NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
← Back to Intel Center
SECURITY INTEL · DAILY
Link copiedRSS

2026-09-02 Daily Security Intelligence

6 itemsTop severity 10.0 (Critical)CSSA 2 · CVE 2 · Poisoning 2

CSSA Exclusive Early Warning2

CSSA Exclusive Early Warning10.0 Critical

Drogon ORM component SQL injection leading to WHERE clause bypass and data disclosure

An attacker exploits a defect in RestfulController where JSON filter operators are not validated, injecting malicious SQL fragments into the WHERE clause. The Criteria constructor only intercepts the in operator and concatenates other strings directly into the SQL statement, allowing the attacker to craft always-true logic or blind-injection payloads to bypass access control and extract sensitive database records.

Component
Drogon is a high-performance asynchronous C++ web framework whose ORM module aims to simplify database interaction and accelerate API development thro…
Type
SQL Injection (CWE-89)
Repo
Remediation
  • Enforce an operator allowlist that strictly limits permitted SQL operators, ensuring every user-supplied operator is validated before participating in SQL construction, and avoid arbitrary string concatenation that enables injection.
CSSA Exclusive Early Warning10.0 Critical

wg-easy authentication interface lacking login attempt limits allowing second-factor bypass and full system control

After obtaining a legitimate account password, an attacker can send unlimited brute-force requests against the TOTP second-factor interface. Because the system imposes no limit on failed authentication attempts, implements no account lockout, and lacks audit logging, the attacker can guess a valid code with high probability in a short time, bypass two-factor authentication and take over administrator privileges.

Component
wg-easy is a web-based WireGuard VPN management panel whose core architecture uses a RESTful API and database interaction model to simplify VPN config…
Type
Improper Restriction of Excessive Authentication Attempts (CWE-307)
Repo
Remediation
  • Introduce a session- or account-scoped failure counter in backend logic, set a reasonable maximum attempt threshold that triggers temporary lockout, and combine exponential backoff with mandatory security-event audit logging to contain automated brute-force attacks.

CVE Intelligence2

CVE-2026-76657CVSS 10.0 Critical2026-09-02

HPE Networking Fabric Composer API authentication bypass leading to full host control

Vulnerabilities were found in the HPE Networking Fabric Composer API that may allow an unauthenticated remote attacker to bypass existing authentication controls. Successful exploitation can grant the attacker administrator privileges and lead to complete control of the HPE Networking Fabric Composer host. The issue is improper authentication (CWE-287); the attack vector is network-based with low complexity, requiring no user interaction and no privileges. It affects all unpatched HPE Networking Fabric Composer deployments. An attacker only needs to send crafted remote requests to obtain the highest privileges without authentication.

Component
HPE Networking Fabric Composer is network orchestration and management software from HPE used to automate configuration and management of network infrastructure.
Risks
  • From ordinary user to administrator: An attacker can obtain administrator privileges directly without any initial credentials
  • Complete system control: An attacker can use this vulnerability to execute arbitrary code on the victim system, and with administrator privileges install programs, view/modify/delete data or create new accounts with full privileges
  • No user interaction required: Through remote network requests (T1190), an attacker can trigger the vulnerability and achieve remote code execution without any target-user interaction
Source
Remediation
  • Deploy firewall rules at the network boundary to restrict unauthorized access to API endpoints
  • Monitor API access logs to identify and block anomalous unauthenticated request behavior
CVE-2026-76658CVSS 10.0 Critical2026-09-02

HPE Networking Fabric Composer SSH daemon remote code execution leading to complete system control

A vulnerability has been found in the SSH daemon of HPE Networking Fabric Composer that may allow an unauthenticated remote attacker to gain administrative access to a vulnerable AFC host. Successful exploitation may allow the attacker to execute arbitrary commands as a privileged user on the underlying operating system, resulting in complete system control. The vulnerability affects all unpatched HPE Networking Fabric Composer deployments; an attacker can launch a remote network attack without authentication, with low complexity and no user interaction required.

Component
HPE Networking Fabric Composer is network orchestration and management software from HPE used to simplify and automate data-center network configuration and management.
Risks
  • Complete system control: An attacker can execute arbitrary commands as a privileged user on the underlying operating system, resulting in complete system control
  • Unauthenticated remote attack: An attacker needs no credentials to exploit the vulnerability remotely over the network and obtain administrative access to the AFC host
  • High impact scope: With a CVSS score of 10.0, the vulnerability seriously affects confidentiality, integrity and availability, and the scope is changed (Scope Changed)
Source
Remediation
  • Immediately isolate affected HPE Networking Fabric Composer hosts and restrict their network access
  • Monitor the SSH daemon for anomalous login attempts and command-execution logs

Package Poisoning2

Package Poisoningnpm2026-09-02

eslint-rxjs@1.0.1 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
4c596e46c9fc02b6f12f5e64ff523ca2
Package Poisoningnpm2026-09-02

chromatitle-dev@1.0.0 flagged as malicious

This version was found communicating with a malicious domain and executing malicious commands. Audit your dependencies and pin safe versions immediately.

MD5
fab750ab2964222e8cae6ba9e358d0ce