The maintainers of the official Model Context Protocol Python SDK disclosed a flaw that lets a malicious MCP server trick an application built on the SDK into handing over the OAuth credentials it uses to log in to a real service. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, because the SDK did not always verify where the authorization server was. Cycode, which reported it, exchanged the stolen material for a valid access token carrying the app's permissions, and noted the long-lived client secret keeps working until rotated. Fixes are in versions 1.30.0 and 2.2.0.
Apple released updates for a zero-day it says was used in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 27. Tracked as CVE-2026-20700, the flaw is an out-of-bounds write in CoreGraphics, the framework for two-dimensional graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS, and was reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple addressed it with improved bounds checking. The affected device list is broad, spanning iPhone 11 and later, many iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple did not attribute the attacks or name the targeted individuals.
Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks, and released fixes. These are the same zero-days that researchers, IT providers, and national cyber agencies warned about privately over the weekend, with some advising immediate NetScaler shutdowns. Organizations commonly deploy NetScaler as internet-facing edge devices for remote access and application delivery, so compromising one gives attackers a foothold at the network perimeter and a potential path to internal systems without first landing on an internal endpoint. CISA added the flaws to its Known Exploited Vulnerabilities catalog with a near-term federal patch deadline.
Cloudflare fixed a flaw in Cloudflare Containers that let a paying customer read data other customers' containers left behind on the same shared server. Cloudflare Sandboxes, sold for running untrusted code including AI-agent code, was affected too. Each container gets a disk built with Linux thin provisioning in 64-kilobyte blocks; when a container was deleted, its blocks returned to a shared pool set to skip wiping before reuse. A new container writing only a little into a reused block left the rest holding the previous customer's data, though the attacker could not choose whose. Accomplish reported it on September 4, and Cloudflare says no customer action is needed.
Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.
The Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting a Roundcube Webmail flaw, CVE-2026-48842, four months after it was patched. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of services and pre-installed with the cPanel hosting control panel. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that handles database-driven user lookups. Exploitation lets an unprivileged attacker bypass authentication, inject and run database commands, and steal data from Roundcube's database, without user interaction in high-complexity attacks. Roundcube fixed it in versions 1.6.16 and 1.7.1, and Shadowserver tracks over 523,000 exposed instances online.
cPanel disclosed a flaw in its CalDAV and CardDAV service, CVE-2026-87899, that lets any logged-in hosting account run code as root and take full control of the server. It lists no requirement beyond having an account, so on a shared server any customer, or anyone with a stolen customer login, could exploit it. cPanel also fixed a WP Toolkit bug, CVE-2026-87900, letting an account holder alter other accounts' databases, and a third issue, CVE-2026-68490, letting a local user read other accounts' calendars and contacts. Fixes ship across cPanel and WHM version 120 and later branches, including builds 11.134.0.57, 11.136.0.41, and 11.138.0.8 or later, plus WP Toolkit 6.11.3.
CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.
DepthFirst published research and exploit code for a Linux kernel use-after-free in the AF_UNIX socket subsystem, CVE-2026-80521, rated 7.8, that can escape a container and gain root on the host. The flaw sits in the garbage collector for file descriptors passed via SCM_RIGHTS, where a race condition can free linked sockets while a pointer remains on an internal list. AF_UNIX sockets are allowed by default in Docker and Kubernetes seccomp profiles, so the bug is reachable from inside a container. It was fixed upstream on August 6, but Ubuntu has not patched its 26.04, 24.04, or 22.04 LTS releases, including AWS, Azure, and GCP kernels. DepthFirst released a working exploit for 26.04.
Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.