π Plug & Pwn: Mapping the Windows PnP Auto-Install Attack Surface
Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely β no physical USB device required.
Look at how this attack works and how Netlas can help map exposed RDP infrastructure.
π https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
Windows Plug & Play can automatically install signed vendor software with SYSTEM privileges. With RDP USB redirection, this attack surface may also be reachable remotely β no physical USB device required.
Look at how this attack works and how Netlas can help map exposed RDP infrastructure.
π https://netlas.io/blog/windows_pnp_auto_install_attack_surface/
netlas.io
Plug & Pwn: Windows PnP Attack Surface - Netlas Blog
How Windows PnP auto-install becomes a privilege-escalation path, what Netlas can reveal about RDP exposure, and which controls reduce the risk.
π₯6π4β€1
CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE in The Events Calendar Plugin for WordPress, 9.8 Rating π₯
Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administratorβs password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/mEm8O
π Dork: http.body:"plugins/the-events-calendar"
Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
Two critical vulnerabilities were recently disclosed in The Events Calendar Plugin for WordPress. The first uses PHP Object Injection to execute arbitrary OS commands on the underlying server. The second allows an unauthenticated attacker to reset an administratorβs password, after which the attacker can upload a malicious plugin and take complete control of the site. The first vulnerability (CVE-2026-78006) is already being exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/mEm8O
π Dork: http.body:"plugins/the-events-calendar"
Read more:
https://www.wordfence.com/blog/2026/09/wordfence-argus-identifies-two-critical-unauthenticated-vulnerability-chains-leading-to-remote-code-execution-in-the-events-calendar-plugin/
β€2π₯2
CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating π₯
A recently disclosed vulnerability in Squid proxy allows a trusted client to poison the web cache and store arbitrary malicious content at any URL, which can then be delivered to other clients in response to their future requests.
Search at Netlas.io:
π Link: https://nt.ls/B7WF8
π Dork: http.headers.server:"squid"
Read more:
https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6
A recently disclosed vulnerability in Squid proxy allows a trusted client to poison the web cache and store arbitrary malicious content at any URL, which can then be delivered to other clients in response to their future requests.
Search at Netlas.io:
π Link: https://nt.ls/B7WF8
π Dork: http.headers.server:"squid"
Read more:
https://github.com/squid-cache/squid/security/advisories/GHSA-537g-4gfh-w7m6
β€2π₯2
CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating π₯
Cisco has disclosed multiple vulnerabilities in Cisco ASA, which allow a remote authenticated attacker to cause system instability or run arbitrary actions via improper exception handling. Other disclosed flaws can lead to improper access control, validation errors, and other security-relevant issues.
Search at Netlas.io:
π Link: https://nt.ls/ci994
π Dork: snmp.banner:"Cisco Adaptive Security Appliance" OR snmp.banner:"Cisco ASA" OR http.headers.set_cookie:"webvpn" OR http.body:"+CSCOE+"
Vendor's advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
Cisco has disclosed multiple vulnerabilities in Cisco ASA, which allow a remote authenticated attacker to cause system instability or run arbitrary actions via improper exception handling. Other disclosed flaws can lead to improper access control, validation errors, and other security-relevant issues.
Search at Netlas.io:
π Link: https://nt.ls/ci994
π Dork: snmp.banner:"Cisco Adaptive Security Appliance" OR snmp.banner:"Cisco ASA" OR http.headers.set_cookie:"webvpn" OR http.body:"+CSCOE+"
Vendor's advisory:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
π₯4β€2
11 new vulnerabilities in WordPress, no CVE assigned yet βοΈ
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
π Link: https://nt.ls/s3kOE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
WordPress 7.1.1 security release patches 11 vulnerabilities including stored XSS, path traversal, and other security flaws.
Search at Netlas.io:
π Link: https://nt.ls/s3kOE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
π4π₯2β€1
CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating π₯
Synology has disclosed 8 vulnerabilities in DiskStation Manager (DSM); 2 of them allow a remote unauthenticated attacker to read or write files and cause a denial of service on affected devices.
Search at Netlas.io:
π Link: https://nt.ls/dgzix
π Dork: tag.name:"synology_diskstation"
Vendor's advisory:
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13
Synology has disclosed 8 vulnerabilities in DiskStation Manager (DSM); 2 of them allow a remote unauthenticated attacker to read or write files and cause a denial of service on affected devices.
