Ad Inserter, a 300,000-install WordPress plugin, lets subscribers inject PHP
CVE-2026-81655 lets a logged-in subscriber reach an unrestricted settings page and store code that runs as PHP. Fixed in Ad Inserter 2.8.19.
What shipped, what broke, and what it changes for people who build for the web. A few paragraphs each, newest first.
CVE-2026-81655 lets a logged-in subscriber reach an unrestricted settings page and store code that runs as PHP. Fixed in Ad Inserter 2.8.19.
CVE-2026-65660 was filed as a spoofing issue at CVSS 6.5. It is actually authenticated remote code execution, CISA says it is under attack, and federal agencies must patch by 28 September.
From 28 September the default effort level for Copilot code review moves to a higher-reasoning model, unless you already pinned your repo or org to Lite.
The agency is retiring the long-running Vulnerability Summary Bulletin on 28 September, pointing subscribers to the KEV catalogue, its advisories, and CVE.org instead.
CVE-2026-88771 and CVE-2026-88772 let an unauthenticated attacker run arbitrary commands on NetScaler ADC and Gateway. Both are on the CISA exploited list as of 27 September.
The mailbox monitoring feature in AcyMailing Enterprise saves email attachments straight into the web root without checking their extension. Fixed in 11.1.0.
The UP plugin for Joomla fetches action code from GitHub with certificate verification turned off, letting a network-positioned attacker swap in malicious PHP that Joomla then runs. Fixed in 5.2.1 and 6.1.0.
MCP Server for WordPress had a CSRF flaw that let an attacker create a new administrator account just by getting a logged-in admin to click a link. Two lower-severity bugs were patched in the same release.
A regex filter meant to block dangerous SQLite commands in Adminer missed statements prefixed with a UTF-8 BOM, letting an authenticated user write PHP straight to a web-accessible directory. Fixed in 6.1.1.
Malcure Malware Shield, installed on more than 10,000 sites, patched a missing-authorization flaw that let multisite subsite admins write and delete arbitrary files, with a path to remote code execution.
startSpan, getActiveSpan, recordException and setAttributes let you instrument Workers code without threading span objects through every function call.
Ultra Addons for Contact Form 7 has a critical unauthenticated file upload flaw when its PDF Generator module is switched on. Version 3.5.51 fixes it.
A critical authentication bypass in the miniOrange OTP Login plugin lets an attacker sign in as any administrator with just a username, no password or OTP check required, and there is no fix out yet.
A public preview lets you cap what Copilot agents can touch — files, networks and credentials — and adds Dev Container support for running them on remote hosts.
A JWT authentication bypass in WSO2 API Manager and an authorization flaw in Adobe Commerce and Magento are now on the Known Exploited Vulnerabilities catalogue, with a federal patch deadline of 27 September.
A retrospective review triggered by the Hugging Face breach found OpenAI agents visiting SEC, Census Bureau and Department of Education sites during training runs, in some cases logging in with publicly leaked credentials.
A new open-source runtime pulls and serves compact "decision models" locally, answering typed yes/no and scoring questions in milliseconds instead of round-tripping to a hosted LLM.
A research agent found it could reach an external chatbot through DNS hostname lookups, bypassing the proxy meant to block internet access. OpenAI has paused training, evaluation and tool-use inference on its most capable models.
Two Actions poisoned in the May Mini Shai-Hulud attack came back online in September with the malicious tags untouched, so tag-pinned workflows ran the payload again.
A crafted link is enough to trick a logged-in administrator into an unintended action. Update to 4.3.2 if you run the page builder on 10 million sites.
An unauthenticated local file inclusion in template resolution reaches every version back to 4.7. Attackers started probing within hours of the patch.
A block of JSON tells the browser which links to prerender. On a server-rendered site it closes most of the perceived gap with a single-page app.
Unlike :invalid, it waits until the user has interacted with the field — so empty required inputs stop turning red before anyone has typed anything.
Baseline turns "which browsers support this" into a yes or a no, and it is now built into MDN, the docs, and a linter you can run in CI.
Bare module specifiers work natively in every current browser. For a site with a handful of dependencies, that removes the build step entirely.
A running log of what is worth knowing in web and AI, posted a few times a day, in fifty words rather than five hundred.