Critical 10.0
CVE-2026-69676
Active Exploitation of Vulnerabilities in Windows, Zimbra, and GitLab
Vendor / product: Microsoft, Zimbra, GitLab
Event date: 2026-08-15
Public PoC: Yes
First tracked by RiskWire: 2026-10-07
Named threat actors
TA412
Sources & citations (14)
- R-Vision назвал три уязвимости сентября 2026 г., которые уже эксплуатируются в реальных атаках cnews.ru · 2026-10-06
- R-Vision назвал три уязвимости сентября, которые уже эксплуатируются в реальных атаках cisoclub.ru · 2026-10-06
- В фокусе RVD: трендовые уязвимости сентября habr.com · 2026-10-06
- Ataques exploram falhas no Ninja Forms e WPC Product Bundles do WordPress tugatech.com.pt · 2026-10-07
- Ninja Forms plugin flaw exploited to hack WordPress sites bleepingcomputer.com · 2026-10-06
- Уязвимость Ninja Forms активно используют для взлома WordPress-сайтов andreyex.ru · 2026-10-06
- Зловмисники використовують XSS-уразливості плагінів WordPress my.ua · 2026-10-06
- WordPress: Κρίσιμες ευπάθειες στα Ninja Forms και WPC Product Bundles for WooCommerce secnews.gr · 2026-10-07
- Ninja Forms mit über 500.000 Installationen: Angreifer verstecken Admin-Konten drweb.de · 2026-10-06
- Уязвимость в плагине Ninja Forms позволяет скрыть администратора сайта WordPress itzine.ru · 2026-10-06
- Злоумышленники взламывают сайты WordPress через два плагина и сохраняют скрытый доступ cisoclub.ru · 2026-10-07
- Hackers Exploit WordPress Plugin XSS Bugs to Plant Backdoors and Rogue Admin Accounts + Video undercodenews.com · 2026-10-06
- Hidden WordPress Admins: Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws + Video undercodenews.com · 2026-10-07
- Ninja Forms WordPress Flaws Are Being Exploited to Plant Backdoors and Rogue Admin Accounts + Video undercodenews.com · 2026-10-07
References
See CVE-2026-69676 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →