Skip to dossier
←fruition.net
verified 1d ago
The Perimeter · Issue 10-02-2026

WordPress core RCE hits KEV; Next.js preps a patch wave

Two pre-announcements landed this week: Next.js has a scheduled security release for September 30, and CISA added a WordPress core remote file inclusion CVE to KEV with observed exploitation. When framework vendors schedule releases ahead of disclosure, patch capacity needs to be reserved, not found later. Drupal shipped a large coordinated wave of contrib advisories, including a critical Webform RCE and a Cloud module command injection, plus PHP security releases across 8.2 through 8.5. Identity news skewed toward OAuth trust bugs: Flarum's Discord provider lets unverified emails take over accounts, and ZITADEL's Login V2 skips MFA on session reuse. Recalculate patch priority for September 30 (Next.js) and audit Drupal contrib and WordPress fleet exposure before the KEV additions drive opportunistic scanning.
Published
Friday, October 2, 2026
Entries
12
Cadence
Weekly · Sundays
Curator
Brad Anderson
Wire
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
01

Web Application

frameworks · browsers · authentication flows

nextjs.orgthis week
▲ headline

Next.js schedules September 30 security release

The Next.js team has pre-announced a scheduled security release for September 30, 2026. No CVE details or severity were disclosed, but pre-scheduled coordinated releases in this framework have historically covered server-side request handling issues affecting self-hosted and Vercel deployments alike.

Next.js
Fruition take

Block maintenance time for September 30. Pin your current versions now and set up the upgrade PR in advance so the patch is a merge, not a scramble.

02

Supply Chain

packages · build systems · dependency attacks

github.com3dCVSS 8.8

Cline Hub dashboard WebSocket lets any website run commands on a developer machine

CVE-2026-59723 (CVSS 8.8): the Cline Hub dashboard launched via `cline dashboard` accepts WebSocket connections on /browser without Origin validation when ROOM_SECRET is unset, the default for local binds. Any page a developer visits can open ws://127.0.0.1:8787/browser, read workspace state, mutate MCP and provider settings, and trigger arbitrary command execution because dashboard sessions default to autoApprove: true.

CVE-2026-59723Cline Hub@cline/cline-hub
Fruition take

Agent tooling with local listeners and auto-approval is a browser-drive-by away from code execution. Patch Cline, and set ROOM_SECRET and autoApprove: false wherever the dashboard is used; treat localhost listeners as internet-exposed.

03

Infrastructure

kubernetes · cloud · network · ingress

containerd image-pull DoS via crafted OCI index graphs

CVE-2026-53493: containerd's PullImage handlers traverse crafted OCI image indexes without depth, breadth, or deduplication limits, so a malicious image reference can stall container creation and exhaust host CPU and memory before any container executes. Fixed in containerd 2.4.1, 2.3.6, 2.2.9, 2.0.x patch, and 1.7.x patch releases.

CVE-2026-53493containerd
Fruition take

Any cluster pulling images from registries that aren't fully trusted (including internal developer registries) should patch containerd this week. This is a pull-time DoS, so admission controllers won't save you.

Podman leaks host environment variables via malicious image config

CVE-2026-57231: a container image config with a bare environment variable key (no value) tricks podman run into pulling that variable from the host session. A key ending in * causes podman to pass all host environment variables into the container, so running an attacker-supplied image can exfiltrate credentials from the launching shell or CI job.

Fruition take

Patch podman, and audit CI jobs that build or run untrusted images with podman. If runners hold registry or cloud credentials in the job environment, scope them to the step, not the session.

04

PHP & CMS

wordpress · drupal · plugins · php frameworks

▲ headline

WordPress Core remote file inclusion added to CISA KEV

CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog: a WordPress Core remote file inclusion in page-template resolution that lets an unauthenticated attacker include a readable local .php file outside active theme directories, leading to RCE. CISA notes exploitation has been observed. Federal agencies must patch per BOD 26-04 timelines.

CVE-2026-87902WordPress Core
Fruition take

If you run WordPress, treat the current core release as the patch floor and check WAF logs for page-template parameter abuse this week. Exploitation is confirmed, not theoretical.

PHP security releases across 8.2, 8.3, 8.4, and 8.5

php.net released 8.2.34, 8.3.35, 8.4.26, and 8.5.11 on September 24 as security releases, urging all users on those branches to upgrade. Container images and distro packages lag the releases by days, so fleet drift is likely until images rebuild.

PHP 8.2PHP 8.3PHP 8.4PHP 8.5
Fruition take

Bump the PHP base image tags in your Kubernetes manifests and trigger rebuilds now. Clients on long-lived PHP-FPM images are the exposure; the release is only a patch if it ships.

drupal.orgthis week

Drupal Cloud module RCE via unsanitized Git arguments in Kubernetes integration

SA-CONTRIB-2026-177: the Drupal Cloud module passes user-controlled Git branch and repository URL values to shell commands in its Kubernetes integration without sanitization, allowing arbitrary OS command execution as the web-server user (CVE-2026-96376). A second advisory (CVE-2026-96375) covers TLS certificate validation failures in the same module's Kubernetes and VMware connections, enabling credential interception.

CVE-2026-96376CVE-2026-96375Cloud (Drupal contrib)
Fruition take

Sites using Cloud's Kubernetes submodule with users who can edit cloud service providers should upgrade to 7.0.1 immediately. This module is rare in production but exactly the kind of admin-facing shell path that gets missed in audits.

drupal.orgthis week

Drupal Webform 6.3.0 ships a coordinated batch of 17 advisories including critical RCE

Drupal Security released 17 advisories against Webform 6.3.0 (<6.3.1), headlined by a critical RCE where submitted data is evaluated as template code during token replacement (CVE-2026-96355). The same batch covers access bypasses, stored XSS, SSRF via the Export/Import submodule, and a JSON:API cache leak returning other users' submissions.

CVE-2026-96355CVE-2026-96356CVE-2026-96357+1 moreWebform (Drupal contrib)
Fruition take

If any client site runs webform 6.3.0, upgrade to 6.3.1 today; the RCE is only mitigated by site configuration, not access control. Then audit webform permissions, since several of the access bypasses involve over-privileged editor roles.

05

Identity & Auth

oauth · saml · iam · session attacks

github.com2dCVSS 9.8

Flarum fof/oauth account takeover via unverified Discord email

CVE-2026-92161 (CVSS 9.8): the fof/oauth extension passes Discord's email claim to Flarum core as a trusted email without checking the verified flag. Discord can return unverified emails when a phone number is verified, so an attacker who knows a victim's email address can link their own Discord identity to the victim's account and authenticate without the password.

CVE-2026-92161fof/oauthFlarumDiscord OAuth
Fruition take

If any Flarum community uses fof/oauth with Discord, upgrade now and audit recent identity-linking events for mismatched account merges. The same trust-the-email-claim pattern recurs across OAuth integrations; verify the flag is checked in your own providers.

github.com3dCVSS 8.2

ZITADEL Login V2 MFA bypass via session reuse

CVE-2026-85056: ZITADEL's Login V2 issues a session after password verification, before the MFA challenge completes. Abandoning the MFA step and restarting login reuses the password-verified session without re-checking TOTP, OTP, or U2F unless the organization forces MFA. An attacker with valid credentials can fully authenticate without the second factor.

Fruition take

Upgrade ZITADEL and enable Force MFA policy in the interim if you rely on second factors. Also confirm your own login flows treat MFA as a gate on session issuance, not a step that can be retried around.

06

Threat Intel

active exploitation · breaches · ransomware

Kiteworks tells customers to stop using the platform after federal threat intelligence warning

Kiteworks, a managed file transfer vendor used for sensitive enterprise and government data exchange, urged customers to stop using the platform after receiving credible intelligence from federal authorities that a threat actor may target Kiteworks systems. No CVE or confirmed compromise has been disclosed yet, but managed file transfer platforms remain a favored initial-access target.

Kiteworks
Fruition take

If clients use Kiteworks (or any MFT), follow the vendor's guidance and inventory what data flows through it now. MFT incidents historically surface weeks after initial access; assume telemetry may already exist and preserve logs.

Labcorp pays $2.3M and agrees to overhaul vendor data security practices

Labcorp settled a cybersecurity enforcement action with a $2.3 million penalty and a consent agreement requiring vendor-specific incident response planning, limits on data shared with vendors, and a risk management team tracking vendor compliance. Enforcement is now directly regulating third-party data-sharing practices, not just breach response.

Fruition take

For regulated clients (airports, government), treat vendor data-sharing limits and vendor-security incident response plans as contractual obligations to document now, before an enforcement action defines them for you.