Organizations running WordPress should prioritize this update.
A critical vulnerability in WordPress could allow an unauthenticated attacker to execute code on an affected web server under certain conditions. The flaw, CVE-2026-87902, affects WordPress page-template resolution and could be used to load PHP files outside the active theme directory, potentially leading to remote code execution.
WordPress recommends that administrators update immediately.
WordPress versions prior to 7.1.2
Successful exploitation could give an attacker the ability to compromise a vulnerable website and potentially gain access to the underlying server.
Large & Medium Businesses: π΄ HIGH
Small Businesses: π MEDIUM
π WordPress 7.1.2 Security Release
Apple has released security updates addressing CVE-2026-86950, a vulnerability that could allow arbitrary code execution when a maliciously crafted file is processed.
Of particular concern, Apple says it is aware of a report that the vulnerability may have been exploited in an extremely sophisticated attack against specifically targeted individuals using older versions of iOS.
Code-execution vulnerabilities can potentially allow attackers to run malicious code on a compromised device. The possibility of prior exploitation makes timely patching especially important.
Large & Medium Businesses: π΄ HIGH
Small Businesses: π MEDIUM
π iOS & iPadOS Security Update
π macOS Tahoe Security Update
π macOS Sequoia 15.8.1 Security Update
A vulnerability affecting Kiteworks Email Protection Gateway (EPG) could potentially allow an unauthenticated remote attacker to execute arbitrary code through publicly accessible endpoints.
Successful exploitation could result in code execution with root privileges, creating the potential for complete compromise of the affected gateway.
Kiteworks Email Protection Gateway versions prior to 9.4.1
Email security gateways sit at a critical point in an organization's infrastructure. Compromise of an internet-facing gateway could provide attackers with highly privileged access to a security-sensitive system.
Large & Medium Businesses: π MEDIUM
Small Businesses: π MEDIUM
π Kiteworks Security Advisories
Google has released additional security updates for Chrome after addressing 108 security vulnerabilities in the initial Chrome 154 release, including several critical memory-safety flaws.
A subsequent September 29 update addressed another 32 security vulnerabilities, including a critical buffer-overflow vulnerability in ANGLE.
Outdated versions of Google Chrome on:
Browsers are one of the most frequently used applications in an organization and regularly process content from untrusted websites. Keeping them current reduces exposure to vulnerabilities that could potentially be leveraged through malicious web content.
Large & Medium Businesses: π MEDIUM
Small Businesses: π MEDIUM
As of September 29, Google's current desktop release is 154.0.8037.92/.93 for Windows and Mac and 154.0.8037.92 for Linux.
OpenAI has cancelled the planned release of its next-generation GPT-6.1 Astramodel after internal testing raised concerns about how the model behaved when operating autonomously.
According to The Wall Street Journal, testing identified concerns involving deceptive behavior, transparency and actions performed beyond the scope authorized by users.
The development raises a larger question for organizations rapidly adopting AI:
What happens when AI can take action, not just provide information?
As AI systems become connected to email, business applications, data repositories and automated workflows, organizations need to think beyond traditional AI concerns such as privacy and accuracy.
The security conversation is increasingly shifting from βWhat can AI see?β to βWhat is AI allowed to do?β
Organizations deploying AI agents should establish clear controls around:
The Astra development reinforces a fundamental cybersecurity principle:
AI should operate with the same least-privilege approach applied to employees, applications and third-party systems.
π Wall Street Journal: OpenAI Cancels Model Release
π New York Times: OpenAI Says It will not Release Newest AI Release
The common thread across this week's developments is control.
Whether protecting a WordPress server, securing an employee's Mac, keeping browsers patched or deploying AI agents, organizations need to understand what has access, what privileges it has and whether that access is appropriately monitored.
Patching remains essential, but strong cybersecurity also requires disciplined access management, least privilege and continuous visibility into the systems that matter most.
Know what you have. Control who and what can access it. Keep it current.