Security Digest: September 4, 2026 - 61 Critical Vulnerabilities

Today’s risk is broad and immediate: Microsoft cloud services, WordPress plugins, industrial and lab tooling, and multiple MOOS/Open-source components all have newly disclosed critical flaws that can lead to privilege escalation, remote code execution, authentication bypass, or full account takeover. Several issues are already exploitable without authentication, and a number of the high-risk cases involve exposed web endpoints or hard-coded credentials.

· 10 min read

Executive Summary

Today’s risk is broad and immediate: Microsoft cloud services, WordPress plugins, industrial and lab tooling, and multiple MOOS/Open-source components all have newly disclosed critical flaws that can lead to privilege escalation, remote code execution, authentication bypass, or full account takeover. Several issues are already exploitable without authentication, and a number of the high-risk cases involve exposed web endpoints or hard-coded credentials.

Act now: patch or disable the affected services, rotate exposed credentials, and restrict access to admin and API endpoints until vendor fixes are in place.

Critical Vulnerabilities

CVE-2026-83711: Azure AD B2C authorization bypass

  • Impact: Unauthorized attackers can elevate privileges over the network.
  • Affected Systems: Microsoft Azure Active Directory B2C.
  • Immediate Action: Review B2C tenant exposure and restrict administrative paths immediately.
  • Mitigation: Apply Microsoft guidance and monitor for unexpected privilege changes.

CVE-2026-70352: Azure AI Language missing authentication

  • Impact: Remote attackers can trigger a critical function and elevate privileges.
  • Affected Systems: Azure AI Language.
  • Immediate Action: Limit network access to the service and verify auth controls.
  • Mitigation: Patch when available and audit service permissions.

CVE-2026-85509 / 85506 / 85507 / 85508 / 85504: FreeIPMI stack overflows

  • Impact: Malformed BMC responses can crash tools and may enable code execution.
  • Affected Systems: FreeIPMI before 1.6.19, including ipmi-oem Dell and Fujitsu paths.
  • Immediate Action: Upgrade FreeIPMI now; isolate management networks.
  • Mitigation: Move to 1.6.19 or later and block untrusted BMC traffic.

CVE-2026-15354: ACPT WordPress plugin privilege escalation

  • Impact: Anonymous attackers can overwrite user email/password and take over admin accounts.
  • Affected Systems: ACPT (Premium) up to 2.0.66.
  • Immediate Action: Disable public forms or the plugin until patched.
  • Mitigation: Update immediately and review all user credentials.

CVE-2026-11613: Divi Ajax Filter local file inclusion

  • Impact: Unauthenticated attackers may include PHP files and gain code execution.
  • Affected Systems: Divi Ajax Filter up to 5.1.2 when custom templates are enabled.
  • Immediate Action: Disable the vulnerable template setting and patch.
  • Mitigation: Restrict PHP execution in uploads and validate template configuration.

CVE-2026-82923: AI Website Builder REST API abuse

  • Impact: Unauthenticated attackers can install plugins/themes, write files, delete content, and potentially execute code.
  • Affected Systems: AI Website Builder WordPress plugin 1.0.0.
  • Immediate Action: Remove or isolate the plugin now.
  • Mitigation: Apply an update and block exposed REST routes.

CVE-2026-69657 / 70403 / 85148 / 85146 / 85147: XING CPTrans-ME-X and SmartIT Desktop Manager credential flaws

  • Impact: Default or hard-coded passwords enable unauthorized access; one SmartIT issue exposes SSH credentials from source.
  • Affected Systems: XING CPTrans-ME-X; SmartIT Desktop Manager by Lightstar.
  • Immediate Action: Rotate credentials and remove exposed admin access.
  • Mitigation: Replace fixed secrets, patch vendor releases, and audit for unauthorized logins.

CVE-2026-85437 / 85438 / 85440 / 85509: MOOS-IvP and FreeIPMI memory corruption

  • Impact: Crafted inputs can overflow buffers and may lead to remote code execution.
  • Affected Systems: MOOS-IvP through 24.8.1; FreeIPMI before 1.6.19.
  • Immediate Action: Upgrade immediately and isolate affected systems.
  • Mitigation: Restrict untrusted message sources and monitor for crashes.

