Vanderbilt REDCap · Netcore NBR200V2 · OrdaSoft Joomla Gallery Extension
Date: 2026-09-21 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
New EUVD data highlights multiple critical vulnerabilities published within the reporting window, including unauthenticated remote code execution in Vanderbilt REDCap and several critical flaws in Netcore NBR200V2 routers. The Netcore issues affect firmware management, backup restoration and network configuration functions and should be treated as high priority where exposed. New reporting also describes npm malware that executes during normal package runtime, bypassing install-script controls. Three Linux kernel vulnerabilities remain actively exploited under CISA KEV with remediation due today.
Critical Vulnerabilities
CVE-2026-90817 — Vanderbilt REDCap
- Severity: CVSS 9.8
- EPSS: 0 — supplied EUVD value; this may reflect incomplete scoring rather than low practical risk.
- Technical detail: An unauthenticated remote code execution vulnerability affects the survey passthrough routing and data-import processing logic in REDCap 13.3.0. The supplied data indicates that a remote attacker can manipulate processing inputs without prior authentication. REDCap deployments containing research, healthcare or personal data are particularly sensitive.
- Exploitation status: NEW — published 2026-09-20; exploitation was not confirmed in the supplied data.
- Remediation: Upgrade to a vendor-fixed release when available. Until then, restrict REDCap access to trusted networks or VPN, review internet exposure and monitor web, application and process-launch logs for anomalous requests or command execution.
CVE-2026-94097 — Netcore NBR200V2
- Severity: CVSS 10.0
- EPSS: 0 — supplied EUVD value; validate independently.
- Technical detail: The vulnerability affects the CGI diagnostic endpoint in firmware 1.3.241127.071246. The supplied description is truncated and does not establish authentication requirements or exact impact, but the maximum severity and router-management context indicate potential compromise of an edge device.
- Exploitation status: NEW — published 2026-09-20; exploitation was not confirmed.
- Remediation: Identify affected devices and apply vendor firmware if available. Remove management interfaces from the public internet, restrict administrative access, preserve configurations for forensic comparison and monitor for unauthorized DNS, routing or firmware changes.
CVE-2026-94100 / CVE-2026-94101 — Netcore NBR200V2
- Severity: CVSS 9.4 for both vulnerabilities
- EPSS: 0 — supplied EUVD value; validate independently.
- Technical detail: CVE-2026-94100 affects WAN VLAN reconfiguration through
wan_config_set_vlan; CVE-2026-94101 affects VLAN loading throughvlan_load_form_uci. Both apply to firmware 1.3.241127.071246. The supplied data does not confirm whether authentication is required, but exploitation could alter segmentation or network connectivity. - Exploitation status: NEW — published 2026-09-21; exploitation was not confirmed.
- Remediation: Patch or replace affected devices. Block internet access to management services, verify VLAN and WAN settings against known-good baselines and investigate unexpected configuration changes.
CVE-2026-94098 / CVE-2026-94099 — Netcore NBR200V2
- Severity: CVSS 9.4 for both vulnerabilities
- EPSS: 0 — supplied EUVD value; validate independently.
- Technical detail: CVE-2026-94098 affects the firmware-upgrade CGI endpoint, while CVE-2026-94099 affects the backup-restore function. Both are present in firmware 1.3.241127.071246. These functions are security-sensitive and could enable persistence, configuration tampering or device takeover if insufficiently protected.
- Exploitation status: NEW — published 2026-09-21; exploitation was not confirmed.
- Remediation: Apply fixed firmware or remove affected devices from service. Restrict upgrade and restore functions to administrators on trusted networks, review firmware integrity and backup activity and monitor outbound traffic from the devices.
CVE-2026-88854 — OrdaSoft Joomla Gallery Extension
- Severity: CVSS 9.3
- EPSS: Not supplied.
- Technical detail: OrdaSoft Joomla Gallery versions below 6.2.7 contain unauthenticated SQL injection in
showSearchResult()andshowSearchResultAjax(). Public-facing Joomla sites using the extension may be exposed without requiring an authenticated administrative session, potentially allowing database access and follow-on compromise. - Exploitation status: NEW — published 2026-09-20; exploitation was not confirmed.
- Remediation: Upgrade the extension to 6.2.7 or later, or disable/remove it. Review web and database logs for suspicious search requests, database errors, unauthorized administrator creation and access to sensitive records.
ONGOING
CVE-2025-39964,CVE-2026-53266,CVE-2025-39682(Linux Kernel): actively exploited CISA KEV items; remediation is due 2026-09-21. Patch, reboot and verify the running kernel.CVE-2026-94084,CVE-2026-94083(Suricata): update to 8.0.7 or later.CVE-2026-93991(Argo Workflows): update to 4.1.4 or later and review cross-namespace access.CVE-2026-93993(Mistral Vibe): update to 2.25.5 or later and restrict untrusted repository processing.CVE-2026-93742(Totolink A3002MU): isolate or replace affected devices and remove management exposure.CVE-2026-76460,CVE-2026-76461(Cisco), and other previously listed exploited or KEV items: continue urgent remediation and compromise assessment.
European Advisories
EUVD recorded a broad set of new high and critical vulnerabilities during the period. In addition to the issues detailed above, the feed includes critical flaws in Netcore NBR200V2, D-Link DIR-868L and R95 routers, Comfast CF-N1-S, OrdaSoft Joomla Gallery, and authenticated remote code execution in openEQUELLA before 2026.1.0. It also lists high-severity issues in getID3, NivoCart, Frappe ERPNext, ZTE SmartLife and several WordPress plugins.
Organisations should prioritise internet-facing appliances and applications, but validate affected-product ownership before broad remediation because several entries originate from vulnerability research feeds and have incomplete technical descriptions. No new BSI CERT-Bund, CERT-EU or BSI BITS advisories were supplied.
Active Threats and Campaigns
- Runtime-executed npm malware — NEW: Researchers report that the malicious
indexed-btreepackage and related activity conceal payloads in normal runtime behaviour rather than installation scripts, allowing the campaign to evade controls that disable lifecycle scripts. Audit recent package additions and lockfiles, inspect CI/CD hosts for unexpected child processes and rotate credentials exposed to affected build environments. BleepingComputer - OpenAI Codex sandbox escapes — NEW reporting: Researchers demonstrated two escape paths, including one that enabled commands on a developer host from a restrictive mode; the supplied report states that OpenAI patched both. Confirm deployed Codex versions, restrict agent access to secrets and review host telemetry for unexpected commands. BleepingComputer
- WaterPlum: Reported compromise of at least 30,000 devices and theft of more than $10.7 million in cryptocurrency remain ongoing concerns. Continue hunting for the supplied campaign indicators and anomalous wallet or endpoint activity.
Security News and Context
- LMU Munich reported a cyberattack involving possible exposure of student names, addresses, bank details and educational records. Scope remains unclear; organisations should review third-party and education-sector data exposure monitoring. Heise
- CrowdSec’s previously reported supply-chain compromise remains relevant to European organisations: approximately 170 private repositories were copied using an account that remained active after employee departure. Validate offboarding and repository-token revocation. The Hacker News
Recommended Actions
- Identify and isolate Netcore NBR200V2 devices; remove management access from the internet and apply fixed firmware.
- Patch or restrict Vanderbilt REDCap and investigate unauthenticated web requests and process execution.
- Update or remove OrdaSoft Joomla Gallery and review database and web logs.
- Complete the three Linux kernel KEV remediations due today; reboot and verify active versions.
- Audit npm dependencies, CI/CD execution and credentials for runtime-based malware.
- Validate OpenAI Codex versions and agent isolation on developer systems.
- Continue remediation of previously reported items: Suricata, Argo Workflows, Mistral Vibe, Totolink, Gravity Forms, IBM Guardium, Cisco and other KEV-listed systems.