Friday, September 25, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Thursday's disclosures were led by critical flaws in the WordPress ecosystem (Visual Composer Website Builder, AF Companion, and a WooCommerce OTP plugin), along with ServiceNow AI Platform, Apache BuildStream, and Nocobase. The brief covers 28 critical CVEs, up 4% from 27 the prior day, and 75 high-priority CVEs, down 12% from 85. Among the highest-scoring issues are CVE-2026-61732 (CVSS 10) in BitterSecurity Decepticon, CVE-2026-82331 (CVSS 9.8) in Apache BuildStream, and CVE-2026-12227 (CVSS 9.8) in Visual Composer Website Builder. Web-facing content management plugins and developer or database tooling (Bytebase DBHub, http4s-scala-xml, Nocobase) make up much of the critical set, and seven CVEs affecting network and security infrastructure from F5, Check Point, Zyxel, and Arista VeloCloud are confirmed as actively exploited. Defenders should verify fix status with each vendor, restrict internet exposure of WordPress admin interfaces and appliance management planes, and prioritize internet-facing systems first.

  • Critical flaws in WordPress plugins including Visual Composer Website Builder (CVE-2026-12227, CVSS 9.8) and AF Companion (CVE-2026-84738, CVSS 9.1)
  • 28 critical CVEs (CVSS 9.0+), up 4% from 27 the prior day
  • 75 high-priority CVEs (CVSS 7.0-8.9), down 12% from 85 the prior day
  • Developer and data platforms affected: Apache BuildStream (CVE-2026-82331), Nocobase (CVE-2026-88402), Bytebase DBHub (CVE-2026-61742), and ServiceNow AI Platform (CVE-2026-13016)
  • Check first: internet-facing WordPress and WooCommerce sites, ServiceNow instances, and self-hosted Nocobase or DBHub deployments
  • 7 actively exploited CVEs affect F5 BIG-IP, Check Point Quantum Security Gateway and Management, Zyxel GS1900 switches, Arista VeloCloud Orchestrator, WSO2 Universal Gateway, and Adobe Commerce

Immediate action: Start with the actively exploited network and security appliances (F5 BIG-IP, Check Point Quantum, Zyxel GS1900, Arista VeloCloud Orchestrator) and Adobe Commerce storefronts, then inventory WordPress sites running Visual Composer, AF Companion, or the affected WooCommerce plugin. Confirm fix status in each vendor's advisory before scheduling remediation. Where a fix cannot be applied right away, restrict management interfaces and admin panels to trusted networks.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation