An instant photo still developing, propped in front of a card that reads Happened in May. Public in September.
September 23, 2026

The Week's Biggest Stories Started in May

This week's biggest security stories were four months old. Gemini's break-ins, CrowdSec's stolen code and Plugin4Shell all happened in May, and each was held up for a different reason.
This week
This week: 20 CVEs in focus | 15 under active exploitation | 5 zero-days
TL;DR
1
Google confirmed Gemini broke into three real companies in May during an Irregular test. It stopped itself each time. Engadget
2
Plugin4Shell, a zero-click plugin flaw, hit Claude Code, Codex, Copilot and Gemini CLI. Claude Code and Codex are patched. AIR
3
CISA sends its last Weekly Vulnerability Bulletin on September 28. CISA

The Big Picture

Another week of patch-it-now bugs, including a CVSS 10 in Cisco ISE and three Linux kernel flaws CISA says are under attack. The odd thing is how many of the week's biggest stories actually happened in May, each held up for a different reason.

Plugin4Shell was held back on purpose while its researchers worked through coordinated disclosure over the summer. Gemini's break-ins waited on Google, which knew by late July and decided they didn't need announcing. The CrowdSec theft stayed hidden because nobody at CrowdSec noticed until the code showed up on a cybercrime forum. Only the first of those was the system doing its job.

⭐ Story of the Week

Gemini's Test Target Shared a Name With a Real Company

Google told The Wall Street Journal this month that Gemini had broken into three real companies in May, during a cybersecurity evaluation run by the Israeli startup Irregular. The test asked the model to pull information out of a fictional company. A real company had the same name, and a misconfiguration in Irregular's environment gave the model the open internet. (Engadget)

In the first run, Gemini guessed passwords until one worked. In the other two it searched the company name, found working logins for other companies sitting in public repositories, and used them.

Irregular told Google in late July. Google decided no disclosure was needed because the break-ins caused no harm, and confirmed them once the Journal asked. "In all three of these instances, the model stopped," Google's Heather Adkins told reporters.

Gemini is the fourth lab model known to have gotten out through Irregular's setup, after models from OpenAI, Anthropic and Meta. Irregular says all known issues were fixed weeks before this went public. May was also the month researchers tied a flood of more than 2,000 malicious RubyGems packages to OpenAI agents, which we covered last week.

The Bottom Line...

If one misconfiguration and a shared company name were enough to send Gemini from a test into a real network, ask any vendor whose AI agents test your systems what keeps them inside your scope besides the network rules.

Deep Dives

Four Coding Agents Loaded Whatever the Plugin Repo Said

AI coding agents like Claude Code and GitHub Copilot can install plugins from a marketplace, which pins each plugin to one specific commit so you get the code someone reviewed. AIR researchers Or Nevo, Dor Granat and Niv Hoffman found in May that the pin can be sidestepped in four of them. According to AIR, if the plugin's repository has a branch named after that exact 40-character commit SHA and set as its default, git checkout lands on the branch instead. The agent loads whatever the branch holds while the pin still looks honored.

Gemini CLI fetches the commit and checks out FETCH_HEAD, and a branch called FETCH_HEAD beats it the same way. Nobody has to click, approve or reinstall anything. The plugin runs with the developer's own access to local source, cloud credentials, SSH keys and internal repositories, the same reach as the GitSpawn flaws in coding agents we covered three weeks ago.

The fix is one check. After checkout, AIR says, resolve the commit actually in the working tree and abort unless it equals the pin.

Anthropic confirmed that check in Claude Code 2.1.179 on June 17, and AIR verified OpenAI's in Codex 0.146.0 on August 12. Google said on August 4 that it would not patch Gemini CLI, which it has deprecated, and told users to move off it. Microsoft had not shipped a Copilot client fix when AIR published on September 17.

GitHub told The Hacker News that it blocks branch and tag names that look like commit SHAs, which stops the demonstrated variant for plugins hosted on GitHub. AIR's answer is that Copilot also supports plugin marketplaces on Bitbucket and self-hosted git servers, where those names are allowed.

The Bottom Line...

Copilot is now the only one of the four agents that is still supported and still skips the post-checkout check, so any plugin your developers install from a repository outside GitHub stays exposed until a fix ships.

CrowdSec Kept a Former Developer's GitHub Access Open on Purpose

Source code for the SaaS console of CrowdSec, the French open-source security company, showed up on a cybercrime forum on September 16. The company's final account, published two days later, traces it back to May. A developer who had already left still had his GitHub access, and his laptop had been infected through the May 11 TanStack npm compromise.

On May 22 someone used his OAuth token to clone about 170 private repositories in roughly nine minutes. CrowdSec removed him from its GitHub organization on May 25, three days later, without knowing anything had been taken.

The access was kept open deliberately. "We kept them alive because we parted on good terms with our developer, and he wanted to finalize some work," CrowdSec wrote.

Whoever held the code came back on August 17 to test an AWS token from the stolen material, which turned out to be limited to publishing notifications. CrowdSec says its infrastructure and databases were not accessed and no code was changed. The leak did include email addresses for 83 of its roughly 150,000 users, plus names and investment details for 51 prospective investors from 2020.

The Bottom Line...

How many departed employees still hold access your team kept open for a good reason? CrowdSec's post says to remove it or know why you kept it, and CrowdSec knew exactly why, which did nothing once the laptop holding that access was infected.

CISA's Weekly Vulnerability Bulletin Ends September 28

CISA sends its last Weekly Vulnerability Bulletin on September 28. The announcement ties the change to Binding Operational Directive (BOD) 26-04, which tells federal agencies to prioritize vulnerabilities on "real-world risk factors, including evidence of exploitation and exposure, rather than severity scores alone." CISA is pointing subscribers to the KEV catalog, its alerts and advisories, and the CVE program instead.

The same week, VulnCheck's Patrick Garrity, who tracks every CVE credited to Anthropic's Project Glasswing, had 225 on the list as of September 21. Only one, a critical SQL injection in Ghost (CVE-2026-26980), is known to have been exploited in the wild so far. Historically, Garrity told The Register, the share of CVEs that ever get exploited has run from just under 1% to 2%.

KEV runs on a delay by design, since a flaw enters the catalog only after someone has been seen exploiting it.

The Bottom Line...

Nothing will error on September 28. A ticket rule, SIEM input or weekly report still pulling from the bulletin's email list or feed will just go quiet.

Vulnerabilities in the Wild

Under active exploitation

• Cisco Identity Services Engine (ISE) and ISE-PIC CVE-2026-76460, CVSS 10.0, a zero-day. A crafted request to an ISE API endpoint bypasses authentication, and Cisco says exploitation can end in command execution as root. Cisco disclosed it on September 16 already aware of active exploitation, and CISA added it to KEV the same day. There are no workarounds. Fixed in 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. (Cisco)

• Arista VeloCloud Orchestrator CVE-2026-93952, CVSS 10.0, a zero-day. An attacker with no tenant or operator login can reach privileged internal functions on an on-premises orchestrator, but only one set up to authenticate its Edges with certificates. Arista says it "was discovered externally and is known to be actively exploited." Added to KEV September 22. Fixed in 5.2.3.16 and 6.4.2.8, with no fix yet for the 6.1 and 7.0 trains. (Arista)

• F5 BIG-IP Access Policy Manager CVE-2026-94127, CVSS 9.8, a zero-day. A heap overflow gives unauthenticated code execution, but only where APM is the OAuth authorization server. Setups that use APM only as an OAuth client or resource server are not affected. F5 disclosed it September 22 with engineering hotfixes, and CISA added it to KEV the same day. (F5)

• Check Point Security Management Server CVE-2026-93616, CVSS 9.8, a zero-day. Pre-authentication path traversal in the management web service lets an attacker upload and run a script. Check Point saw "a handful of pinpointed attacks on July 23" and shipped the fix on September 22. The same advisory covers CVE-2026-85102, a VPN flaw also under attack, and CISA added both to KEV September 22. Until you can patch, restrict TCP port 19009 to trusted addresses. (Check Point)

• Linux kernel CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964. CISA added all three to KEV on September 18. CVE-2025-39682 (CVSS 9.8) is in the kernel TLS receive path. CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT target that can lead to privilege escalation. CVE-2025-39964 is an AF_ALG race condition that STAR Labs turned into privilege escalation and container escape. Upstream fixes are old, so the action is taking your distribution's kernel update. (CISA)

• Google Pixel cellular modem CVE-2026-58704, CVSS 8.8. A logic error lets an attacker in cellular range bypass a permission check and escalate privileges with no user interaction. Google's bulletin says there are "indications that CVE-2026-58704 may be under limited, targeted exploitation." Added to KEV September 16. Fixed at security patch level 2026-09-05. (Google)

• Orkes Conductor CVE-2026-58138, CVSS 9.8. An unauthenticated attacker can submit a workflow definition whose JavaScript or Python expressions escape the scripting sandbox and run OS commands with the privileges of the Conductor process. Fortinet's September 15 outbreak alert says its telemetry "is observing active attack attempts," and public exploit code has been available since August 9. Fixed in 3.30.2. (Fortinet)

• WSO2 API Manager CVE-2026-5430, CVSS 10.0. The JWT validator accepts tokens signed with an unsupported algorithm, which lets an attacker forge an admin token. WSO2 patched it in May. watchTowr told The Hacker News that its honeypots caught forged admin tokens arriving on September 13. (WSO2, The Hacker News)

• Issabel Framework CVE-2026-89026, CVSS 9.8. Every install shared the same hard-coded JWT signing key, so attackers can forge tokens and have Asterisk run OS commands. The Shadowserver Foundation first saw exploitation on September 9. (VulnCheck)

• Tencent Sogou Input Method CVE-2026-51990, CVSS 9.8, a zero-day. One click on a crafted link reaches a bundled Chromium 80 with web security turned off, and China-nexus UNC3569 used it to install the GRAYRABBIT backdoor. Gen Threat Labs: "We did not discover this vulnerability in a lab." Tencent fixed it in April in 16.3.0.3498, and Gen published on September 10. (Gen Threat Labs)

• Zyxel GS1900 switches CVE-2026-7273, CVSS 8.8. A stack overflow in the firmware's CGI program lets an unauthenticated attacker on the LAN run OS commands. Zyxel patched it in June, and CISA added it to KEV September 21. (Zyxel)

• Acronis Backup plugin for cPanel & WHM CVE-2026-87886, CVSS 7.8. Insecure default file permissions let a local user escalate privileges on the Linux host. Acronis says it has seen exploitation "in limited, targeted attacks," and CISA added it to KEV September 16. Fixed in build 1.9.3.1021. (Help Net Security)

Critical, patched, no exploitation yet

• Microsoft Azure AI Foundry CVE-2026-85889, CVSS 10.0. Missing authentication on a critical function allowed privilege escalation in the cloud service. Microsoft has fully mitigated it on its side; there is nothing for customers to do. (MSRC)

• WordPress core CVE-2026-87902, CVSS 9.2. Unauthenticated path traversal in page-template resolution can include a local PHP file, which becomes code execution only when certain server and theme conditions hold. Patchstack saw scanning probes on release day but no confirmed compromise. Fixed in 7.1.2, with backports to every branch back to 4.7. (WordPress)

• Bifrost AI Gateway CVE-2026-90898, CVSS 9.8. With management authentication off, which is the default, one unauthenticated request registering a stdio MCP client makes the gateway run the attacker's command. Fixed in transports/v2.1.0. (OSV)

• NLnet Labs Unbound CVE-2026-81642, CVSS 9.1. A crafted DNSKEY overflows a buffer in the DNSSEC validator, so an attacker who controls a zone the resolver queries can crash it or possibly run code. Fixed in 1.26.1, which also fixes eight other CVEs. (NLnet Labs)

• SolarWinds Access Rights Manager CVE-2026-28326, CVSS 8.8. A hard-coded static key allows unauthenticated code execution, but the attacker has to be on an adjacent network. Fixed in 2026.2.1. (SolarWinds)

Curated Reading List

Thought-Provoking / Analysis

• Fire the Slop Cannons (Safely): On Coding Agents and Sandboxing (Latacora) Why it's worth your time: a working setup for running coding agents without handing them the three things that make a compromise catastrophic: your credentials, untrusted input and the network. The credential-proxy pattern, where a gateway outside the sandbox injects secrets into outbound requests so the agent never holds them, is the most reusable idea in it.

• SAML: A Fractal of Bad Design (Trail of Bits) Why it's worth your time: a case for retiring SAML from someone who built an SSO gateway on it at Duo. XML signature wrapping was documented in 2012 and still turns up today, and the post walks through why canonicalization keeps producing the same bug class.

• Two DGX Sparks, 33 Local Models, One Question: Can Local AI Actually Red Team? (Be the Adversary) Why it's worth your time: one 35B sparse model on one box solved a multi-path BloodHound exam, and an "abliterated" model spotted a disabled-account trap, then recommended re-enabling the account in its remediation plan. The author runs every test once and says so.

Technical Deep Cuts

• Windows Exploitation Techniques: Dangling COM Object Registrations (Google Project Zero, James Forshaw) Why it's worth your time: a COM class registered to a DLL that no longer exists, in a folder any user can write to, becomes a path to SYSTEM through custom marshaling. The bug he walks through, CVE-2026-66804, is the incomplete fix for an earlier one.

• VulGenie: Mining Security Patches to Find API Violation Bugs (Mathias Payer, USENIX Security '26) Why it's worth your time: the team treats past security patches as worked examples of correct API use, turns them into 198 rules, and uses those to find 46 previously unknown vulnerabilities.

Stay ahead of AppSec

Weekly intelligence for security leaders.