Actively Exploited Linux Kernel Flaws, a Cisco Email Gateway Zero-Day, and a WordPress Core 'Click2Shell' Bug Top This Week's Threat Board
CISA KEV Linux kernel flaws actively exploited, Cisco email gateway 0-day patched, WordPress Click2Shell CSRF PoC, and M365 companion app retirement.
- CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and warns they are being exploited in the wild, one rated critical.
- Cisco patched an actively exploited zero-day in its email gateway appliances (September 12), while a new WordPress Core CSRF flaw dubbed 'Click2Shell' has a public proof-of-concept allowing PHP execution.
- Microsoft will retire the Calendar, People and Files Microsoft 365 companion apps on December 16, and admins must remove them from managed devices before that date.
What to do now
- Inventory every Linux host across district servers, appliances and virtual infrastructure; capture kernel versions, exposure, and owner, then apply vendor kernel updates and schedule reboots in an approved change window (live patching alone is not sufficient).
- Apply Cisco's September 12 email gateway patch immediately, verify the installed version, and review gateway logs for signs of zero-day exploitation such as unexpected outbound connections or new admin accounts.
- For WordPress Core, apply the latest security release as soon as it ships; until then restrict wp-admin/wp-login access by IP or VPN, enable a WAF rule set against CSRF patterns targeting admin-ajax.php, disable the built-in file editor, and enforce MFA for all elevated accounts.
- Remove the Microsoft 365 Calendar, People and Files companion apps from managed endpoints (Intune/Configuration Manager uninstall packages) before December 16 and notify staff of web-based alternatives.
- Enable automatic updates where feasible, verify offline backups are current and restorable, and confirm DMARC, DKIM and SPF are enforced to blunt government-agency impersonation phishing.
Related items
- Microsoft to retire Microsoft 365 Companion apps in December
- WordPress Takes Its Turn Leading the Open Website Alliance
- UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns
- WordPress Click2Shell flaw lets hackers execute PHP on the server
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
- Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
- U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
- CISA alerts of active exploitation of three Linux kernel flaws