Security news, decoded.
73 stories in the last 7 days, naming 202 CVEs; 57 of those CVEs are in CISA KEV.
Most covered this week
The CVEs the week's stories name, ranked by how many stories cover them. Point at one, or choose "Trace in the wire", to follow it through the stories below.
- CVE-2026-87902An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for ...8 stories · 5 sourcesCVSS 8.1
- CVE-2026-85102Improper Certificate Validation in Quantum Security Gateway7 stories · 4 sourcesCVSS 9.8
- CVE-2026-93616Directory Traversal and File upload allows execution of arbitrary script on the Management Server6 stories · 4 sourcesCVSS 9.8
- CVE-2026-7273A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw...6 stories · 4 sourcesCVSS 8.8
- CVE-2026-94127BIG-IP APM OAuth vulnerability5 stories · 5 sourcesCVSS 9.8
- CVE-2026-93952Security Advisory 01834 stories · 4 sourcesCVSS 10.0
- CVE-2026-65660Microsoft SharePoint Server Remote Code Execution Vulnerability4 stories · 3 sourcesCVSS 8.8
- CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily explo...4 stories · 3 sourcesCVSS 9.8
Columns are stories per day, Sep 21 to Sep 27. Verdicts are what the source reports; the magenta dot means the CVE is in CISA KEV.
The wire
Today, Sep 273 stories
- SecurityWeek
- Help Net Security
- The Hacker News
Yesterday, Sep 264 stories
- BleepingComputer
- The Hacker News
- The Hacker News
- The Hacker News
Friday, Sep 2511 stories
- Krebs on Security
- BleepingComputer
- BleepingComputer
- SecurityWeek
- Bishop Fox
- BleepingComputer
- SecurityWeek
- The Hacker NewsRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the WildReported exploitedRoundcube Webmail
- Help Net SecurityFake payroll desktop apps hand attackers a route to company paychecksIncidentScreenConnect
- SecurityWeekRoundcube Webmail Vulnerability in Attackers’ CrosshairsReported exploitedRoundcube Webmail
- The Hacker NewsWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVReported exploitedWSO2 API Control Plane
Thursday, Sep 248 stories
- The Hacker News
- The Hacker News
- BleepingComputerHackers now exploit critical Roundcube flaw in code injection attacksReported exploitedRoundcube Webmail
- BleepingComputerCISA: Ransomware gangs now exploiting critical TeamCity flawReported exploitedTeamCity
- SecurityWeekSolarWinds Patches Critical RCE Flaws in Observability Self-HostedPatchObservability Self-Hosted
- Help Net Security
- SecurityWeekCritical WordPress Vulnerability Exploited Immediately After DisclosureReported exploitedWordPress
- The Hacker NewsAttackers Exploit WordPress CVE-2026-87902 Within Hours of DisclosureReported exploitedWordPress
Wednesday, Sep 2314 stories
- watchTowr LabsIs This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
watchTowr Labs found that CVE-2026-94127 in F5 BIG-IP APM lets an unauthenticated attacker send an oversized Authorization header during an OAuth request, causing a heap overflow that can be developed into remote code execution. The issue affects BIG-IP APM 21.x and 17.x, and F5 reports active exploitation, making prompt installation of the available hotfixes important for exposed deployments.
PoC publicBIG-IP - BleepingComputerCheck Point warns of hackers exploiting Security Gateway VPN RCE flaw
Check Point confirmed attackers are exploiting CVE-2026-85102, a pre-authentication RCE flaw in Security Gateway VPN certificate handling, and CVE-2026-93616, a pre-authentication path traversal issue in the Management web service that can enable script execution and Java class loading. Organizations should deploy the recommended LivePatch or Jumbo Hotfix updates for supported gateways and update Spark firewalls, while applying access-rule mitigations where patching is not possible.
Reported exploitedSecurity Gateway - BleepingComputerHackers start exploiting critical WordPress flaw for code execution
Threat actors are actively exploiting the critical unauthenticated path traversal flaw CVE-2026-87902 in WordPress to write PHP files that can run shell commands when accessed. WordPress fixed the issue in version 7.1.2 and backported fixes to branches down to 4.7; administrators should update promptly and review logs for double-encoded traversal probes and suspicious files in /tmp or /var/tmp.
Reported exploitedWordPress - The Hacker NewsMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Attackers have exploited the MikroTrick chain, combining CVE-2026-67279 and CVE-2026-86060 to gain administrator control of Internet-exposed MikroTik RouterOS devices without credentials. MikroTik fixed the flaws in RouterOS 6.49.21, 7.23.4, and 7.24.2, but organizations should also investigate systems for signs of prior compromise, including SSH logins using -2 and unknown ops accounts. Exposed SSH services face the greatest risk; compromised routers should be isolated, reset, rebuilt from trusted configurations, and have credentials rotated.
