Severity Daily

IT and AI security incidents, checked against the primary source

Six of today’s nine stories end the same way: a real fix and a record that understates it

DAILY RECAP — Six of today’s nine stories end the same way: a real fix and a record that understates it

Written by

in

The day’s most important item is not the highest-scored one. Two WordPress plugins drew CVSS 9.8s for unauthenticated account takeover, and the thing to handle first is still N-able’s second N-central hotfix in two days. On Saturday, N-able told on-premises customers to install Hotfix 3 “immediately.” On Sunday it published CVE-2026-86218, a pre-authentication remote code execution flaw it scores 10.0, and pointed customers at Hotfix 4, build 2026.3.1.14. HF3 does not fix it. Every self-hosted administrator who did exactly what the vendor asked a day ago is not finished, and the change ticket they closed was the wrong one. N-central is an RMM server with reach into every endpoint it manages; N-able says its hosted instances are already patched, which leaves the on-premises operators to act on their own.

The day had a thread, and it runs through six of the nine stories: the fix is real, and the record that should point a defender at it understates it or leaves it out. Frontend Admin’s 9.8 was fixed 12 days ago in a release the changelog describes as improved permission checks. JFrog’s CVE for the Bifrost LLM gateway arrived 11 days after a release whose notes call an unauthenticated shared-object loader a path normalization issue. The top Grav record names one affected plugin where the vendor advisory it came from names three. NVD published nine curl records four days after the fixes shipped, with no CVSS, no CWE, and no CPE on any of them. And MemberDash’s 9.8 names no fixed version at all, while the product’s release-notes page returns HTTP 410 Gone and its only vendor reference redirects to a sales page.

That MemberDash record is the second thing to deal with, and it is the one with no clean answer: an unauthenticated visitor can set the password on any account, administrators included, with no notice to the victim, and there is nothing published to upgrade to. Frontend Admin, with more than 9,000 installations, at least has 3.29.13. Next is a clock rather than a score: the three form plugins in Ninja Forms, JetFormBuilder, and Redirection for Contact Form 7 all escape input before expanding shortcodes, all are fixed, and WPScan publishes the proof-of-concept code on September 16 and 17. Bifrost matters to a narrower set of readers, but it matters a lot to them, because management authentication is off by default and the gateway holds the provider API keys. The rest is build-level work: curl 8.22.0, Grav’s three 8.7s in the API plugin, and libpcap 1.10.7, whose highest-scored fix carries a commit note saying Include Security reported the problem in 2018. Last, and least urgent but the most instructive, a Perl module got its own CVE for building a SAML binding without a trust anchor — the exact omission Net::SAML2 made fatal at construction time five weeks earlier.

What is still open: MemberDash has no fixed version, and the vendor has published nothing resembling an advisory. The nine curl records and both of today’s late arrivals sit in NVD’s Received status, unanalyzed and unscored, so a version-matching scanner has nothing to match on. N-able says it has no confirmation of exploitation of the 10.0 but that unpatched systems remain at risk, and there is no KEV listing or federal deadline on any of today’s records. And the WPScan disclosure clock runs out in ten days.