Sep 21: REDCap 9.8 RCE, Keycloak IAM, Jade Sleet Backdoors
CVE-2026-90817 unauthenticated RCE hits clinical research platforms. Red Hat patches four Keycloak IAM flaws. Jade Sleet deploys FLATROOF/ROOFDECK at Indian IT provider.
- CVE-2026-90817 (REDCap, CVSS 9.8): Unauthenticated RCE via survey passthrough routing and data import. No credentials required. Clinical research platform used at hundreds of academic medical centers. Patch available.
- Keycloak: Red Hat issued advisories for four CVEs today covering admin API cache leaks, authorization services exposure, UMA token confusion, and session enforcement bypass. Patches out.
- Jade Sleet (North Korea) has compromised an India-based IT services provider, deploying FLATROOF and ROOFDECK backdoors. Attribution confirmed by researchers; customer impact unconfirmed.
- ShinyHunters vs. Clop: 72-hour extortion deadline against Clop operators running since approximately September 19. Situation ongoing. Unconfirmed whether deadline has been acted on.
- SolarWinds ARM CVE-2026-28326 (CVSS 8.8): Hardcoded key enables unauthenticated RCE. Patch ARM 2026.2.1 is out. Published September 20.
CVE-2026-90817 (CVSS 9.8, critical). Unauthenticated remote code execution in REDCap via the survey passthrough routing and data import processing endpoints. No credentials required. Arbitrary code execution on the server.
REDCap runs at hundreds of academic medical centers and research institutions worldwide. It handles clinical trial data, patient surveys, and IRB-regulated datasets. An unpatched internet-facing instance is a full compromise from a single unauthenticated request. That is the exposure.
Patch is available. Full coverage.
Keycloak: four CVEs, Red Hat advisories out
Red Hat published advisories for four Keycloak vulnerabilities today. Individual CVSS scores range from 3.1 to 5.5, but IAM infrastructure flaws are a consistent initial-access vector regardless of headline score.
- CVE-2026-94213 (CVSS 4.9): Authorization Services policy evaluation endpoint exposes internal admin context to non-admin callers.
- CVE-2026-94215 (CVSS 5.5): Admin REST API per-request cache resolves clients incorrectly under concurrent load, leaking client configuration data.
- CVE-2026-94217 (CVSS 3.5): UMA token endpoint confusion when two different users hold ownership of the same resource.
- CVE-2026-94218 (CVSS 3.1): Session enforcement bypass. When an admin upgrades an authentication flow to a stricter policy, active sessions bypass the new requirement until they re-authenticate. The window depends on session lifetime configuration.
All four are patched. Full coverage.
Jade Sleet: FLATROOF and ROOFDECK at Indian IT provider
North Korea-linked Jade Sleet has compromised an India-based IT services provider, deploying two custom backdoors: FLATROOF and ROOFDECK. The positioning inside a managed services provider suggests the goal is downstream access to customer networks.
Attribution is to Jade Sleet based on tooling and methodology consistent with prior operations. Customer-side impact is unconfirmed at time of publication.
ShinyHunters vs. Clop: 72-hour clock running
ShinyHunters breached the Clop ransomware operation’s Tor-hosted data leak site on or around September 19, defacing it and claiming to have obtained private onion service keys and server data. A 72-hour extortion deadline was posted against the Clop operators.
Unconfirmed: whether that deadline has been acted on. Organizations with data previously listed on Clop’s leak site are now in a compound exposure: their exfiltrated data may be in ShinyHunters’ hands as well.
Prior coverage. Monitoring.
Also on the board
-
SolarWinds ARM CVE-2026-28326 (CVSS 8.8): Hardcoded cryptographic key in Access Rights Manager through 2026.2 enables unauthenticated RCE. Patch ARM 2026.2.1 is out. Published September 20.
-
kcp CVE-2026-61682 (CVSS 9.9): The kcp front-proxy passes client-supplied X-Remote-User headers without validation. An authenticated user can impersonate any other user in the cluster. Fixed in 0.31.4 and 0.32.2.
-
Icinga 2 CVE-2026-61550 (CVSS 9.8): Cluster node auth bypass. A node presenting a certificate from an unrelated CA accepted at the TLS layer can join the cluster without valid node credentials. Fixed in 2.14.9, 2.15.4, and 2.16.2.
-
nvm CVE-2026-94185 (CVSS 5.5): Path traversal in alias resolution in nvm before 0.40.8. Real exposure depends on how the alias directory is structured in the build environment. Analysis at 0dayNews.
-
BragJack: PoC from researcher Gal Weizman shows a single malicious browser extension can intercept and manipulate AI assistant sessions in Chrome, Edge, and Chromium-based browsers. No CVE assigned. The attack surface is real.
- 0dayNews — REDCap Patches CVSS 9.8 Unauth RCE via Survey Route
- 0dayNews — Red Hat Patches Four Keycloak IAM Flaws
- 0dayNews — Jade Sleet Hits Indian IT Firm with Custom Backdoors
- 0dayNews — ShinyHunters Breaches Clop Tor Site, Steals Onion Keys
- 0dayNews — SolarWinds ARM Hard-Coded Key Allows Unauthenticated RCE