Skip to content

Sam's News β€” security β€” 2026-09-03

Security

8.5 Over 3 Million WordPress sites affected by migration plugin SQL injection vulnerability

A critical SQL injection vulnerability (CVE-2026-19949, CVSS 8.8) in the All-in-One WP Migration and Backup plugin affects over 3 million WordPress sites. Unauthenticated attackers can execute remote code by submitting trackbacks with malicious payloads, retrieving the archive restore secret key, and importing a crafted archive containing a malicious plugin. The flaw was patched in version 7.110 on August 20, 2026.

  • Over 3 million WordPress sites affected
  • CVSS score 8.8 (critical severity)
  • Affects plugin versions up to 7.109
  • Unauthenticated remote code execution possible
  • Patched in version 7.110 on August 20, 2026

Sources: SecurityWeek AI Web Searched

8 CISA adds seven actively exploited vulnerabilities to known threats catalog

CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 3, including two CVSS 10.0 flaws in SonicWall and Kestra. Threat actors have deployed reverse shells, minted admin tokens, and chained vulnerabilities for remote code execution and ransomware deployment.

  • CVE-2026-83548 (CVSS 10.0): SonicWall server-side request forgery, unauthenticated remote access
  • CVE-2026-9586 (CVSS 9.3): Sangoma Switchvox SQL injection, remote code execution
  • CVE-2026-82329 (CVSS 9.8): JFrog Artifactory improper authentication, unauthenticated admin access
  • CVE-2026-49869 (CVSS 10.0): Kestra OS command injection, unauthenticated workflow execution
  • CVE-2026-48710 (CVSS 6.5) chained with CVE-2026-42271; Qilin ransomware actors exploiting actively

Sources: The Hacker News AI Web Searched

8 153 Million Driver License Images Offered on Dark Web

Cybercriminals offered over 153 million digital scans of US and Canadian driver's licenses on the dark web marketplace Nexus beginning September 3, 2026. The documents were likely stolen from IDScan.net, a Louisiana-based identity verification firm serving major brands across automotive, banking, fintech, gaming, and other sectors. IDScan.net performs over 21 million verifications monthly. The FBI launched an investigation after discovering stolen licenses belonging to agency personnel.

  • 153 million driver's license scans offered on dark web
  • Likely stolen from IDScan.net identity verification service
  • IDScan.net performs over 21 million verifications monthly across 20,000+ locations
  • Threat actor claimed possession of IDs for 170 million individuals total
  • FBI launched official investigation after discovering stolen agent licenses

Sources: SecurityWeek AI Web Searched

8 Cisco warns of unpatched S/MIME email flaws; patches critical switch vulnerabilities

Cisco disclosed two unpatched medium-severity S/MIME vulnerabilities (CVE-2026-20354, CVE-2026-20355) in Secure Email affecting AsyncOS version 16.5.0 and earlier, allowing man-in-the-middle attackers to intercept and modify encrypted communications. Cisco separately patched multiple critical-severity bugs in IOS XR and Nexus 9000 switches, including two IOS XR flaws with CVSS 9.8 scores and a Nexus bug allowing unauthenticated remote code execution with root privileges.

  • Two unpatched S/MIME vulnerabilities in Secure Email (AsyncOS 16.5.0 and earlier)
  • Man-in-the-middle attacks can obtain plaintext from encrypted communications
  • Seven critical IOS XR CVEs patched; two carry CVSS 9.8
  • Nexus CVE-2026-20212 allows unauthenticated RCE with root privileges (CVSS 9.8)
  • S/MIME flaws publicly disclosed but no active exploitation reported

Sources: SecurityWeek AI Web Searched

8 Critical Cisco Nexus 9000 Flaw Allows Remote Code Execution

Cisco patched a critical vulnerability (CVE-2026-20212, CVSS 9.8) in 10 Silicon One-based Nexus 9000 switch models that allows unauthenticated remote attackers to execute code as root by connecting to TCP ports 43210 or 43211. Affected NX-OS releases span 10.3(1) through 10.6(3s), with mitigations including infrastructure ACLs, software updates, and a temporary Live Protect shield for supported models.

  • CVE-2026-20212, CVSS 9.8 critical rating
  • Unauthenticated remote code execution as root via TCP 43210–43211
  • 10 Nexus 9000 models affected; Nexus 3000/7000 unaffected
  • 45 affected NX-OS releases from 10.3(1) to 10.6(3s)
  • No fixed release confirmed; no known malicious exploitation reported

Sources: The Hacker News AI Web Searched

8 SonicWall SMA 1000 Critical Zero-Day Enables Unauthenticated Remote Compromise

A critical zero-day vulnerability in SonicWall SMA 1000 appliances allows complete system compromise without authentication.

Sources: Cybernews RSS Update to: SonicWall Warns of Two Active Zero-Day Vulnerabilities in SMA1000 Appliances

7.5 FalconFlank privilege escalation zero-day disclosed in CrowdStrike Falcon

Researcher Chaotic Eclipse released a proof-of-concept exploit on September 3 for FalconFlank, a privilege escalation zero-day in CrowdStrike Falcon's office malicious macros remediation feature. The PoC is functional on fully updated Windows 11 and Windows Server 2025 systems.

  • FalconFlank: privilege escalation zero-day in CrowdStrike Falcon Sensor
  • PoC released September 3, 2026; functional on Windows 11 25H2 and Windows Server 2025
  • Exploits office malicious macros remediation feature
  • May require obfuscation or security exclusions to test

Sources: The Hacker News AI Web Searched

7.5 Critical Elementor Pro vulnerability exploited to compromise WordPress sites

A critical Elementor Pro plugin vulnerability (CVE-2026-32475) is being actively exploited to deliver webshells and execute arbitrary commands on WordPress servers.

Sources: BleepingComputer RSS

7.5 Thomson Reuters breach exposes sealed court data and sensitive personal information

Thomson Reuters disclosed that unauthorized parties obtained files from its C-Track court case management platform in March 2026, affecting courts across 11 U.S. states and Canadian jurisdictions.

Sources: The Record RSS, The Hacker News RSS

7.5 Attackers leverage Node.js runtime as malware delivery tool in targeted attacks

Threat actors are weaponizing the trusted Node.js JavaScript runtime to deploy malware in targeted attacks against government and technology sectors.

Sources: The Hacker News RSS