461.25.09.26- Critical WordPress Vulnerability CVE-2026-87902

461.25.09.26- Critical WordPress Vulnerability CVE-2026-87902

Severity: CriticalCVSS Score: 9.2Affected Product: WordPress CoreAffected Versions: WordPress 4.7.0 through 7.1.1 Overview TT-CSIRT is advising organizations using WordPress to urgently apply security updates for CVE-2026-87902, a critical WordPress Core vulnerability that allows attackers to access unintended PHP files and achieve remote code execution. Exploitation has also been observed using public scanning and proof-of-concept tools increasing […]

460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation CVE-2026-85102 and CVE-2026-93616

Severity: Critical CVSS Score: 9.8 Affected Vendor: Check Point Software Technologies Exploitation Status: Active exploitation observed Date: 23 September 2026 Overview The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is advising organizations and system administrators of two (2) critical vulnerabilities affecting Check Point Security Gateway, Spark Firewall and Security Management products. The vulnerabilities […]

TT-CSIRT – 459.20.07.26 – SharePoint Hardening After New Exploitations (CVE-2026-58644)

Please be advised of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys […]

TT-CSIRT – 456.08.05.26 – CYBERSECURITY ADVISORY: Critical Palo Alto Networks PAN-OS Vulnerability (CVE-2026-0300)

CVE-2026-0300 is a critical buffer overflow vulnerability affecting the User-ID™ Authentication Portal (also known as the Captive Portal) service in PAN-OS. Successful exploitation may allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series and VM-Series firewalls through specially crafted packets. Palo Alto Networks has confirmed that this vulnerability is […]

TT-CSIRT – 453.24.09.25 – Shai-Hulud Self-Replicating Worm Supply Chain Compromise

Please be advised, CISA has issued a critical alert regarding a widespread supply chain attack involving npmjs.com, the largest JavaScript package registry. A self-replicating worm named “Shai-Hulud” has compromised over 500 npm packages. After initial access, the attacker deployed malware scans for sensitive credentials such as GitHub Personal Access Tokens (PATs) and cloud service API […]

TT-CSIRT – 451.13.09.25 – Malware Alert: Azure Function Abuse

Please be advised there has been a discovery of a highly evasive attack using a malicious ISO image named Servicenow-BNM-Verify.iso, containing four files, with two openly visible and two hidden. The visible files include a Windows shortcut, servicenow-bnm-verify.lnk, which launches PanGpHip.exe; a legitimate Palo Alto Networks binary. Hidden are libeay32.dll, a genuine OpenSSL library, and […]

TT-CSIRT – 450.29.08.25 – FreePBX Vulnerability

Please be advised, A critical vulnerability has been discovered in the FreePBX Endpoint module, affecting versions 15, 16, and 17. The vulnerability arises from improper sanitization of user-supplied data, which can be exploited by unauthenticated attackers to gain unauthorized access to the FreePBX Administrator Control Panel. Successful exploitation can result in arbitrary database manipulation and remote […]

TT-CSIRT – 436.24.10.24. Missing Authentication in FortiManager fgfmd

Fortinet has released a patch to address a critical vulnerability in their FortiManager product. This vulnerability allows threat actors to use a compromised FortiManager device to execute arbitrary code or commands via specially crafted requests against other FortiManager devices, through a missing authentication for critical function vulnerability [CWE-306] in FortiManager fgfmd daemon.   Reports have […]

TTCSIRT – 435.26.09.24: Phishing Alert

The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is aware of a phishing email originating from a GovNeTT user’s compromised email “akesha.hazel@gov[.]tt’”. In this respect we are advising all persons not to engage with any emails received from the aforementioned email address with the following details: Persons who receive the email are advised […]

TTCSIRT 434.25.09.24: Keep Your Firewall Up to Date

Regularly updating your firewall is essential for maintaining a strong security posture, protecting your network and data, and mitigating the risks associated with cyber threats. From the Trinidad and Tobago perspective, the exploitation of outdated and unpatched firewall systems is one of the most successful attack vectors executed against local organizations. This email serves as […]