Skip to dossier
Archived issue·09-18-2026
View latest issue
←fruition.net
verified 1w ago
The Perimeter · Issue 09-18-2026

Identity edges under fire: Cisco ISE, GitLab, and OAuth client confusion

This week's load-bearing story is authentication and authorization trust at the edges. Cisco ISE (CVE-2026-76460, KEV) and GitLab CE/EE (CVE-2026-85706, KEV) both have unauthenticated remote flaws under active exploitation, and the kcp front-proxy advisory shows how trusted header authentication collapses when a proxy fails to strip client-supplied identity. The Obot advisories are a working case study in OAuth dynamic client registration going wrong. On the CMS side, Wordfence reported active exploitation of the WooCommerce Wholesale Lead Capture file-upload flaw, Tutor LMS shipped a fix for an object-injection RCE chain, and Drupal core picked up a CKEditor XSS via SA-CORE-2026-013. The miniorange SAML module fixes eleven issues at once, several of them core SAML correctness problems. Recalculate your patch order: anything unauthenticated on a management or identity plane goes to the front of the queue this week, ahead of authenticated user-facing fixes.
Published
Friday, September 18, 2026
Entries
10
Cadence
Weekly · Sundays
Curator
Brad Anderson
Wire
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
cisa.govNew addition to the Known Exploited Vulnerabilities catalog·
github.comGHSA: critical npm package compromise affecting CI pipelines·
wordfence.comWordPress plugin vulnerability with active exploitation·
drupal.orgHighly critical core security advisory published·
aws.amazon.comAWS security bulletin: IAM policy evaluation update·
unit42.paloaltonetworks.comThreat actor expands toolkit targeting public-facing PHP apps·
krebsonsecurity.comBreach disclosure with named victim and confirmed initial vector·
snyk.ioComposer dependency advisory affecting production framework versions·
01

Web Application

frameworks · browsers · authentication flows

wordfence.com1wCVSS 9.8

Critical libheif vulnerability enables file disclosure and RCE on servers processing HEIC uploads

Wordfence Argus disclosed a CVSS 9.8 vulnerability in libheif, the HEIC image library commonly used server-side to handle iPhone photos. The researchers demonstrated protected-file disclosure and code execution on a WordPress deployment; exploitation is target-specific but they show adapting image-parsing exploits to real systems (HEIF Heist) is practical.

libheifWordPress
Fruition take

If your ingestion pipeline processes user-uploaded HEIC images, check which libheif version your distro or container image ships and rebuild once a patched release is available. Treat image decode libraries as network-facing code, not local dependencies.

02

Supply Chain

packages · build systems · dependency attacks

no entries this week

03

Infrastructure

kubernetes · cloud · network · ingress

github.com1wCVSS 9.9

kcp front-proxy header injection grants system:masters in any workspace

The kcp front-proxy (CVE-2026-61682, CVSS 9.9) forwards client-supplied X-Remote-Group and X-Remote-Extra-* headers to shards, which trust them as verified identity. Any authenticated tenant can inject groups and escalate to cluster administrator with full read/write/delete across all workspaces on a shard. It is a complete multi-tenant isolation bypass, the same failure class as classic Kubernetes front-proxy misconfigurations.

Fruition take

This is a reminder for anyone running request-header auth in front of Kubernetes APIs: the proxy must strip X-Remote-* from inbound requests before it sets its own. Grep your ingress and auth-proxy configs for header passthrough rules this week.

04

PHP & CMS

wordpress · drupal · plugins · php frameworks

Tutor LMS object injection leads to RCE on 100,000+ WordPress sites

Wordfence Argus found a PHP Object Injection vulnerability in Tutor LMS exploitable by subscriber-level users to reach remote code execution, affecting more than 100,000 sites. The fix shipped in version 4.0.8. Object injection chains in widely installed plugins with low-privilege entry points remain the most common path from a subscriber account to server compromise in WordPress.

Tutor LMSWordPress
Fruition take

Running sites with Tutor LMS should be on 4.0.8 today; check your fleet for the plugin even on sites you don't consider e-learning properties. If you allow open subscriber registration, assume low-privilege accounts are attacker-controlled when assessing plugin risk.

Drupal core SA-CORE-2026-013 ships CKEditor XSS fix

Drupal core releases 10.5.x, 11.0.x through 11.4.6 need updating for a CKEditor cross-site scripting issue (SA-CORE-2026-013, moderately critical). Any user who can create or edit content, even without CKEditor access themselves, may exploit it against users who do have the WYSIWYG available, including site admins. Sites not using CKEditor for WYSIWYG are unaffected.

Drupal coreCKEditor
Fruition take

Standard core patch release; schedule it with this week's maintenance window. The exploitation pattern (content editors targeting admins through WYSIWYG) is why editor roles on client sites should be reviewed, not just the core version.

