Generated · Archived snapshot 8 findings · 4 CVEs
On this page

Exploitation Report

Executive Summary

Active exploitation campaigns are targeting critical vulnerabilities across WordPress ecosystems, enterprise networking equipment, and widely deployed client software. Over 440,000 exploit attempts have been recorded against Super Forms and Elementor Pro plugins, with CVE-2026-32475 in Elementor Pro actively delivering webshells to compromise WordPress sites. Google has patched an actively exploited V8 type confusion zero-day (CVE-2026-85046) in Chrome, while Cisco has addressed a critical unauthenticated RCE (CVE-2026-20212) affecting ten Nexus 9000 switch models. These incidents demonstrate rapid weaponization of high-severity flaws across both web applications and infrastructure hardware.

Simultaneously, multiple zero-day and undisclosed vulnerabilities are emerging in security and productivity tools. A proof-of-concept for FalconFlank—a privilege escalation in CrowdStrike Falcon Sensor—has been publicly released, while NSO Group's Pegasus spyware leveraged an iMessage zero-click exploit to infect a Serbian activist's iPhone. Plex has issued urgent update advisories for multiple undisclosed flaws across its media server and desktop clients, with CVE identifiers still pending. Threat actors are also abusing legitimate software such as Node.js runtime for malware delivery in targeted campaigns against government, technology, and hospitality sectors since February 2026.

Threat actor activity shows increased sophistication in both automated and targeted operations. The Shai-Hulud infostealer worm has expanded its credential-harvesting scope to 469 locations across developer environments, CI/CD pipelines, and AI tool configurations. The "Phantom Deal" campaign conducts detailed reconnaissance for business email compromise via fake M&A scenarios, while an RMM phishing operation spanning 46 countries now targets the United States as its primary victim. Supply chain compromise of Coder's registry infrastructure delivered malicious Terraform modules, and the BraZetsu framework commercializes access to compromised Windows hosts through an Initial Access Broker marketplace model.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-32475#

  • Description: A critical vulnerability in the Elementor Pro plugin for WordPress that allows attackers to deliver webshell payloads and execute arbitrary commands on the server.
  • Impact: Full server compromise via webshell deployment, enabling arbitrary command execution, data theft, and persistence on compromised WordPress sites.
  • Status: Actively exploited in the wild; patch available in recent Elementor Pro versions.

CriticalActive exploitationPatchCVE-2026-14894#

  • Description: A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, leading to remote code execution.
  • Impact: Unauthenticated remote code execution via malicious file upload, enabling complete site takeover and server compromise.
  • Status: Actively exploited with over 440,000 exploit attempts observed; patch available.

HighActive exploitationPatchCVE-2026-85046#

  • Description: A type confusion bug in V8, Chrome's JavaScript and WebAssembly engine, affecting versions prior to 152.0.7977.82. This zero-day was actively exploited in the wild before patching.
  • Impact: Remote code execution via crafted web content, allowing attackers to escape the sandbox and compromise the browser and potentially the underlying system.
  • Status: Actively exploited zero-day; patched in Chrome 152.0.7977.82 released September 2026.

CriticalObservedPatchCVE-2026-20212#

  • Description: A critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that allows an unauthenticated, remote attacker to execute code as root. Part of a broader IOS XR hardening release bundling 7 umbrella CVEs, two rated 9.8.
  • Impact: Unauthenticated remote root code execution on core network infrastructure, enabling complete device compromise, network pivoting, and traffic interception.
  • Status: Patches released by Cisco; no workaround available for any IOS XR version.

HighPotentialInvestigate#

  • Description: A zero-day privilege escalation flaw (dubbed FalconFlank) that abuses the "office malicious macros remediation" feature in CrowdStrike Falcon Sensor. A proof-of-concept has been publicly released by researcher Chaotic Eclipse.
  • Impact: Local privilege escalation on endpoints running CrowdStrike Falcon Sensor, potentially allowing attackers to bypass security controls and gain SYSTEM-level access.
  • Status: Zero-day with public PoC; no CVE assigned yet; vendor response pending.

CriticalActive exploitationMonitor#

  • Description: An iMessage zero-click exploit used to deploy NSO Group's Pegasus spyware on an iPhone belonging to a Serbian student protest movement member, confirmed by Citizen Lab and SHARE Foundation.
  • Impact: Full device compromise without user interaction, enabling surveillance of communications, location tracking, and data exfiltration.
  • Status: Actively exploited in targeted attacks; no public patch information available at time of reporting.

Severity unknownStatus unknownPatch#

  • Description: Multiple undisclosed security vulnerabilities in Plex Media Server and Plex Desktop clients. Plex has requested CVE identifiers but has not disclosed technical details of the flaws.
  • Impact: Unspecified security impact; Plex urges immediate updates for all server owners and Desktop users.
  • Status: Patches available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0; CVE identifiers pending.

CriticalObservedPatch#

  • Description: A critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Hewlett Packard Enterprise has released patches.
  • Impact: Remote code execution on network infrastructure devices running ArubaOS-CX.
  • Status: Patched by HPE; exploitation status not explicitly confirmed in source.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities