A heavier week than the last one. The MikroTik router chain I flagged in the last roundup turned out to be a live zero-day, a popular WordPress events plugin picked up a 9.8 RCE, and Cisco dropped another advisory batch.
- MikroTik’s “no details yet” RouterOS release from the last roundup turned out to be actively exploited. CERT Polska disclosed the chain, dubbed MikroTrick: CVE-2026-67276 (SSH auth bypass, CVSS 9.2) combined with CVE-2026-86060 (privilege escalation) gives an unauthenticated attacker full admin on any RouterOS device with SSH reachable from the internet. Exploitation reportedly started September 2, a day before the patch shipped, so this was a zero-day in practice. CISA added both CVEs to its KEV catalog on September 10, and Shadowserver counted roughly 122,500 internet-exposed RouterOS SSH endpoints as of September 5. If you haven’t patched to 7.24.2, 7.23.4, or 6.49.21 yet, do that now, then check for a “Flagged” device status and an unexpected user named something like “ops” before assuming you’re clean.
- The Events Calendar plugin patched two critical code-injection bugs. CVE-2026-78159 (CVSS 9.8) is an unauthenticated code injection from insufficient validation; a second flaw, CVE-2026-78006, is also critical. Both need comments enabled on the plugin to be exploitable. Fixed in 6.17.3.1, but the plugin has over 600,000 active installs and download data suggests roughly half may still be sitting on a vulnerable version.
- Cisco’s September 16 advisory batch covers hardening releases for BroadWorks CommPilot, Identity Services Engine, Nexus Dashboard, ThousandEyes Virtual Appliance, and a combined release for all three Secure Firewall products (ASA, FMC, and FTD). Worth calling out separately: the same batch includes a Secure Email Gateway hardening release with a SQL injection flaw that Cisco says is already being exploited, which bumps it above the usual “patch when convenient” priority.
- WordPress 7.1.1 is still on track as a bug-fix-only release for tomorrow, September 17, covering 16 core tickets and 22 Gutenberg pull requests. No security content in this one, but if anything you run leans on responsive styles, the Icon Registration API, or the iframed editor, it’s worth a spin on staging before it lands.
Leave a Reply