← All briefings

WordPress AI Copilot · MSI Radix AXE6600 Router · D-Link DWR-M961 Router

Date: 2026-08-09 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Today’s new material centers on three clusters: a WordPress plugin authorization bypass (CVE-2026-14526, CVSS 9.8, EPSS 0.61) with high exploitation probability; ten-plus command injection flaws across MSI Radix AXE6600 and D-Link DWR-M961 routers (CVSS 9.3, no EPSS signal yet); and two Bouncy Castle FIPS cryptographic library vulnerabilities affecting enterprise Java environments. The Metabase zero-day and N-able N-central exploitation remain active. No new CISA KEV additions or European government advisories were published in the last 24 hours.


Critical Vulnerabilities

CVE-2026-14526 — WordPress AI Copilot – Content Generator Plugin

  • Severity: CVSS 9.8
  • EPSS: 0.61 — high exploitation probability
  • Technical detail: An authorization bypass in all versions up to and including 1.5.6 allows unauthenticated or low-privileged users to perform actions that should require elevated permissions. The flaw stems from missing capability checks on plugin endpoints. WordPress plugins with broken access control are a consistently high-volume exploitation target; the elevated EPSS score indicates active scanning or exploitation is likely imminent.
  • Exploitation status: Not confirmed in the wild; EPSS 0.61 indicates high near-term risk.
  • Remediation: Update the AI Copilot – Content Generator plugin to a version beyond 1.5.6 immediately. If no patched version is available, deactivate and remove the plugin. Audit WordPress plugin inventories for this component.

CVE-2026-71983 through CVE-2026-71993 — MSI Radix AXE6600 Router (Multiple Command Injections)

  • Severity: CVSS 9.3 per CVE
  • EPSS: 0 (newly published)
  • Technical detail: Ten distinct command injection vulnerabilities affect firmware version v781521 across multiple CGI interfaces: wps.cgi, urlfilter, accesscontrol, dmz, alg, portFw, porTrigger, TelnetSSH (SSH and Telnet config), and macfilter/openvpn. Each allows a remote attacker to execute arbitrary OS commands on the device without authentication. The breadth of affected interfaces suggests systemic input sanitization failures across the firmware. These are consumer/SOHO routers but may appear in small-office or branch environments.
  • Exploitation status: No confirmed exploitation; no patch announced at time of publication.
  • Remediation: Disable remote management interfaces where possible. Restrict router admin access to trusted LAN segments. Monitor for vendor firmware update; apply immediately when available.

  • Severity: CVSS 9.3 per CVE
  • EPSS: 0 (newly published)
  • Technical detail: Fourteen vulnerabilities affect hardware version C1 running firmware before 1.1.5_C1_202607071108, spanning command injection across at least ten boafrm CGI endpoints (NTP, SMS, USSD, PIN management, IMEI, L2TPv3, diagnostic tools, LTE FOTA upgrade) and buffer overflows in app.cgi and quicksetup.cgi. Remote unauthenticated attackers can achieve arbitrary command execution or memory corruption. A patched firmware version (1.1.5_C1_202607071108) is available.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update D-Link DWR-M961 firmware to 1.1.5_C1_202607071108 immediately. Restrict management interface exposure to trusted networks pending update.

CVE-2026-13505 / CVE-2026-8798 — Bouncy Castle FIPS for Java (BC-FJA)

  • Severity: CVSS 8.7 (both)
  • EPSS: 0.25 / 0.33
  • Technical detail: CVE-2026-13505 affects BC-FJA 1.0.x before 1.0.2.7, 2.0.x before 2.0.2, and 2.1.x before 2.1.3 — sensitive key material held by AES, DESede, and SP 800-90A DRBG engines is not zeroed from memory after use, creating a key-extraction risk in shared or compromised JVM environments. CVE-2026-8798 (2.1.x before 2.1.3 only) causes the native Intel entropy source (RDSEED/RDRAND) to retry without bound on failure, potentially causing a denial of service or weakened entropy. BC-FJA is widely used in enterprise Java applications requiring FIPS 140 compliance, including financial services and government deployments.
  • Exploitation status: No confirmed exploitation; moderate EPSS scores warrant prompt patching in sensitive environments.
  • Remediation: Upgrade BC-FJA to 1.0.2.7, 2.0.2, or 2.1.3 as appropriate. Prioritize systems handling cryptographic key material in regulated or high-sensitivity environments.

