CVE Tools

Security news, decoded.

73 stories in the last 7 days, naming 202 CVEs; 57 of those CVEs are in CISA KEV.

RSS feed

Most covered this week

The CVEs the week's stories name, ranked by how many stories cover them. Point at one, or choose "Trace in the wire", to follow it through the stories below.

  1. CVE-2026-87902An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for ...8 stories · 5 sourcesCVSS 8.1
  2. CVE-2026-85102Improper Certificate Validation in Quantum Security Gateway7 stories · 4 sourcesCVSS 9.8
  3. CVE-2026-93616Directory Traversal and File upload allows execution of arbitrary script on the Management Server6 stories · 4 sourcesCVSS 9.8
  4. CVE-2026-7273A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw...6 stories · 4 sourcesCVSS 8.8
  5. CVE-2026-94127BIG-IP APM OAuth vulnerability5 stories · 5 sourcesCVSS 9.8
  6. CVE-2026-93952Security Advisory 01834 stories · 4 sourcesCVSS 10.0
  7. CVE-2026-65660Microsoft SharePoint Server Remote Code Execution Vulnerability4 stories · 3 sourcesCVSS 8.8
  8. CVE-2026-35273Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily explo...4 stories · 3 sourcesCVSS 9.8

Columns are stories per day, Sep 21 to Sep 27. Verdicts are what the source reports; the magenta dot means the CVE is in CISA KEV.

The wire

Page 1 of 36 · newest first · times in UTC

Today, Sep 273 stories

  1. SecurityWeek
  2. Help Net Security
  3. The Hacker News

Yesterday, Sep 264 stories

  1. BleepingComputer
  2. The Hacker News
  3. The Hacker News
  4. The Hacker News

Friday, Sep 2511 stories

  1. Krebs on Security
  2. BleepingComputer
  3. BleepingComputer
  4. SecurityWeek
  5. Bishop Fox
  6. BleepingComputer
  7. SecurityWeek
  8. The Hacker News
  9. Help Net Security
  10. SecurityWeek
  11. The Hacker News

Thursday, Sep 248 stories

  1. The Hacker News
  2. The Hacker News
  3. BleepingComputer
  4. BleepingComputer
  5. SecurityWeek
  6. Help Net Security
  7. SecurityWeek
  8. The Hacker News

Wednesday, Sep 2314 stories

  1. watchTowr Labs
    Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

    watchTowr Labs found that CVE-2026-94127 in F5 BIG-IP APM lets an unauthenticated attacker send an oversized Authorization header during an OAuth request, causing a heap overflow that can be developed into remote code execution. The issue affects BIG-IP APM 21.x and 17.x, and F5 reports active exploitation, making prompt installation of the available hotfixes important for exposed deployments.

    PoC publicBIG-IP
  2. BleepingComputer
    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    Check Point confirmed attackers are exploiting CVE-2026-85102, a pre-authentication RCE flaw in Security Gateway VPN certificate handling, and CVE-2026-93616, a pre-authentication path traversal issue in the Management web service that can enable script execution and Java class loading. Organizations should deploy the recommended LivePatch or Jumbo Hotfix updates for supported gateways and update Spark firewalls, while applying access-rule mitigations where patching is not possible.

    Reported exploitedSecurity Gateway
  3. BleepingComputer
    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors are actively exploiting the critical unauthenticated path traversal flaw CVE-2026-87902 in WordPress to write PHP files that can run shell commands when accessed. WordPress fixed the issue in version 7.1.2 and backported fixes to branches down to 4.7; administrators should update promptly and review logs for double-encoded traversal probes and suspicious files in /tmp or /var/tmp.

    Reported exploitedWordPress
  4. The Hacker News
    MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    Attackers have exploited the MikroTrick chain, combining CVE-2026-67279 and CVE-2026-86060 to gain administrator control of Internet-exposed MikroTik RouterOS devices without credentials. MikroTik fixed the flaws in RouterOS 6.49.21, 7.23.4, and 7.24.2, but organizations should also investigate systems for signs of prior compromise, including SSH logins using -2 and unknown ops accounts. Exposed SSH services face the greatest risk; compromised routers should be isolated, reset, rebuilt from trusted configurations, and have credentials rotated.

    Reported exploitedRouterOS
  5. Qualys Security Blog
    CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

    CISA added actively exploited Linux kernel flaws CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog, with the shortest BOD 26-04 remediation deadline expiring on September 21, 2026. CVE-2025-39682 can expose memory or cause denial of service, CVE-2026-53266 can corrupt memory and potentially enable local privilege escalation, and CVE-2025-39964 can crash systems or produce corrupted cryptographic output. Organizations should urgently update affected Linux systems, prioritizing internet-facing assets.

