Actively Exploited Linux Kernel Flaws, a Cisco Email Gateway Zero-Day, and a WordPress Core 'Click2Shell' Bug Top This Week's Threat Board

CISA KEV Linux kernel flaws actively exploited, Cisco email gateway 0-day patched, WordPress Click2Shell CSRF PoC, and M365 companion app retirement.

  • CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and warns they are being exploited in the wild, one rated critical.
  • Cisco patched an actively exploited zero-day in its email gateway appliances (September 12), while a new WordPress Core CSRF flaw dubbed 'Click2Shell' has a public proof-of-concept allowing PHP execution.
  • Microsoft will retire the Calendar, People and Files Microsoft 365 companion apps on December 16, and admins must remove them from managed devices before that date.

What to do now

  1. Inventory every Linux host across district servers, appliances and virtual infrastructure; capture kernel versions, exposure, and owner, then apply vendor kernel updates and schedule reboots in an approved change window (live patching alone is not sufficient).
  2. Apply Cisco's September 12 email gateway patch immediately, verify the installed version, and review gateway logs for signs of zero-day exploitation such as unexpected outbound connections or new admin accounts.
  3. For WordPress Core, apply the latest security release as soon as it ships; until then restrict wp-admin/wp-login access by IP or VPN, enable a WAF rule set against CSRF patterns targeting admin-ajax.php, disable the built-in file editor, and enforce MFA for all elevated accounts.
  4. Remove the Microsoft 365 Calendar, People and Files companion apps from managed endpoints (Intune/Configuration Manager uninstall packages) before December 16 and notify staff of web-based alternatives.
  5. Enable automatic updates where feasible, verify offline backups are current and restorable, and confirm DMARC, DKIM and SPF are enforced to blunt government-agency impersonation phishing.

Related items