ONGOING:

  • CVE-2026-8037 (Progress LoadMaster): CISA KEV deadline 2026-08-10 — patch immediately; restrict management interface access.
  • CVE-2026-63077 (JetBrains TeamCity): CISA deadline expired 2026-08-08 — treat unpatched instances as compromised; hunt for .jspws webshells.
  • Metabase SQL injection zero-day (CVE pending): Apply emergency patch; audit query logs; treat exposed instances as potentially compromised.
  • CVE-2026-64638 (WordPress Core): Apply core patch; enforce CSP on login pages.
  • CVE-2026-64637 (Plesk): Upgrade to 18.0.80.1; enforce MFA on all accounts.
  • CVE-2026-0257 (PAN-OS GlobalProtect): Qilin ransomware exploitation ongoing — patch immediately.
  • CVE-2026-16232 (Check Point SmartConsole): Actively exploited — treat unpatched instances as compromised.

European Advisories

No new BSI WID or CERT-EU advisories were published in the last 24 hours.

Previously reported BSI advisories remain actionable — see ONGOING items above and yesterday’s report for full details: WID-SEC-2026-2702 (Arista VeloCloud), WID-SEC-2026-2703 (Flowise, unpatched), WID-SEC-2026-2699 (Wazuh), WID-SEC-2026-2690 (Sophos Endpoint), WID-SEC-2026-2701 (WordPress), and the Microsoft/Google/Apache batch from 2026-08-07.


Active Threats and Campaigns

NEW — N-able N-central Hotfix 2 / Ongoing Managed Service Exploitation: N-able released a second hotfix for N-central as threat actors continue to evolve attack techniques against the recently disclosed RMM vulnerability. Attackers have demonstrated the ability to reach managed endpoints and establish persistence through the N-central management plane — a supply-chain-style risk for MSPs and their customers. Apply Hotfix 2 immediately; audit managed endpoint activity for lateral movement or new persistence mechanisms. Source: The Hacker News

NEW — Head Mare Trojanizes TrueConf Installers: The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with backdoored versions. Organizations using TrueConf — particularly prevalent in Russian-speaking and Eastern European environments — should verify installer integrity via vendor-provided hashes before deployment and scan existing installations for backdoor indicators. Source: Bleeping Computer

ONGOING — UNC6671 vishing campaign (financial/professional services): No new developments; brief staff, enforce SaaS MFA, monitor for bulk downloads. ONGOING — Microsoft 365 AitM phishing (payroll/finance targeting): No new developments; enforce Conditional Access, block legacy auth. ONGOING — ~800 malicious npm packages (RAT/infostealer): Audit dependency trees; enforce lockfile integrity.


Security News and Context

  • Atlassian Rovo prompt injection: Attacker-controlled content can instruct Rovo to exfiltrate Jira/Confluence data accessible to a signed-in user; one attack path remains unconfirmed as closed. Organizations using Rovo should review data access scoping and monitor for anomalous AI-assistant activity. The Hacker News
  • CSS-based webmail attacks: Researchers demonstrated cross-client techniques (Outlook, Gmail, Proton Mail, Yahoo, AOL) allowing email content to escape message boundaries and capture passwords, tokens, and hijack UI actions. The Hacker News
  • AI enabling more zero-days: Google Threat Intelligence head Sandra Joyce stated AI tooling is producing more zero-day discoveries than ever, flooding bug-bounty programs and accelerating attacker capability. Heise Security

  1. WordPress AI Copilot plugin (CVE-2026-14526): Update beyond 1.5.6 or deactivate immediately; EPSS 0.61 indicates imminent exploitation risk.
  2. Progress LoadMaster (CVE-2026-8037): CISA deadline tomorrow (2026-08-10) — patch now; restrict management interface to trusted IPs.
  3. N-able N-central: Apply Hotfix 2 immediately; audit managed endpoints for persistence and lateral movement.
  4. D-Link DWR-M961: Update firmware to 1.1.5_C1_202607071108; restrict management access pending update.
  5. MSI Radix AXE6600: Disable remote management; apply vendor firmware update when released.
  6. Bouncy Castle FIPS (CVE-2026-13505 / CVE-2026-8798): Upgrade BC-FJA to 1.0.2.7 / 2.0.2 / 2.1.3; prioritize FIPS-regulated environments.
  7. TrueConf (Head Mare supply chain): Verify installer integrity via vendor hashes; scan existing deployments for backdoor indicators.
  8. Atlassian Rovo: Review data access scoping; monitor for anomalous AI-assistant query patterns in Jira/Confluence.
  9. JetBrains TeamCity (CVE-2026-63077): If not yet patched, treat as compromised — hunt for .jspws webshells and review server logs.
  10. Continue remediation of previously reported items: Metabase zero-day, CVE-2026-64638 (WordPress Core), CVE-2026-64637 (Plesk), CVE-2026-0257 (PAN-OS), CVE-2026-16232 (Check Point), Wazuh (WID-SEC-2026-2699), Arista VeloCloud (WID-SEC-2026-2702), Flowise (WID-SEC-2026-2703).