Suprema BioStar 2 / BioStar X · HAProxy · Strapi
Date: 2026-09-14 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
New EUVD records identify high-severity vulnerabilities in Suprema BioStar access-control software, HAProxy with HTTP/3 enabled, Strapi, and CyberPanel. The most operationally significant issue is CVE-2026-31278, which can expose Active Directory service-account credentials from vulnerable Suprema deployments. Separately, reporting confirms exploitation of a Tencent Sogou Input Method flaw to deploy the GrayRabbit backdoor, while passkey-themed phishing continues targeting Microsoft 365 accounts.
Critical Vulnerabilities
CVE-2026-31278 — Suprema BioStar 2 / BioStar X
- Severity: CVSS 7.7
- EPSS: Not supplied
- Technical detail: BioStar 2 before 2.9.12 and BioStar X before 1.0.2 expose an issue in the
/api/v2/setting/adserversettingendpoint. Attackers may obtain Active Directory service-account credentials in cleartext or otherwise recoverable form. Exposure is particularly relevant where the management interface is internet-accessible or reachable from untrusted network segments. - Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade BioStar 2 to 2.9.12 or later and BioStar X to 1.0.2 or later. Restrict management interfaces, rotate potentially exposed AD service-account credentials, and review authentication and directory-service logs.
CVE-2026-90678 — HAProxy
- Severity: CVSS 7.5
- EPSS: Not supplied
- Technical detail: The vulnerability affects HAProxy 3.3.0–3.3.14, 3.4.0–3.4.4 and specified 3.5 development builds. Exploitation requires an HTTP/3 frontend, QUIC support and a suitable HAProxy configuration; malformed HTTP/3 traffic can trigger service disruption. Deployments using only HTTP/1.1 or HTTP/2 are not indicated as exposed by the supplied data.
- Exploitation status: NEW — no exploitation reported.
- Remediation: Upgrade to the vendor-fixed release. Until patched, disable HTTP/3 or QUIC frontends where operationally feasible and monitor for abnormal process restarts, memory consumption and connection failures.
CVE-2026-90561 — Strapi
- Severity: CVSS 9.3
- EPSS: Not supplied
- Technical detail: Strapi 4.x through 4.26.2 and 5.x before 5.48.1 contain stored cross-site scripting in the content-manager WYSIWYG preview component. Malicious script content may be stored and executed when privileged users view affected content, creating risk of administrative-session compromise and content manipulation.
- Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade Strapi to 5.48.1 or the applicable fixed 4.x release. Review content entries and administrative activity for unexpected scripts, newly created users, token use or unauthorized content changes.
CVE-2026-29811 — CyberPanel
- Severity: CVSS 7.7
- EPSS: Not supplied
- Technical detail: CyberPanel versions before 2.4.4 contain an issue in alias-domain detection and ORM query handling. The supplied record does not establish remote code execution, but exposed control-panel services should be treated as high-value targets because compromise can affect hosted websites, credentials and server configuration.
- Exploitation status: NEW — no exploitation reported.
- Remediation: Upgrade to CyberPanel 2.4.4 or later. Restrict panel access to trusted administration networks, review panel and web-server logs, and rotate credentials if the management interface was exposed.
CVE-2026-90770 — Spug
- Severity: CVSS 8.7
- EPSS: Not supplied
- Technical detail: Spug through 3.4.0 contains command injection in the
ping_checkfunction, where user-controlled monitor addresses are interpolated into shell commands. The record indicates authentication is required, but successful exploitation may provide code execution with the privileges of the Spug service. - Exploitation status: NEW — no confirmed exploitation supplied.
- Remediation: Upgrade to a fixed release when available, restrict access to authenticated administrators and review monitoring definitions for shell metacharacters or unexpected commands. Inspect the host for persistence and unauthorized process activity.
ONGOING
CVE-2026-85706(GitLab CE/EE): actively exploited; patch immediately and investigate repository API traversal and arbitrary-file access.CVE-2026-84869(ConnectWise ScreenConnect): actively exploited; remediation deadline is 2026-09-14.CVE-2026-42016/CVE-2026-42018(JFrog Artifactory): actively exploited and reportedly chained; patch, rotate tokens and hunt for Rust backdoors.CVE-2026-67277/CVE-2026-86060(MikroTik RouterOS): actively exploited; restrict management and testing interfaces.CVE-2026-75650(Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file modification.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-81963/CVE-2026-85880(Windows): actively exploited; complete September update deployment.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC remain reported; verify patching and hunt for web shells.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation remains reported; deploy current maintenance releases.
European Advisories
EUVD published multiple high-severity records during the reporting period. Of immediate enterprise relevance, CVE-2026-31278 affects Suprema BioStar access-control platforms and can expose Active Directory service-account credentials; CVE-2026-90678 affects HAProxy configurations using HTTP/3 and QUIC; and CVE-2026-90561 affects Strapi content-management deployments. These issues are covered in Critical Vulnerabilities.
Additional EUVD records concern Totolink A3002MU routers, WordPress plugins, SIPp, CAPEv2, Froxlor, PostGIS, Open Notebook and other software. Triage these against asset inventory, prioritizing internet-facing systems and software embedded in administrative or development workflows.
No new BSI, CERT-Bund or CERT-EU advisory was supplied.
Active Threats and Campaigns
- GrayRabbit malware deployment — NEW: Threat actors linked in reporting to a China-aligned espionage group are exploiting
CVE-2026-51990in Tencent Sogou Input Method for Windows. The activity can lead to installation of the GrayRabbit backdoor. Review vulnerable installations, input-method software inventories, process creation and persistence mechanisms. BleepingComputer - Passkey-themed Microsoft 365 phishing — NEW: Campaigns are using passkey and single-sign-on lures to compromise corporate Microsoft accounts and exfiltrate cloud data. Hunt for unusual OAuth grants, unfamiliar authentication methods, impossible-travel activity and suspicious mailbox access. The Hacker News
- GitLab exploitation — ONGOING: Active probing of
CVE-2026-85706continues; investigate traversal payloads and access to configuration, credential or runner files. - JFrog Artifactory exploitation — ONGOING: Attackers are chaining authorization and authentication flaws to gain administrator access and deploy Rust backdoors.
Security News and Context
- Microsoft reports large-scale scam-mail activity combined with passkey-themed social engineering against cloud accounts. Organizations should treat passkey prompts and SSO re-registration requests as high-risk phishing indicators. The Hacker News
- Security reporting indicates exploitation of the Sogou Input Method flaw to deploy GrayRabbit, demonstrating continued targeting of trusted desktop utilities rather than only server infrastructure. BleepingComputer
Recommended Actions
- Patch or isolate Suprema BioStar systems and rotate any potentially exposed AD service-account credentials.
- Identify HAProxy deployments using HTTP/3 or QUIC and patch or temporarily disable HTTP/3.
- Upgrade Strapi, CyberPanel and Spug; review administrative and host logs for exploitation indicators.
- Inventory Tencent Sogou Input Method on Windows endpoints and investigate GrayRabbit-related persistence.
- Brief users on passkey-themed phishing and review Microsoft 365 authentication, OAuth and mailbox-access telemetry.
- Complete remediation of
CVE-2026-84869and other KEV items approaching or exceeding their deadlines. - Continue remediation of previously reported items: GitLab, Artifactory, RouterOS, Magento, N-central, Windows, SharePoint and PaperCut.