    Reported exploitedLinux Kernel
  6. BleepingComputer
    InfraTrust report warns network management systems under attack

    Eclypsium's InfraTrust report says attackers are increasingly targeting network administration platforms, where compromise can provide broad control over managed infrastructure. Actively exploited vulnerabilities include Cisco Secure Firewall Management Center flaws CVE-2026-20079 and CVE-2026-20316, Cisco Identity Services Engine flaw CVE-2026-76460, and SonicWall SMA 1000 flaws CVE-2026-83548 and CVE-2026-83549. Organizations should apply vendor hotfixes and updates, restrict access to management interfaces, and investigate potentially compromised appliances.

    Reported exploitedCisco Secure Firewall Management Center
  7. BleepingComputer
    Arista patches actively exploited VeloCloud Orchestrator zero-day

    Arista Networks has issued patches for CVE-2026-93952, an actively exploited zero-day in VeloCloud Orchestrator (VCO) On-Prem deployments using certificate-based VeloCloud Edge-to-VCO authentication. The input-validation flaw can let remote attackers with network access to the VCO web interface reach privileged internal host functions without VCO credentials; hosted VCO 5.2.3.16 or later and VCO 6.4.2.8 or later are patched, while fixes are planned for 6.1.3.7 and below and 7.0.0.2 and below.

    Reported exploitedVeloCloud Orchestrator
  8. The Hacker News
    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    cPanel has fixed CVE-2026-87899 in CalDAV and CardDAV, which could allow an authenticated hosting account to execute code as root on cPanel & WHM version 120 and later. The updates also address CVE-2026-68490, exposing other accounts' calendar and contact data, and CVE-2026-87900 in WP Toolkit 6.11.2-10794 and older, which permits cross-account database changes; administrators should update cPanel & WHM to 11.134.0.57, 11.136.0.41, 11.138.0.8, or later, and WP Toolkit to 6.11.3 or later.

    PatchcPanel & WHM
  9. SecurityWeek
    Adobe Patches Critical Flaws in Connect, AEM Forms

    Adobe has issued updates for 36 vulnerabilities, including critical flaws in Adobe Connect and AEM Forms that could enable code execution or privilege escalation. The Adobe Connect issues are CVE-2026-75682, CVE-2026-75684, CVE-2026-75686, CVE-2026-75689, CVE-2026-75697, and CVE-2026-75698, involving SQL injection, XSS, and input-validation weaknesses. AEM Forms fixes CVE-2026-75745, CVE-2026-81995, and CVE-2026-82000, while Adobe also patched other products; the company reports no known in-the-wild exploitation and recommends applying the priority 2 updates within 30 days.

    PatchAdobe Connect
  10. The Hacker News
    Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    DepthFirst released proof-of-concept code for CVE-2026-80521, a Linux Kernel AFUNIX socket use-after-free that can let a containerized attacker obtain root access on the host. Ubuntu 26.04, 24.04, and 22.04 LTS remain unpatched, including newer kernel packages used for AWS, Azure, and GCP workloads. The upstream Linux Kernel fix is available, but Ubuntu lists the issue as work in progress; no confirmed in-the-wild exploitation has been reported.

    PoC publicLinux Kernel
  11. Help Net Security
    Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

    Check Point has issued emergency fixes for CVE-2026-93616, a pre-authentication path traversal flaw affecting its Management Server products, after attacks dating to July 23, 2026. Exploitation attempts are also targeting Check Point Spark Firewalls through CVE-2026-85102, an authentication bypass and RCE vulnerability; organizations should patch, review Mobile Access activity, and limit Management Server access where fixes cannot be applied. CISA also added CVE-2026-93952 in Arista VeloCloud Orchestrator and CVE-2026-94127 in F5 Networks’ BIG-IP APM to its Known Exploited Vulnerabilities catalog, highlighting the need to check affected systems for compromise.

    Reported exploitedCheck Point Management Server
  12. Help Net Security
    WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

    WordPress has released 7.1.2 to address CVE-2026-87902, an unauthenticated path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw in getpagetemplate() can let remote attackers cause WordPress to include readable PHP files outside the active theme directories, potentially leading to server-side code execution under certain configurations. WordPress also backported the fix to supported older branches, and site operators should update promptly.

    PatchWordPress
  13. SecurityWeek
    Arista Urges Immediate Patching of Exploited VCO Zero-Day

    Arista has released emergency fixes for CVE-2026-93952, a CVSS 10 improper input validation flaw actively exploited against on-premises VeloCloud Orchestrator deployments. The issue can let a remote attacker reach privileged internal functions, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its managed data. Arista fixed the affected 5.2.x and 6.1.x trains in VCO versions 5.2.3.16 and 6.4.2.8, respectively, and advises organizations to update immediately.

    Reported exploitedVeloCloud Orchestrator
  14. The Hacker News
    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    F5 has released engineering hotfixes for CVE-2026-94127, an exploited heap-based buffer overflow in BIG-IP Access Policy Manager when it operates as an OAuth authorization server. Unauthenticated attackers can send crafted traffic to an affected virtual server and execute code; impacted releases are 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3 before their respective hotfixes. Organizations should install the applicable F5 hotfix, or obtain F5's iRule mitigation while investigating for compromise.

    Reported exploitedBIG-IP Access Policy Manager

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store