Windows users arriving from search engines, at most twice every 12 hours. The MSI variants delivered LUNEXSTEALER directly, through a loader that bypassed User Account Control and abused the vulnerable AMD driver PDFWKRNL.sys (CVE-2023-20598) to disable security tools, or through DLL side-loading of a malicious spkvol.dll by the legitimate FnHotkeyUtility.exe. LUNEXSTEALER, a 64-bit Windows infostealer and remote tasking agent, stole browser passwords, tokens, cryptocurrency wallet data and system information, executed further payloads, persisted through a scheduled task named "psychedelicloveUtils", and could install LUNARAXE, a malicious Chromium extension disguised as "Microsoft Office Word Editor" that harvested cookies, browsing history and form credentials while giving the attackers remote control of the browser.

Vulnerabilities Severity Title Patch Abused By Malware OSS
CVE-2026-36356 Critical OS Command Injection vulnerability in GoAhead web server on MeiG Smart FORGE_SLT711 devices No ClingSTUN False
CVE-2026-87827 Critical Initialization of a Resource with an Insecure Default vulnerability in KGUARD DVR Yes ClingSTUN False
CVE-2026-88772 Critical Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Citrix NetScaler Yes WHIPSHOT
SLAPSHOT
False
CVE-2025-34035 Critical OS Command Injection Vulnerability in EnGenius EnShare IoT Gigabit Cloud Service No ClingSTUN False
CVE-2025-34037 Critical OS Command Injection Vulnerability in Linksys E-Series Routers No ClingSTUN False
CVE-2025-67038 Critical Code Injection vulnerability in Lantronix EDS5000 Yes ClingSTUN False
CVE-2023-20598 High Improper Privilege Management vulnerability in AMD Radeon Yes UAC-0277
LUNEXSTEALER
False

What were the most trending OSS vulnerabilities this week?

Open-Source Software (OSS) vulnerabilities are security weaknesses discovered in publicly available codebases that can be exploited across widely used libraries, frameworks, and tools, often impacting thousands of downstream applications.

CVE-ID Title Ecosystem
CVE-2026-39364 Information Disclosure via Path Traversal vulnerability in Vite MinimOS
CVE-2026-39682 Improper Check for Unusual or Exceptional Conditions vulnerability in Linux Kernel Android
CVE-2026-61687 Cross-Site Request Forgery vulnerability in Hatchet Go
CVE-2026-106445 Prototype Pollution vulnerability in Handlebars.js npm
CVE-2026-105642 Code Injection vulnerability in Ghost npm

Were any PRE-NVD vulnerabilities identified this week?

PRE-NVD vulnerabilities refer to security flaws that are discovered, discussed, or even exploited in the wild before their official inclusion in the National Vulnerability Database (NVD). These early-stage vulnerabilities often emerge through threat actor chatter, exploit proof-of-concepts, and technical disclosures shared across social media platforms and underground forums, signaling potential exploitation risks before public awareness.

CVE-ID Type of vulnerability Product Reference
CVE-2026-41508 Improper Handling of Exceptional Conditions Coraza Resource
CVE-2026-77206 Null Pointer Dereference Libreswan Resource
CVE-2026-104201 Heap Out-of-Bounds Write radsecproxy Resource
CVE-2026-105052 Path Traversal Maximo Application Suite Resource
CVE-2026-106108 Path Traversal Quasar Framework Resource

Conclusion

The first week of October showed how quickly attackers turned disclosed flaws, overlooked devices and trusted platforms into entry points, with exploitation often beginning within hours of public release. From AI-driven intrusions and zero-day appliance compromises to stealthy proxy networks and ClickFix lures, the activity highlighted that no layer of the attack surface remained off-limits. Organizations that prioritized known exploited vulnerabilities, reduced internet exposure and actively hunted for signs of compromise stood in the strongest position to contain the risk. Loginsoft Vulnerability Intelligence (LOVI) continues to deliver timely, actionable insight into emerging threats and actively exploited vulnerabilities, helping security teams stay ahead of adversaries and focus remediation where it matters most.

FAQs

1) What is a ClickFix attack?  

ClickFix is a social engineering technique in which attackers show victims a fake error message, CAPTCHA or verification page, often disguised as a trusted service like Cloudflare. The lure tells the user to copy and paste a command into the Windows Run dialog or terminal to "fix" the issue or prove they are human. Running the command silently downloads and executes malware, so the victim effectively infects their own system.

2) What is ClingSTUN malware?

ClingSTUN is a Linux backdoor that infects internet-facing IoT and edge devices by exploiting known, unpatched vulnerabilities across many vendors' products. It turns compromised devices into remotely controlled proxy nodes and self-propagates using hardcoded exploits. It abuses public STUN servers to traverse NAT and blend its traffic with legitimate VoIP and WebRTC communications, making detection harder.

3) Does inclusion in the CISA KEV catalog mean exploitation is widespread?

Not necessarily widespread - but confirmed. KEV inclusion indicates verified in-the-wild exploitation. While the scale may vary, the operational reality is that threat actors possess working exploits, making patch prioritization urgent regardless of observed targeting volume.

4) How does LOVI help organizations manage vulnerabilities effectively?

Loginsoft Vulnerability Intelligence empowers you to efficiently prioritize and respond to potential vulnerabilities by focusing on those actively exploited in the wild. LOVI correlates vulnerability data with real-world threat activity to reduce noise and improve decision-making. This approach enables faster remediation and stronger security posture.

5) What is Cytellite?

Cytellite is a Loginsoft security intelligence platform that provides real-time visibility into emerging threats through a global sensor network. It delivers actionable IP intelligence to help organizations detect, analyze, and respond to attacks quickly. By correlating threat data with live activity, Cytellite strengthens resilience across dynamic threat landscapes.

Stay Ahead

Get the Latest Cybersecurity Insights

Security research, threat intelligence, vulnerability updates, product news, and expert insights, delivered directly to your inbox. Stay informed. Stay secure.