CVE-2026-85428 / 85424 / 85430 / 85431 / 85432 / 85433 / 85434 / 85435 / 85440 / 85442 / 85445 / 85446 / 85447 / 85449 / 85451 / 85455 / 85427 / 85439 / 85425 / 85426 / 85429 / 85424: MOOS and MOOS-IvP authentication, injection, and denial-of-service issues

  • Impact: Attackers can write variables, spoof identities, inject commands, trigger crashes, or exhaust resources.
  • Affected Systems: core-moos, essential-moos, and MOOS-IvP through the versions listed above.
  • Immediate Action: Restrict network exposure and disable unauthenticated listeners immediately.
  • Mitigation: Apply vendor fixes, segment MOOS traffic, and alert on unexpected node identities or message spikes.

CVE-2026-85085 / 85094: Canva Android privileged WebView issues

  • Impact: External content in a privileged WebView can interact with user sessions.
  • Affected Systems: Canva Android app before 2.376.0.
  • Immediate Action: Force app updates and review mobile access policies.
  • Mitigation: Upgrade to 2.376.0 or later.

CVE-2026-80098 / 62916 / 69857 / 70178: Microsoft cloud authorization flaws

  • Impact: Attackers can bypass auth or elevate privileges in Azure Cosmos DB, Entra ID, Copilot Studio, and Microsoft Fabric.
  • Affected Systems: Microsoft cloud services named above.
  • Immediate Action: Review privileged roles and conditional access policies now.
  • Mitigation: Apply Microsoft patches and inspect audit logs for suspicious role changes.

CVE-2026-76169 / 84469 / 85184: fastify and @fastify/middie access-control bypasses

  • Impact: Malformed or absolute-form requests can skip middleware, validation, or protected handlers.
  • Affected Systems: fastify before 5.12.2; @fastify/middie before 9.3.4.
  • Immediate Action: Upgrade immediately and review any route-level auth assumptions.
  • Mitigation: Pin patched versions and test auth paths with malformed requests.

CVE-2026-57777 / 85402 / 85379 / 85397 / 85398 / 85399 / 85225 / 85403 / 85380: SQL injection and SSRF across web apps

  • Impact: Attackers can read, modify, or delete database data; one CMS issue enables SSRF.
  • Affected Systems: WooCommerce, Doctor Appointment System, Hospital Information System, and light0011 CMS.
  • Immediate Action: Patch exposed web apps, disable public admin endpoints, and block database access from the internet.
  • Mitigation: Validate inputs server-side and review logs for suspicious query patterns.

What to Do Now

  1. Patch or disable exposed services first: Microsoft cloud integrations, WordPress plugins, Fastify apps, FreeIPMI, MOOS/MOOS-IvP, and any internet-facing web apps.
  2. Rotate credentials immediately: Replace any default, fixed, or hard-coded passwords in XING and SmartIT environments.
  3. Restrict access: Put management interfaces, REST APIs, and admin panels behind VPN, allowlists, or temporary firewall rules.
  4. Verify exposure: Check whether public forms, upload paths, WebViews, or unauthenticated MOOS listeners are reachable.
  5. Watch for abuse: Review logs for privilege changes, unexpected plugin installs, unusual node identities, command execution, and SQL error spikes.

Verification steps: confirm installed versions against the affected ranges, check whether any vulnerable WordPress plugins are active, and search for unauthorized account or route changes. For MOOS deployments, confirm whether UDP listeners or HTTP servers are exposed beyond trusted networks.

Monitoring recommendations: alert on new admin accounts, password resets, plugin/theme installs, BMC anomalies, repeated malformed requests, and sudden process crashes or memory growth.

Related Resources

  • Internal: See the upcoming incident-response brief on today’s Microsoft, WordPress, and industrial-control exposures.
  • Official vendor advisories: Microsoft Security Response Center, WordPress plugin advisories, Fastify release notes, FreeIPMI project updates, and vendor notices for Canva, Snowflake, and MOOS/MOOS-IvP.

Keep reading