WooCommerce Wholesale Lead Capture file upload actively exploited

Attackers are actively exploiting an unauthenticated arbitrary file upload (disclosed February 20, 2026) in the WooCommerce Wholesale Lead Capture plugin, ~6,000 active installs, to drop PHP backdoors and achieve RCE. Wordfence is reporting exploitation activity against sites that never patched after the February disclosure.

WooCommerce Wholesale Lead CaptureWordPress
Fruition take

A seven-month-old disclosed flaw is still being farmed, which means scanning for unpatched instances matters more than the advisory date. Audit client sites for this plugin and check uploads directories for unexpected PHP files if it was ever installed.

Drupal miniorange_saml fixes 11 advisories including auth bypass and critical crypto flaws

SAML SSO - Service Provider (miniorange_saml) < 3.2.0 received a batch of eleven advisories (SA-CONTRIB-2026-141 through 151): critical improper access control, improper certificate validation, open redirect, and weak cryptography (non-constant-time signature comparison, predictable request IDs), plus XSS, SSRF, assertion replay, and authentication bypass via algorithm confusion. The signature-algorithm issue (CVE-2026-87947) lets an attacker influence which algorithm validates a SAML assertion.

CVE-2026-87943CVE-2026-87944CVE-2026-87945+8 moreSAML SSO - Service Provider (miniorange_saml)Drupal
Fruition take

Any Drupal client portal using this module for SSO should go to 3.2.0 immediately; the signature-algorithm and access-control issues are exactly the SAML implementation classes we treat as auth bypasses, not hardening items. Verify your IdP's configured signing algorithm afterward.

05

Identity & Auth

oauth · saml · iam · session attacks

github.com1wCVSS 8.8

Obot OAuth dynamic client registration minted full-privilege bearer tokens

Obot <= v0.22.1 allowed unauthenticated OAuth dynamic client registration with arbitrary redirect URIs and auto-completed authorization without a consent screen. A logged-in victim visiting a crafted URL leaked an authorization code that exchanged for a token carrying the victim's full group memberships, usable against any Obot API endpoint the victim could reach. Two companion advisories cover SSRF via remote MCP server registration (CVSS 7.6) and registry endpoints readable despite enabled auth.

Obot
Fruition take

If you run Obot, upgrade past v0.22.1 now. More broadly, audit any MCP or agent gateway you've deployed for dynamic client registration and confirm token scopes are narrowed per resource, not inherited from user groups.

06

Threat Intel

active exploitation · breaches · ransomware

nvd.nist.gov1wKEVCVSS 10.0
▲ headline

Cisco ISE auth bypass CVE-2026-76460 added to CISA KEV

CVE-2026-76460 (CVSS 10.0) is an incorrect use of privileged APIs in Cisco Identity Services Engine and ISE-PIC that lets an unauthenticated remote attacker bypass the web-based management interface. CISA added it to the KEV catalog on September 16, citing exploitation. Dark Reading reports the root issue is API endpoint authentication, and Cisco disclosed the flaw alongside its zero-day advisory.

CVE-2026-76460Cisco Identity Services EngineCisco ISE Passive Identity Connector
Fruition take

If ISE or ISE-PIC faces any network you don't fully control, patch before the weekend and restrict the admin interface to a dedicated management VLAN in the meantime. This is exactly the kind of device that sits between your NAC decisions and your production networks.

nvd.nist.gov2wKEVCVSS 10.0
▲ headline

GitLab path traversal CVE-2026-85706 under active exploitation

CVE-2026-85706 (CVSS 10.0) is an unauthenticated path traversal in the GitLab CE/EE repository commits API with missing authentication enforcement, allowing arbitrary file reads. CISA added it to the KEV catalog on September 11. On self-managed instances, arbitrary file read against a GitLab server typically yields signing keys, CI secrets, and configuration that enable further supply-chain compromise.

CVE-2026-85706GitLab Community EditionGitLab Enterprise Edition
Fruition take

Self-hosted GitLab should be patched this week regardless of your normal cadence; check that your instance's commits API isn't reachable from the internet. If you mirrored or pulled artifacts since the fix date, treat stored CI/CD variables as potentially exposed and rotate them.

Sandworm chains Cisco flaws to deploy Cyclops Blink

Dark Reading reports the Russian APT Sandworm is chaining multiple Cisco vulnerabilities to deploy an upgraded Cyclops Blink botnet implant, the malware the FBI disrupted in 2022. The campaign targets Cisco network devices, a class already under sustained KEV pressure this month alongside ISE, Secure Email Gateway, and Firewall Management Center advisories.

Cisco
Fruition take

Inventory any Cisco network appliances in your estate and their firmware dates; exploit chaining means a single unpatched edge device is a botnet foothold, not just an information disclosure. Prioritize anything internet-reachable.