One executes unsigned code before operating-system defenses start; the other turns a user-creatable ProgramData DLL path into SYSTEM code execution on unpatched Windows.
The firmware can continue to report Secure Boot enabled after the handler is overwritten.
Vendor-signed UEFI Shell applications used by Acer, Dell, Eurosoft, Framework, Getac, Lenovo, MinisForum, MSI, Seagate, Uniwill, and unidentified OEMs on UEFI systems.
Secure Boot bypass and persistent pre-OS code execution
The bypass comes from code already accepted by the platform trust database, making signature trust the route around the control it is meant to enforce.
With physical access—or administrative control sufficient to stage and boot an accepted shell—an attacker can use the shell's memory-write command to overwrite the Secure Boot security-handler pointer.
Unsigned UEFI or kernel code can then run before operating-system and EDR initialization, with firmware still reporting Secure Boot enabled and firmware-level persistence possible.
The response is incomplete: pre-fix images remain accepted, revocation is not complete, and we still do not know the full certificate, hash and device population or whether remediation reaches end-of-life hardware.
A dangling system-wide COM registration resolves beneath user-creatable ProgramData.
Microsoft Windows Cross Device Service and its system-wide COM registration on supported Windows 10 and Windows 11 installations.
Local privilege escalation to NT AUTHORITY\SYSTEM
This is more than publication of a patched CVE: public end-to-end code now crosses the standard-user-to-SYSTEM boundary on affected unpatched builds.
The standard user plants the missing DLL, keeps the user-accessible CreateObjectTask's SYSTEM service active and passes it a custom-marshaled object; COM then loads the DLL into a SYSTEM dllhost process.
Microsoft identifies the fixed build boundaries, and patched systems close this path.
The revocation question is not applicable to the disclosed remediation; “unknown” avoids claiming either complete or incomplete revocation.
Check Point Security Gateway and Spark Firewall appliances terminating Remote Access or Site-to-Site VPN connections.
An unauthenticated client that can reach affected Remote Access or Site-to-Site negotiation can supply crafted certificate data and execute arbitrary code on the gateway.
Today's change is exploitation status: Check Point says the wave began September 12, and CISA added CVE-2026-85102 to KEV on September 22.
F5 BIG-IP Access Policy Manager, an enterprise access and authentication gateway appliance.
Exposure is limited to virtual servers combining an APM access policy with an OAuth profile; there, crafted unauthenticated traffic triggers a heap overflow and arbitrary code execution.
F5 confirms exploitation in the wild, and CISA included CVE-2026-94127 in KEV.
The published remediation does not revoke pre-fix BIG-IP images; they remain accepted.
WordPress Core, the PHP content-management system used by self-hosted websites.
A double-encoded pagename survives early sanitization, is decoded during template resolution and escapes the theme root through an unchecked local PHP include.
The reproduction required a published page, a qualifying top-level page-* theme directory and a usable local PHP path; the demonstration used PEAR's pearcmd.php to write and include controlled PHP.
WordPress has fixed the affected branches, and public proof-of-concept code exists.
Check Point Security Management, Multi-Domain Management, Log Server and SmartEvent systems used to administer Check Point security infrastructure.
A client that can reach the management web service on TCP/19009 can use directory traversal and file upload to execute an arbitrary-path script or load an arbitrary Java class without credentials.
Check Point says a handful of customers were attacked through this path.
Meta Muse, a personal AI agent whose macOS client controls a cloud agent and user-authorized apps, services and linked devices.
An unprivileged process could rewrite Muse's dictation endpoint, but credential capture still required the victim to use voice dictation afterward.
The credential could then expose sessions and authority already granted across connected services and devices; the researcher demonstrated device location and Bluetooth Low Energy scans.
lwIP MQTT Client Application, a lightweight TCP/IP component compiled into embedded, IoT and industrial device firmware.
An oversized or malformed MQTT header can advance msg_idx beyond the fixed receive-buffer limit and write attacker-supplied bytes into adjacent memory.
The attacker must control or intercept the broker connection; the memory corruption is confirmed, but controlled execution on a shipping device and the downstream product population remain unproven.
Upstream now bounds msg_idx before the write and tests malformed input.
Linux kernel Bluetooth HIDP support for Classic Bluetooth input devices.
With an established HIDP session, an attacker can send an empty interrupt or control frame whose absent first byte is nevertheless accessed by the kernel.
We do not know whether that read produces an observable disclosure, a reliable crash or a stronger effect, and a released fixed version is not yet established.
D-Link DIR-X1860 and DIR-X1860Z embedded Wi-Fi routers.
A client that can reach the ubus JSON-RPC service on TCP/23355 can call routerd.passwd_set without a session, choose a new administrator password and then log in normally.
D-Link confirms a DIR-X1860Z fix, but the evidence does not establish complete remediation across the affected deployments.
D-Link DIR-600 B5 embedded Wi-Fi routers running the tested legacy firmware.
An unauthenticated CRLF injection through /session.cgi can plant a chosen uid cookie; if the administrator processes that response and then logs in, the uid can be reused from another client.
No patch is published for the demonstrated DIR-600 path.
Linux kernel Bluetooth BNEP networking, used by Linux PAN clients and access points.
A peer with an established Bluetooth PAN session can send truncated data, control, filter or extension frames; the remaining paths read beyond the logical skb, and one control form can fall through to Ethernet delivery.
The correction has been merged upstream, but we do not know whether the old behavior yields an observable disclosure, reliable crash, memory corruption or control-flow effect on a hardened distribution kernel.
No additional findings today.
No new zero-click capability was confirmed; missing vulnerability rows in the August Android bulletin still prevent a clean quiet finding.
CERT/CC turned the signed-shell Secure Boot bypass into a concrete multivendor catalog with application hashes.
No new mobile-platform capability was confirmed; incomplete August Android data and restricted Mozilla evidence leave unresolved gaps.
Signed-UEFI-shell scope, exploited Check Point management execution and reproducible WordPress template execution changed today.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.