HGiga OAKlouds · Unbound DNS Resolver · Grav CMS
Date: 2026-09-18 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Multiple high-severity vulnerabilities were disclosed during the reporting window, including unauthenticated remote code execution in HGiga OAKlouds, remote code execution in Grav CMS, and a critical Unbound DNSSEC flaw reportedly exploitable through a malicious DNS zone. German CERT-Bund also issued new advisories for Check Point Security Management, Cisco Nexus Dashboard, Tanium Endpoint Management, Jenkins plugins, Apache NiFi and other enterprise technologies. A Brevo supply-chain compromise injected ClickFix scripts into customer-facing websites.
Critical Vulnerabilities
CVE-2026-93467 — HGiga OAKlouds
- Severity: CVSS 9.3
- EPSS: Not supplied
- Technical detail: An unauthenticated remote attacker can exploit insecure deserialization in affected OAKlouds custom-page components to execute arbitrary code on the server. The affected versions include multiple OAKlouds product branches below version 26.
- Exploitation status: NEW — Newly published in EUVD; no exploitation evidence was supplied.
- Remediation: Upgrade affected OAKlouds deployments to vendor-fixed versions when available. Restrict administrative interfaces from the internet, monitor for suspicious serialized requests and unexpected server-side processes, and isolate exposed instances pending remediation.
CVE-2026-81642 — Unbound DNS Resolver
- Severity: Critical; score not supplied
- EPSS: Not supplied
- Technical detail: Unbound releases before 1.26.1 reportedly contain a heap overflow in DNSSEC validation. An attacker controlling a malicious DNS zone may trigger the flaw when a vulnerable resolver queries that zone, potentially resulting in remote code execution.
- Exploitation status: NEW — Public vendor disclosure and technical reporting; active exploitation was not confirmed in the supplied data.
- Remediation: Upgrade Unbound to 1.26.1 or later immediately. Identify recursive resolvers exposed to untrusted clients, restrict outbound DNS where practical, and review resolver crashes, abnormal DNSSEC responses and unexpected child processes.
CVE-2026-72819 — Grav CMS
- Severity: CVSS 8.7
- EPSS: 0.50 — high exploitation probability
- Technical detail: Grav versions below 2.0.13 are vulnerable to remote code execution through malicious ZIP-file uploads. Exploitation could provide web-server-level access and enable web-shell deployment or modification of hosted content.
- Exploitation status: NEW — EUVD-listed vulnerability with EPSS at the high-priority threshold; exploitation was not confirmed in the supplied data.
- Remediation: Upgrade Grav to 2.0.13 or later, disable or tightly restrict administrative upload functionality, and inspect upload directories, web roots and CMS accounts for unauthorized files or changes.
CVE-2026-75827 — Grav CMS
- Severity: CVSS 9.3
- EPSS: 0.78 — high exploitation probability
- Technical detail: Grav versions below 2.0.15 contain an arbitrary file-write issue in the Blueprint dynamic-data handling path. Depending on permissions and deployment configuration, an attacker may write or alter files that affect application behavior or enable code execution.
- Exploitation status: NEW — EUVD-listed with a high predicted exploitation probability; exploitation was not confirmed in the supplied data.
- Remediation: Upgrade to Grav 2.0.15 or later, while also applying the current Grav release because the product has multiple newly disclosed vulnerabilities. Hunt for recent changes to PHP files, configuration files and administrator-controlled content.
CVE-2026-77179 — Docker Sandboxes for macOS
- Severity: Critical; score not supplied
- EPSS: Not supplied
- Technical detail: Malicious code running inside a Docker Sandboxes virtual machine on macOS can escape the intended project-directory restriction and read or modify files elsewhere on the host. The activity occurs with the privileges of the host account running the sandbox.
- Exploitation status: NEW — Publicly reported by Docker; exploitation was not confirmed.
- Remediation: Apply Docker’s security update, avoid running untrusted workloads in affected sandbox versions, and review host filesystem access and recent modifications. Treat systems used to process untrusted images or code as higher priority.