Reported exploitedRouterOS - Qualys Security BlogCISA BOD 26-04 Timelines for Three Linux Kernel CVEs
CISA added actively exploited Linux kernel flaws CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog, with the shortest BOD 26-04 remediation deadline expiring on September 21, 2026. CVE-2025-39682 can expose memory or cause denial of service, CVE-2026-53266 can corrupt memory and potentially enable local privilege escalation, and CVE-2025-39964 can crash systems or produce corrupted cryptographic output. Organizations should urgently update affected Linux systems, prioritizing internet-facing assets.
Reported exploitedLinux Kernel - BleepingComputerInfraTrust report warns network management systems under attack
Eclypsium's InfraTrust report says attackers are increasingly targeting network administration platforms, where compromise can provide broad control over managed infrastructure. Actively exploited vulnerabilities include Cisco Secure Firewall Management Center flaws CVE-2026-20079 and CVE-2026-20316, Cisco Identity Services Engine flaw CVE-2026-76460, and SonicWall SMA 1000 flaws CVE-2026-83548 and CVE-2026-83549. Organizations should apply vendor hotfixes and updates, restrict access to management interfaces, and investigate potentially compromised appliances.
Reported exploitedCisco Secure Firewall Management Center - BleepingComputerArista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has issued patches for CVE-2026-93952, an actively exploited zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments using certificate-based VeloCloud Edge-to-VCO authentication. The input-validation flaw can let remote attackers with network access to the VCO web interface reach privileged internal host functions without VCO credentials; hosted VCO 5.2.3.16 or later and VCO 6.4.2.8 or later are patched, while fixes are planned for 6.1.3.7 and below and 7.0.0.2 and below.
Reported exploitedVeloCloud Orchestrator - The Hacker NewsNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
cPanel has fixed CVE-2026-87899 in CalDAV and CardDAV, which could allow an authenticated hosting account to execute code as root on cPanel & WHM version 120 and later. The updates also address CVE-2026-68490, exposing other accounts' calendar and contact data, and CVE-2026-87900 in WP Toolkit 6.11.2-10794 and older, which permits cross-account database changes; administrators should update cPanel & WHM to 11.134.0.57, 11.136.0.41, 11.138.0.8, or later, and WP Toolkit to 6.11.3 or later.
PatchcPanel & WHM - SecurityWeekAdobe Patches Critical Flaws in Connect, AEM Forms
Adobe has issued updates for 36 vulnerabilities, including critical flaws in Adobe Connect and AEM Forms that could enable code execution or privilege escalation. The Adobe Connect issues are CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, involving SQL injection, XSS, and input-validation weaknesses. AEM Forms fixes CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, while Adobe also patched other products; the company reports no known in-the-wild exploitation and recommends applying the priority 2 updates within 30 days.
PatchAdobe Connect - The Hacker NewsExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
DepthFirst released proof-of-concept code for CVE-2026-80521, a Linux Kernel AFUNIX socket use-after-free that can let a containerized attacker obtain root access on the host. Ubuntu 26.04, 24.04, and 22.04 LTS remain unpatched, including newer kernel packages used for AWS, Azure, and GCP workloads. The upstream Linux Kernel fix is available, but Ubuntu lists the issue as work in progress; no confirmed in-the-wild exploitation has been reported.
PoC publicLinux Kernel - Help Net SecurityAttackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point has issued emergency fixes for CVE-2026-93616, a pre-authentication path traversal flaw affecting its Management Server products, after attacks dating to July 23, 2026. Exploitation attempts are also targeting Check Point Spark Firewalls through CVE-2026-85102, an authentication bypass and RCE vulnerability; organizations should patch, review Mobile Access activity, and limit Management Server access where fixes cannot be applied. CISA also added CVE-2026-93952 in Arista VeloCloud Orchestrator and CVE-2026-94127 in F5 Networks’ BIG-IP APM to its Known Exploited Vulnerabilities catalog, highlighting the need to check affected systems for compromise.
Reported exploitedCheck Point Management Server - Help Net SecurityWordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress has released 7.1.2 to address CVE-2026-87902, an unauthenticated path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw in getpagetemplate() can let remote attackers cause WordPress to include readable PHP files outside the active theme directories, potentially leading to server-side code execution under certain configurations. WordPress also backported the fix to supported older branches, and site operators should update promptly.
PatchWordPress - SecurityWeekArista Urges Immediate Patching of Exploited VCO Zero-Day
Arista has released emergency fixes for CVE-2026-93952, a CVSS 10 improper input validation flaw actively exploited against on-premises VeloCloud Orchestrator deployments. The issue can let a remote attacker reach privileged internal functions, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista fixed the affected 5.2.x and 6.1.x trains in VCO versions 5.2.3.16 and 6.4.2.8, respectively, and advises organizations to update immediately.
Reported exploitedVeloCloud Orchestrator - The Hacker NewsF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
F5 has released engineering hotfixes for CVE-2026-94127, an exploited heap-based buffer overflow in BIG-IP Access Policy Manager when it operates as an OAuth authorization server. Unauthenticated attackers can send crafted traffic to an affected virtual server and execute code; impacted releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 before their respective hotfixes. Organizations should install the applicable F5 hotfix, or obtain F5's iRule mitigation while investigating for compromise.
Reported exploitedBIG-IP Access Policy Manager