Search at Netlas.io:
π Link: https://nt.ls/dgzix
π Dork: tag.name:"synology_diskstation"
Vendor's advisory:
https://www.synology.com/en-global/security/advisory/Synology_SA_26_13
π2π₯2β€1
CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating π₯
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/Z9gGT
π Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
A recently disclosed improper input validation vulnerability in on-premises VeloCloud Orchestrator (VCO) allows a remote attacker to access privileged internal functionality and impact the VCO host. This vulnerability is known to be actively exploited in the wild!
Search at Netlas.io:
π Link: https://nt.ls/Z9gGT
π Dork: http.body:"single-spa-application:@velocloud/vco-header" OR http.body:"vco/branding.css" OR http.body:"vco/favicon"
Vendor's advisory:
https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
π₯3β€1
CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating π₯
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
π Link: https://nt.ls/B4TJE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
Another newly disclosed WordPress RCE vulnerability allows an unauthenticated attacker to execute arbitrary code under specific server conditions.
Search at Netlas.io:
π Link: https://nt.ls/B4TJE
π Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
π₯2β€1πΎ1
CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Rancher, 9.4 Rating π₯
An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.
Search at Netlas.io:
π Link: https://nt.ls/dtxM5
π Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
An unauthenticated attacker can plant malicious content that runs in the browser of anyone visiting the Rancher login page. This can leak the local administrator bootstrap password or hijack an active admin session, leading to complete control of the Rancher installation and its managed downstream clusters.
Search at Netlas.io:
π Link: https://nt.ls/dtxM5
π Dork: http.favicon.hash_sha256:2d7adbc74e7c8941927d04e702acbff577d219fef8617c8c3014d34ae395525b OR http.body:"<title>Rancher</title>" OR http.unknown_headers.key:"x_api_cattle_auth"
Vendor's advisory:
https://github.com/rancher/rancher/security/advisories/GHSA-992f-xh8r-jg2f
β€1π₯1
CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating π₯
Recently disclosed vulnerabilities in ServiceNow include an unauthenticated SQL injection flaw and multiple authorization bypasses.
Search at Netlas.io:
π Link: https://nt.ls/BxHZZ
π Dork: http.body:"<title>ServiceNow</title>" OR http.favicon.hash_sha256:41b71be5f4ce761e9772c2a5ab8afe5b3e7cfb56226597fc406155b868531a0e OR http.headers.set_cookie:"glide_user"
Vendor's advisory:
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
Recently disclosed vulnerabilities in ServiceNow include an unauthenticated SQL injection flaw and multiple authorization bypasses.
Search at Netlas.io:
π Link: https://nt.ls/BxHZZ
π Dork: http.body:"<title>ServiceNow</title>" OR http.favicon.hash_sha256:41b71be5f4ce761e9772c2a5ab8afe5b3e7cfb56226597fc406155b868531a0e OR http.headers.set_cookie:"glide_user"
Vendor's advisory:
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
π₯2β€1
CVE-2026-88771 & CVE-2026-887722: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gateway, both rated 9.5 βπ₯
Citrix disclosed two exploited vulnerabilities. The first (CVE-2026-88771) allows an unauthenticated attacker to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments. The second (CVE-2026-88772) leads to RCE or DoS. It affects appliances with DTLS enabled. These vulnerabilities are already being actively exploited in the wild, and PoCs exist!
Search at Netlas.io:
π Link: https://nt.ls/m5KaR
π Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
Citrix disclosed two exploited vulnerabilities. The first (CVE-2026-88771) allows an unauthenticated attacker to run arbitrary commands. It affects all NetScaler ADC and NetScaler Gateway deployments. The second (CVE-2026-88772) leads to RCE or DoS. It affects appliances with DTLS enabled. These vulnerabilities are already being actively exploited in the wild, and PoCs exist!
Search at Netlas.io:
π Link: https://nt.ls/m5KaR
π Dork (NetScaler Gateway): http.title:"citrix gateway" OR http.headers.set_cookie:"pwcount" OR http.favicon.hash_sha256:7b2fe2b7235b6645998edcae988ce1edaac40764c202abc3a4766db1b8ae6360 OR http.favicon.hash_sha256:3e8f8b98d8fe34a5e627c3033f0940777144effe4b5f588c67bfc6ba3bf106fa
Vendor's advisory:
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
β€1π₯1