ONGOING
CVE-2026-76460(Cisco ISE): actively exploited; patch before the 2026-09-19 KEV deadline and review management-interface activity.CVE-2026-87886(Acronis Backup): KEV-listed and actively exploited; remediate cPanel/WHM and Plesk integrations before 2026-09-19.CVE-2026-58704(Google Pixel modem): KEV-listed; deploy the applicable Pixel update before 2026-09-19.CVE-2026-76461(Cisco Secure Email Gateway): actively exploited; remediation is overdue.CVE-2026-85706(GitLab CE/EE): actively exploited; patch and investigate arbitrary-file access.CVE-2026-84869(ConnectWise ScreenConnect): active exploitation reported; remediation remains overdue.CVE-2026-42016/CVE-2026-42018(JFrog Artifactory): actively exploited and reportedly chained; patch and rotate exposed tokens.CVE-2026-75650(Adobe Commerce/Magento): actively exploited; hunt for web shells and payment-file changes.CVE-2026-86218(N-able N-central): actively exploited; upgrade to 2026.3.1.14 or later.CVE-2026-63520(Microsoft SharePoint): exploitation and public PoC reported; verify patching and hunt for web shells.
European Advisories
BSI CERT-Bund published new high-severity advisories for Check Point Security Management, where an unauthenticated remote attacker may execute code with administrator privileges; Cisco Nexus Dashboard, Tanium Endpoint Management, Apache NiFi, Jenkins plugins and PJSIP, covering privilege escalation, code execution, authentication bypass, data exposure, SSRF and denial-of-service impacts. Prioritize internet-accessible management systems and systems with administrative integrations. BSI advisory index
WID-SEC-2026-3434 (Eclipse Jetty): newly published advisory concerning false-information display and information disclosure; apply the relevant vendor update.
WID-SEC-2026-1686 (Samba), WID-SEC-2026-2640 (Linux Kernel), WID-SEC-2026-2954 (libvirt), and related OpenSSL, NGINX, PostgreSQL, CPython and Go advisories were updated. Review the update details against local package versions; no new exploitation information was supplied.
CISA also issued multiple ICS advisories affecting Mitsubishi Electric, Hitachi Energy, Schneider Electric, ABB and Bransys products. These are primarily OT-focused and should be handled by infrastructure owners; Schneider PowerChute may also affect enterprise server-management environments.
Active Threats and Campaigns
- Brevo supply-chain compromise: Attackers reportedly stole a Cloudflare API key and injected ClickFix scripts into Brevo websites and JavaScript embedded on customer sites. Inspect externally hosted scripts, web integrity monitoring alerts and browser telemetry for suspicious copy-and-paste instructions or PowerShell execution. Bleeping Computer
- LausivLoader malspam: A campaign used a quotation-themed email impersonating a legitimate company and a malicious attachment to deliver a multi-stage loader. Review quarantined messages, attachment detonation results and follow-on script execution. SANS ISC
- RatHat Android malware: Newly reported Android malware uses an AI-assisted subsystem for remote device control. Monitor managed Android devices for sideloaded applications, accessibility-service abuse and unusual remote-control behavior. Bleeping Computer
- SparroWocky, HEAVYGRAM and previously reported phishing, web-shell and credential-theft activity remain under monitoring; no additional campaign-specific indicators were supplied.
Security News and Context
- Cisco’s actively exploited ISE authentication-bypass issue remains a high-priority European enterprise risk, with Cisco security updates available. The Hacker News
- A breach at Gyazo reportedly exposed approximately 23.62 million user records and 490 million image-metadata records. Organizations should assess reuse of affected credentials and monitor for targeted password-reset activity. The Hacker News
- The U.S. seizure of NightmareStresser domains disrupts one DDoS-for-hire service but does not remove the broader DDoS threat. Bleeping Computer
Recommended Actions
- Patch or isolate OAKlouds, Unbound, Grav and Docker Sandboxes assets; prioritize internet-exposed systems.
- Apply the Grav fixes and hunt for web shells, modified PHP files and suspicious ZIP uploads.
- Complete Cisco ISE, Acronis and Google Pixel remediation before the 2026-09-19 KEV deadline.
- Patch Check Point Security Management and validate that management interfaces are not internet-accessible.
- Audit Brevo-hosted scripts and customer-facing web assets for unauthorized ClickFix content.
- Search mail and endpoint telemetry for LausivLoader-style quotation lures and malicious attachments.
- Continue remediation of previously reported items: Cisco Secure Email Gateway, GitLab, ScreenConnect, Artifactory, Magento, N-central, Windows, SharePoint, RouterOS and PaperCut.