The Exploit Bulletin — Thursday, September 24, 2026: 6 issues require action
Thursday, September 24, 2026 — 6 issues require action. If you run none of the software below, you are done.
Affects: WordPress · Ubiquiti UniFi OS Server, Ubiquiti Express, Ubiquiti UDM, Ubiquiti UDM-Pro, Ubiquiti UDM-SE, Ubiquiti UDM-Pro-Max, Ubiquiti UDM-Beast, Ubiquiti EFG, Ubiquiti UDW, Ubiquiti UDR · Arista VeloCloud Orchestrator On-Prem, VeloCloud Orchestrator Hosted · @memtensor/memos-cloud-openclaw-plugin, MemoryOS · MikroTik RouterOS · tac_plus TACACS+ daemon, Shrubbery Networks tac_plus
1. Unauthenticated path traversal in page-template resolution leads to code execution in WordPress core (CVE-2026-87902)
REMOTE CODE EXECUTION · CRITICAL · CVSS 8.1
Exploitation began within hours of the 2026-09-22 disclosure and has progressed from probing to writing web shells, so any unpatched site left through the normal patch cycle should be assumed reachable by automated attacks now.
An unauthenticated request can make WordPress's get_page_template() resolution include an attacker-chosen readable .php file outside the active theme directories. Depending on server and theme preconditions this becomes local file inclusion and remote code execution; attackers are already writing files to disk that run shell commands when accessed.
Affected: WordPress < 7.1.2 (all branches back to 4.7 have security backports)
How to Test: Confirm the running core version in the WordPress dashboard (Updates screen) — anything below 7.1.2 (or lacking the equivalent security backport for your branch) is vulnerable. Review web server access logs for requests carrying path traversal sequences against page/template resolution, and inspect the filesystem for recently created or modified .php files outside the theme and plugin directories that were not part of a deployment; reports describe attackers dropping files that execute shell commands when accessed.
How to Patch: Update to WordPress 7.1.2, or apply the security backport released for your branch (backports exist for every branch back to 4.7). If an update must wait, put a web application firewall with a rule for this path traversal in front of the site (Patchstack and Wordfence have published coverage).
Evidence: VulnCheck KEV · BleepingComputer: attackers exploiting the flaw to write files that execute shell commands · Canadian Centre for Cyber Security AV26-952: exploited in the wild · Patchstack: active exploitation observed on firewall, including file-write attempts · The Hacker News: exploited within hours of disclosure · SecurityWeek: exploited immediately after disclosure
2. Unauthenticated path traversal in Ubiquiti UniFi OS exposes system files and enables account takeover (CVE-2026-34909)
CISA KEV (due 2026-06-26) · AUTHENTICATION BYPASS · CRITICAL · CVSS 10.0
A public exploit is available in VulnCheck XDB and new reporting this week (BleepingComputer 2026-09-22) again cites the flaw as exploited, so any gateway or console still below the fixed UniFi OS release is exposed to unauthenticated account compromise of the device that fronts the network.
A path traversal flaw in UniFi OS lets a network-reachable attacker with no credentials read files on the underlying system, including material that can be used to take over an account on the device. It affects UniFi OS Server, Express, the Dream Machine family (UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast), EFG, UDW and UDR.
Affected: Ubiquiti UniFi OS Server < 5.0.8; Ubiquiti Express < 4.0.14; Ubiquiti UDM < 5.1.12; Ubiquiti UDM-Pro < 5.1.12; Ubiquiti UDM-SE < 5.1.12; Ubiquiti UDM-Pro-Max < 5.1.12; Ubiquiti UDM-Beast < 5.1.11; Ubiquiti EFG < 5.1.12; Ubiquiti UDW < 5.1.12; Ubiquiti UDR < 5.1.12
How to Test: On each console check the UniFi OS version: UniFi OS Server below 5.0.8, Express below 4.0.14, UDM/UDM-Pro/UDM-SE/UDM-Pro-Max/EFG/UDW/UDR below 5.1.12, and UDM-Beast below 5.1.11 are vulnerable. Review the device's web access logs for traversal sequences (../) in request paths to the UniFi OS management interface, especially from external addresses, and audit local accounts, SSH keys, scheduled tasks and running processes for anything not created by administrators.
How to Patch: Update to UniFi OS Server 5.0.8, Express 4.0.14, UDM-Beast 5.1.11, and 5.1.12 for UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW and UDR. Until updated, block access to the UniFi OS management interface from the internet and untrusted networks.
Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · BleepingComputer 2026-09-22: CISA flags the Ubiquiti flaws as actively exploited since late June 2026 · VulnCheck XDB public exploit
3. Unauthenticated OS command injection in Arista VeloCloud Orchestrator On-Prem gives full host compromise (CVE-2026-16812)
CISA KEV (due 2026-07-30) · REMOTE CODE EXECUTION · CRITICAL · CVSS 10.0
Arista's advisory states the flaw was discovered externally and is known to be actively exploited, and BleepingComputer reported on 2026-09-23 that fixed releases are now available; an orchestrator left below the fixed versions is an unauthenticated route to the entire SD-WAN fabric it controls.
Functionality intended for internal use only in VeloCloud Orchestrator (VCO) On-Prem is reachable remotely without authentication and allows OS command injection on the VCO host. An attacker gains control of the orchestrator and the configuration and data of every SD-WAN edge it manages.
Affected: Arista VeloCloud Orchestrator On-Prem >= 5.2.0 < 5.2.3.14; Arista VeloCloud Orchestrator On-Prem >= 6.1.0 < 6.1.3.4; Arista VeloCloud Orchestrator On-Prem >= 6.4.0 < 6.4.2.4; Arista VeloCloud Orchestrator On-Prem >= 7.0.0 < 7.0.0.1; VeloCloud Orchestrator Hosted (patched by Arista)
How to Test: Check the VCO release against the affected list: 5.2.x below 5.2.3.14, 6.1.x below 6.1.3.4, 6.4.x below 6.4.2.4 and 7.0.x below 7.0.0.1 are vulnerable; Arista notes end-of-support versions have not been assessed and should be treated as exposed. Arista provides a CSAF JSON file with the advisory for automated version matching. Review VCO web access logs for requests to internal-only functionality from external addresses, and inspect the VCO host for unexpected processes, accounts, cron entries or outbound connections.
How to Patch: Upgrade VCO On-Prem to 5.2.3.14, 6.1.3.4, 6.4.2.4 or 7.0.0.1 (or later in each train). Hosted and Dedicated VCO instances are being patched by Arista. Until the upgrade is applied, restrict network access to the orchestrator so it is reachable only from trusted management addresses and the SD-WAN edges that need it.
Evidence: CISA KEV · VulnCheck KEV · Vendor confirmed · CISA SSVC: active · BleepingComputer 2026-09-23: Arista patches actively exploited VeloCloud Orchestrator zero-day
4. MemTensor AI-memory packages backdoored on npm and PyPI with 'sckit' credential stealer
SUPPLY-CHAIN COMPROMISE · CRITICAL
The malicious releases went out on 23 September 2026 and were live in the default install path, so any agent gateway, developer workstation or CI runner that installed them this week must be treated as having leaked every credential in its environment before the versions are pulled and the trail goes cold.
Three releases of the npm package @memtensor/memos-cloud-openclaw-plugin (0.1.21, 0.1.23, 0.1.25) and the PyPI package MemoryOS 2.0.34 were published with a hidden cross-platform Go implant dubbed 'sckit'. The payload is launched when the AI agent gateway starts and on every memory-recall call, and is handed the host process environment — including any inherited cloud, registry and API credentials — plus the user's prompt text, which it exfiltrates.
Affected: @memtensor/memos-cloud-openclaw-plugin 0.1.21 (npm); @memtensor/memos-cloud-openclaw-plugin 0.1.23 (npm); @memtensor/memos-cloud-openclaw-plugin 0.1.25 (npm); MemoryOS 2.0.34 (PyPI, project quarantined)
How to Test: Grep lockfiles, npm/pip caches and container images for @memtensor/memos-cloud-openclaw-plugin at 0.1.21, 0.1.23 or 0.1.25 and for MemoryOS==2.0.34 (npm ls @memtensor/memos-cloud-openclaw-plugin, pip show memoryos, search package-lock.json/pnpm-lock.yaml/poetry.lock and CI build logs since 22 Sep 2026); on hosts that match, look for a bundled Go executable dropped alongside the plugin and for a child process spawned by the agent gateway making outbound connections at gateway start and on memory-recall, and review egress logs from those hosts for unexplained destinations.
How to Mitigate: Remove the malicious releases and pin to a known-clean version (0.1.22/0.1.24 are reported clean) or uninstall the plugin and MemoryOS 2.0.34 entirely, rebuild affected runners and workstations from clean images, then rotate every secret that was present in the environment of those processes — cloud keys, npm/PyPI publish tokens, CI/CD and GitHub tokens, model/API keys — and revoke the corresponding OAuth grants.
Evidence: The Hacker News: Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI · StepSecurity: Sckit Supply Chain Worm Hits MemTensor npm & PyPI scopes (names compromised versions 0.1.21/0.1.23/0.1.25)
5. SSH state-machine flaw lets unauthenticated clients run exec requests on MikroTik RouterOS (CVE-2026-67279)
AUTHENTICATION BYPASS · HIGH · CVSS 6.9
CERT Polska published the full MikroTrick technical analysis on 2026-09-22 after reporting active exploitation on 2026-09-05, so routers with SSH reachable from untrusted networks that are still on pre-fix builds are now exposed to attackers armed with public details.
RouterOS's SSH server enters the connection protocol after a client-requested rekey even though authentication never happened, so an unauthenticated client can open a session channel and issue exec requests. Chained with a second RouterOS flaw (the "MikroTrick" chain), this lets an attacker create and overwrite files in the managed file namespace and take full administrative control of an internet-exposed router without a password or key.
Affected: MikroTik RouterOS >= 7.24 < 7.24.2; MikroTik RouterOS >= 7.0.0 < 7.23.4; MikroTik RouterOS >= 6.0.0 < 6.49.21
How to Test: Check the installed version under System/Packages (or via Check For Updates); anything below 6.49.21, 7.23.4 or 7.24.2 is vulnerable. Check whether SSH is reachable from untrusted networks. Review the Log section for a critical entry stating the device has been "Flagged" — RouterOS sets this status when it detects compromise — and, even if not flagged, inspect the configuration after upgrading for unknown scripts, users or other settings you do not recognise.
How to Patch: Upgrade to RouterOS 6.49.21 (long-term), 7.23.4 (long-term), 7.24.2 (stable) or 7.25 beta 3 via System/Packages > Check For Updates or the MikroTik download page. Until then, restrict SSH to trusted source IPs only, or close management ports entirely and reach the router over a VPN such as WireGuard.
Evidence: VulnCheck KEV · CERT Polska: critical RouterOS vulnerabilities actively exploited, immediate update recommended · CERT Polska MikroTrick technical analysis (2026-09-22)
6. Pre-auth format string RCE as root on TCP/49, patched only in Shrubbery F4.0.4.32; Facebook fork unpatched (tac_plus)
UNVERIFIED PUBLIC REPORT · NO CVE · REMOTE CODE EXECUTION · CRITICAL
The write-up, proof of concept and advisory were published yesterday (2026-09-23), a fix exists for one fork and none for the other, and a compromised TACACS+ server sees administrative credentials for every router, switch and firewall in the estate in near real time. Operators of the Facebook fork have no patch coming and need to migrate or fence the service now.
Researchers at elttam report a remote, pre-authentication format string vulnerability on an error path in tac_plus, the widely deployed open-source TACACS+ daemon descended from Cisco's 1990s reference code. A crafted packet to TCP port 49 yields code execution as the daemon user, which is root by default. The packet must be keyed with the TACACS+ pre-shared key, but the write-up describes a PSK oracle in the server that turns the bug into a practical chain without prior knowledge of the secret, and notes that any network device which forwards externally supplied usernames to the server may let an attacker get a correctly keyed payload through without being on the management network. elttam says Shrubbery Networks fixed it in F4.0.4.32 and that the Facebook fork will not be fixed. A CVE is pending but not yet assigned; no vendor advisory page and no reports of exploitation were found in this material.
Affected: Shrubbery Networks tac_plus releases before F4.0.4.32 (fixed in F4.0.4.32); all versions of the Facebook/Meta tac_plus fork (no fix planned). Exact first-affected release not stated — the researchers say the code path is 25+ years old and descends from the original Cisco reference daemon.
How to Test: Check whether you run tac_plus: look for a tac_plus/tacacs process listening on TCP/49 (ss -lntp | grep :49), and run tac_plus -v to get the version — anything below F4.0.4.32 on the Shrubbery line, or any build of the Facebook fork, is affected per the report. Check whether TCP/49 is reachable from anything other than your network devices' management addresses. Review which devices are TACACS+ clients and whether any accept logins (SSH, web, console server) from the corporate LAN or internet, since those can relay a payload to the server. Indicators given in the report are limited to the bug being on an error path, so look for unusual malformed-packet or parse errors in the tac_plus log and for unexpected child processes of the daemon.
How to Patch: Shrubbery tac_plus: upgrade to F4.0.4.32 from shrubbery.net. Facebook fork: no fix is planned — migrate to Shrubbery F4.0.4.32 or to a maintained TACACS+ server, or at minimum firewall TCP/49 to the explicit list of device management IPs. After upgrading, rotate the shared secret on the server and all clients and, where devices support it, move to TACACS+ over TLS (RFC 9887).
Evidence: elttam: ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].