Monday, September 14, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Consumer and small-business networking hardware dominated the day's critical disclosures, with D-Link and Totolink routers accounting for six of the 14 critical CVEs, alongside a maximum-severity flaw in a WordPress payment plugin. The brief covers 14 critical CVEs (down 26% from the prior day's 19) and 102 high-priority CVEs (up 19% from 86). CVE-2026-81648 in the CryptoPayment Gateway WordPress plugin carries a CVSS of 10, while CVE-2026-90692 and CVE-2026-90693 affect the D-Link DIR-878 at CVSS 9.9, and CVE-2026-84939 reaches 9.1 in Apache FreeMarker. Remote code execution against internet-facing router firmware and CMS extensions is the recurring pattern, which puts branch offices, remote worker sites, and self-hosted web properties in scope. Fourteen CVEs carry confirmed active exploitation, including issues in Citrix NetScaler, Cisco Secure Firewall Management Center, and ConnectWise ScreenConnect; restrict management interfaces on those platforms to trusted networks and verify remediation guidance directly with each vendor.

  • D-Link (DIR-878, DIR-823G) and Totolink (A3002MU) account for six critical CVEs at CVSS 9.9, all affecting router firmware commonly exposed to the internet
  • 14 critical CVEs (CVSS 9.0+), down 26% from 19 the prior day
  • 102 high-priority CVEs (CVSS 7.0-8.9), up 19% from 86 the prior day
  • Remote code execution and authentication bypass are the dominant patterns, spanning router firmware, Apache FreeMarker (CVE-2026-84939, CVSS 9.1), and Joomla and WordPress extensions
  • Check first: CryptoPayment Gateway WordPress plugin (CVE-2026-81648, CVSS 10), Regular Labs Conditional Content Pro for Joomla (CVE-2026-85192, CVSS 9.4), and any D-Link or Totolink devices in branch or remote-site deployments
  • 14 CVEs have confirmed active exploitation, covering Citrix NetScaler, Cisco Secure Firewall Management Center, ConnectWise ScreenConnect, GitLab, Microsoft Windows, Google Chrome, and JFrog Artifactory

Immediate action: Prioritize the actively exploited issues in remote access and management platforms first: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, ConnectWise ScreenConnect, N-able N-central, and MikroTik RouterOS, followed by inventory of internet-exposed D-Link and Totolink routers and any sites running the CryptoPayment Gateway plugin. Consult each vendor's advisory to confirm the current fix status and the exact version that addresses the issue before scheduling maintenance windows.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation