Programmer’s Digest #205
09/30/2026-10/07/2026 Critical Atlassian Flaw; WordPress Malware Comes Back After Removal; GitLab Patches Critical AI Gateway Flaw And More.
1. Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw (CVE-2026-21589, CVSS 9.3) in eight self-hosted Atlassian Data Center products lets unauthenticated attackers read files in the web application root directory. Attackers must already know a file’s exact name and path. Atlassian disclosed it on October 5 and listed fixed versions per product. Cloud products are already patched.
Atlassian advises upgrading to a fixed LTS version or later, including for end-of-life releases. If that isn’t possible immediately, take the instance offline or restrict external access. Temporary mitigations block URLs with “..” next to “/”, “” or “::”, including encoded forms, via a WAF or reverse proxy, a Tomcat RewriteValve rule, or urlrewrite.xml (Bitbucket). Atlassian calls these limited and no replacement for patching.
Details are inconsistent: the Crowd and Bamboo fixed versions differ between the advisory and the CVE record. Server editions are listed as affected with no fixes.
Atlassian found no exploitation in cloud, but can’t confirm for self-hosted instances. Teams should search access logs for traversal patterns. A similar Jira flaw (CVE-2021-26086) was later exploited.
2. WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor
A WordPress backdoor called SC, documented by Sucuri on September 30, 2026, restores deleted malware within seconds by spreading its components across website files, the database, and server memory. The report doesn’t establish the original entry point or how many sites are affected.
SC occupies at least eight locations. A configuration directive launches a loader before ordinary PHP requests, and the loader rebuilds a fake caching plugin from copies, encoded backups, or recovery archives. Early-loading components and an injected theme block provide further recovery routes. The backdoor hides from plugin lists and update checks, conceals an administrator account, and can forge authentication cookies. For commands, it queries smart contracts through about twenty public Ethereum gateways, so blocking one route doesn’t help. Replies can deliver PHP, browser scripts, or orders to delete security plugins.
Sucuri advises neutralizing the loader target first, then removing the directive. Next come database payloads, shared memory copies, scheduled tasks, triggers, and hidden admins, then all files in one pass. Finish by closing the entry point and rotating credentials.
3. LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Researchers have shown that a malicious spreadsheet can make LibreOffice and Apache OpenOffice run attacker code the moment it’s opened, with no macro-style warning. It works only when Java support is enabled, and so far exists only as a proof of concept, with no reported real-world use.
The attack chains normal features: a spreadsheet’s auto-refreshing “database range” fetches an ODB file from a web address, which names a JDBC driver hosted in a remote JAR file. The program downloads and starts it, running the attacker’s code without ever asking the user to trust the document. Researchers tested it on Windows and Linux.
LibreOffice fixed CVE-2026-63277 on October 5; users should update to 26.2.5 or 26.8.0. Apache OpenOffice (CVE-2026-59265) remains unpatched through version 4.1.16, with a fix expected in 4.1.17. Until then, disable Java or avoid opening untrusted spreadsheets.
4. GitLab Patches Critical AI Gateway Flaw Allowing Arbitrary Command Execution
GitLab has patched CVE-2026-90970 (CVSS 9.9), a critical flaw in its AI Gateway that lets authenticated users run arbitrary commands on self-hosted deployments. It affects versions from 18.1.6 up to, but excluding, 19.2.4, plus the 19.3 branch before 19.3.2 and the 19.4 branch before 19.4.1.
The bug is an improper neutralization issue in the custom-flow prompt template mechanism. A user with Duo Agent Platform access can submit a crafted flow configuration, escape the template sandbox, and execute commands on the gateway host or container.
Fixed releases are 19.2.4, 19.3.2, and 19.4.1. GitLab lists no workaround, so upgrading is the main mitigation. Because the AI Gateway is separate from the core application, administrators should check the gateway image or Helm configuration rather than assume a GitLab CE/EE upgrade covers it. Teams should also restrict flow-configuration access and review recent templates for unexpected changes.
GitLab.com, Dedicated, and instances using a GitLab-hosted gateway need no action.
5. 100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
CERT-UA has identified over 100 websites compromised in September 2026 with malicious JavaScript that serves LunexStealer, a campaign attributed to the cluster UAC-0277. Visitors see a fake Cloudflare verification page that tricks them into running a command (ClickFix), which installs a malicious MSI package. The script retrieves its settings from a Polygon or Ethereum smart contract (EtherHiding), and the lure is shown only to Windows users arriving from search results.
Three MSI variants exist: a basic installer; one that bypasses UAC, sets Defender exclusions and abuses a vulnerable AMD driver to blind security tools; and one that uses DLL sideloading.
LunexStealer also installs a browser extension, LUNARAXE, posing as “Microsoft Office Word Editor”. It steals cookies, history and credentials, strips CSP headers and can run arbitrary JavaScript. The NAIVEMESS component gives it file system access.
CERT-UA advises blocking the Run dialog, restricting MSI installs, monitoring msiexec.exe, enabling Microsoft’s vulnerable driver blocklist, and allowlisting browser extensions.