← All briefings

Suricata · Argo Workflows · Mistral Vibe

Date: 2026-09-20 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

New vulnerability data identifies critical flaws in Suricata, Argo Workflows, Mistral Vibe and Totolink networking equipment. The Suricata issues are particularly relevant to organisations operating network detection infrastructure, while the Argo Workflows and Mistral Vibe vulnerabilities affect cloud-native and developer environments. A joint law-enforcement advisory reports that the North Korean-linked WaterPlum operation compromised at least 30,000 devices and moved more than $10.7 million in cryptocurrency. No new CISA KEV additions or German advisories were supplied.

Critical Vulnerabilities

CVE-2026-94084 — Suricata

  • Severity: CVSS 9.4
  • EPSS: Not supplied
  • Technical detail: Suricata versions before 8.0.7 contain a use-after-free in Http2ThreadMultiBuf. The issue can be triggered when an HTTP transaction is inspected by rules using http.response_header with and without a transform. Exploitation requires traffic to be processed by a vulnerable Suricata sensor and may affect sensor stability or potentially enable code execution depending on execution context.
  • Exploitation status: NEW — Published 2026-09-20; exploitation was not confirmed in the supplied data.
  • Remediation: Upgrade Suricata to 8.0.7 or later. Prioritise internet-facing sensors and deployments processing untrusted HTTP/2 traffic. Review sensor crashes and restart events while remediation is pending.

CVE-2026-94083 — Suricata

  • Severity: CVSS 9.4
  • EPSS: Not supplied
  • Technical detail: Suricata versions before 8.0.7 contain a type-confusion flaw in DoH2 handling that can result in an invalid free. The vulnerability is associated with cleanup of HTTP/2 state when a request is processed as HTTP/1, potentially allowing denial of service and possibly memory corruption.
  • Exploitation status: NEW — Published 2026-09-20; exploitation was not confirmed in the supplied data.
  • Remediation: Upgrade to Suricata 8.0.7 or later. Until patched, review whether DoH/HTTP2 inspection is required and monitor sensors for abnormal process termination or memory-related errors.

CVE-2026-93991 — Argo Workflows

  • Severity: CVSS 8.3
  • EPSS: Not supplied
  • Technical detail: Argo Workflows 4.1.0 through 4.1.3 contain an authorisation bypass in ListArchivedWorkflows. The vulnerable path fails to apply cluster-scoped access review correctly when the namespace metadata is supplied, potentially allowing users to access workflow information outside their authorised scope.
  • Exploitation status: NEW — Published 2026-09-19; exploitation was not confirmed in the supplied data.
  • Remediation: Upgrade to Argo Workflows 4.1.4 or later. Review Kubernetes RBAC assignments, archived-workflow access logs and activity by users accessing workflows across namespaces.

CVE-2026-93993 — Mistral Vibe

  • Severity: CVSS 8.6
  • EPSS: Not supplied
  • Technical detail: Mistral Vibe versions before 2.25.5 execute Git hooks during worktree creation before repository trust validation. An attacker can provide a crafted repository that runs commands when opened or processed by the affected development tool. Risk is highest on developer workstations and CI/CD systems that process untrusted repositories.
  • Exploitation status: NEW — Published 2026-09-19; exploitation was not confirmed in the supplied data.
  • Remediation: Upgrade to 2.25.5 or later. Restrict developer tooling from processing untrusted repositories, disable unnecessary Git hook execution and review recent worktree creation and process-launch activity.
  • Severity: CVSS 9.4
  • EPSS: 1.88 — exceptionally high predicted exploitation probability; validate the source score before operational use
  • Technical detail: Firmware version Hh-B20211125.1046 is vulnerable in the formWsc function through manipulation of the localPin argument. The supplied data indicates a remotely reachable device-management flaw, but does not provide sufficient detail to determine authentication requirements or the precise impact.
  • Exploitation status: NEW — Published 2026-09-19; exploitation was not confirmed in the supplied data.
  • Remediation: Identify affected Totolink A3002MU devices and apply a vendor-fixed firmware release if available. Remove management interfaces from the internet, restrict administrative access and replace unsupported devices where fixes are unavailable. Monitor for configuration changes and unexpected outbound traffic.

ONGOING

  • CVE-2026-84434 (Gravity Forms): CVSS 9.8 and EPSS 0.70; update beyond 3.1.0.4 and inspect upload directories for malicious files.
  • CVE-2026-82967 (IBM Guardium Data Protection): patch version 12.2 and keep management interfaces restricted to trusted networks.
  • CVE-2025-39964, CVE-2026-53266, CVE-2025-39682 (Linux Kernel): CISA KEV items remain actively exploited; complete remediation by 2026-09-21 and verify active kernels after reboot.
  • CVE-2026-76460, CVE-2026-76461 (Cisco ISE/Secure Email Gateway): actively exploited; continue urgent patching and compromise assessment.
  • CVE-2026-87886, CVE-2026-85706, CVE-2026-84869, CVE-2026-42016, CVE-2026-42018, CVE-2026-75650, CVE-2026-86218, CVE-2026-63520: actively exploited or KEV-listed; continue remediation.

European Advisories

The European Vulnerability Database recorded new critical and high-severity vulnerabilities affecting Suricata, Argo Workflows, Mistral Vibe, Exim, libexpat, QloApps and multiple WordPress plugins. The Suricata, Argo Workflows and Mistral Vibe issues are covered in Critical Vulnerabilities. Organisations should also review exposure to Exim versions before 4.100.1 where Proxy Protocol is enabled, and update internet-facing WordPress plugins from the supplied EUVD list.

No new BSI CERT-Bund, CERT-EU or CISA advisories were supplied for the reporting period.

Active Threats and Campaigns

  • WaterPlum campaign: A joint law-enforcement advisory reports that the North Korean operation compromised at least 30,000 devices worldwide between December 2025 and July 2026 and transferred more than $10.7 million in stolen cryptocurrency. Review the reported campaign for applicable indicators and detection guidance; prioritise cryptocurrency-related systems, endpoint telemetry and unusual wallet activity.
  • BragJack malicious browser-extension research: A proof-of-concept demonstrates prompt-forcing attacks against AI browser agents in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome. Review BleepingComputer’s report and restrict unapproved extensions, particularly on systems where browser agents can access corporate data or internal applications.

Security News and Context

  • CrowdSec reported that an attacker copied approximately 170 private GitHub repositories using a former employee’s still-active account after a TanStack supply-chain compromise. Organisations should validate offboarding controls, repository access and CI/CD credentials. The Hacker News
  • Security testing reportedly demonstrated chained flaws enabling access to OpenAI employee ChatGPT and Codex accounts and an internal repository. Treat AI-service identities as privileged accounts and review session, OAuth and repository-access controls. The Hacker News
  1. Upgrade Suricata deployments to 8.0.7 or later and investigate sensor crashes or abnormal memory errors.
  2. Upgrade Argo Workflows to 4.1.4 or later; review cross-namespace archived-workflow access.
  3. Upgrade Mistral Vibe to 2.25.5 and restrict Git hook execution on developer and CI/CD systems.
  4. Identify and isolate Totolink A3002MU devices; remove exposed management interfaces.
  5. Complete Linux Kernel KEV remediation by 2026-09-21 and verify running kernel versions.
  6. Hunt for WaterPlum activity, cryptocurrency theft indicators and suspicious browser extensions.
  7. Continue remediation of previously reported items: Gravity Forms, IBM Guardium, OAKlouds, Unbound, Grav, Docker Sandboxes, Cisco, Acronis, GitLab, ScreenConnect, Artifactory, Magento, N-central and SharePoint.