Security news, decoded.
73 stories in the last 7 days, naming 202 CVEs; 57 of those CVEs are in CISA KEV.
The wire
Wednesday, Sep 238 stories
- The Hacker NewsChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Chinese-linked actor UTA0565 used fake websites to exploit a zero-day chain affecting Google Chrome and Microsoft Windows: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The flaws enabled a browser sandbox escape and remote code execution, delivering the CLEANGULP malware, which can run commands, manage files, inspect processes, and execute BOF payloads.
Reported exploitedChrome - SecurityWeekCritical F5 BIG-IP Vulnerability Exploited as Zero-Day
F5 has confirmed active zero-day exploitation of CVE-2026-94127, a CVSS 9.8 vulnerability in BIG-IP Access Policy Manager. Unauthenticated attackers can execute code remotely when a vulnerable BIG-IP APM deployment is configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server. Affected releases are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3; F5 has issued hotfixes. CISA has also added the flaw to its Known Exploited Vulnerabilities catalog, making prompt remediation important.
Reported exploitedBIG-IP Access Policy Manager - BleepingComputerF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
F5 released fixes for CVE-2026-94127, an actively exploited remote code execution zero-day in BIG-IP Access Policy Manager. The issue affects BIG-IP APM virtual servers configured with both an access policy and OAuth profile when operating as an OAuth Authorization Server; OAuth Client or Resource Server-only deployments are not affected. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. Organizations should install F5's updates, investigate OAuth authentication failures, suspicious commands, and subsequent TMM SIGABRT events, or apply F5's iRule mitigation where patching is delayed.
Reported exploitedBIG-IP Access Policy Manager - SecurityWeekShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
ShinyHunters claims it breached FBI systems, defaced a subdomain of fbijobs.gov, and obtained personal data allegedly belonging to thousands of FBI employees. The group says it used a zero-day flaw in Oracle PeopleSoft to access FBI systems and steal 2-3 TB of information, though the FBI is still investigating and the data's source has not been confirmed. ShinyHunters has previously been linked to in-the-wild exploitation of the Oracle PeopleSoft vulnerability tracked as CVE-2026-35273, but it is unclear whether that flaw was used in the alleged FBI incident.
Reported exploitedPeopleSoft - The Hacker NewsCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Vercel has patched CVE-2026-94545, a critical Next.js vulnerability that can allow server-side code execution when Node.js ImageResponse processes attacker-controlled values in generated SVG content. The issue affects Next.js 16.2.0 through 16.3.5; Next.js 15 and the Edge implementation of ImageResponse are not affected. Organizations should upgrade to Next.js 16.3.6, while developers using Satori directly should update to version 0.33.5.
PatchNext.js - SecurityWeekCheck Point Patches Exploited Management Server Zero-Day
Check Point has issued urgent fixes for CVE-2026-93616, a CVSS 9.8 directory traversal and file upload flaw exploited in attacks against Management Server. The issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, allowing unauthenticated attackers to upload and run arbitrary scripts. The company also reports exploitation attempts targeting Spark Firewall customers through CVE-2026-85102, which can bypass VPN authentication and enable code execution on Security Gateway and Spark Firewall; organizations should apply the available updates and restrict Management Server access to trusted IP addresses.
Reported exploitedManagement Server - The Hacker NewsShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claims it breached the FBI and obtained data on current and former employees, as well as FBI job applicants. The group says it used an undisclosed Oracle PeopleSoft pre-authenticated RCE flaw to compromise FBIjobs.gov, while CVE-2026-35273 was previously exploited by the group against enterprise networks; the FBI is investigating the claims.
Reported exploitedPeopleSoft - Help Net SecurityNetBSD 10.2 security fixes close a remote kernel bug in ipfilter
The NetBSD Project released NetBSD 10.2 with a fix for a remotely triggerable null pointer dereference in ipfilter that could crash the kernel, plus a TCP timestamp issue that exposes 4 bytes of kernel stack data. The update also addresses unspecified security issues in NFS and telnet, updates OpenSSL to 3.0.21, Xorg to 21.1.24, and xkbcomp to 1.5.0, and includes fixes for libXpm CVE-2026-4367 and unbound CVE-2025-11411. Administrators should upgrade NetBSD 10 systems, updating the kernel and modules before userspace when using a manual upgrade path.
PatchNetBSD 10.2
Tuesday, Sep 2218 stories
- PatchstackCVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
Patchstack observed active probing for CVE-2026-87902 less than five hours after WordPress 7.1.2 was released. The unauthenticated path traversal flaw affects WordPress Core 4.7.0 to 7.1.1 and can lead to local file inclusion and, under certain server conditions, RCE; administrators should update to 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the applicable backport through 4.7.37.
Reported exploitedWordPress Core - BleepingComputerChinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor linked to Red Heron exploited WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to breach organizations, including government targets, and steal database records containing passwords and PII. The campaign also exploited ZyXEL GS1900 Smart Managed Switches flaw CVE-2026-7273 and targeted PAN-OS GlobalProtect, FlowiseAI CVE-2026-56271, Ubiquiti UniFi OS CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, Linux CVE-2022-0847, Gitea CVE-2026-60004, Nuclio CVE-2026-79756, SENAITE LIMS CVE-2026-54569, and Proxmox VE CVE-2023-54391. Organizations should review GreyNoise IoCs and patch exposed systems, as the activity resulted in stolen credentials, device configurations, and sensitive records.
Reported exploitedWordPress - The Hacker NewsCheck Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Check Point says CVE-2026-93616 was used in targeted attacks against its Security Management Server on July 23. The path traversal vulnerability can let an unauthenticated attacker upload and execute scripts through the server's web service, so administrators should apply the fixes in sk1000171 and investigate for prior compromise. The company also reported exploitation attempts against CVE-2026-85102 on Check Point Spark Firewalls, a VPN certificate-validation flaw fixed on September 9.
Reported exploitedCheck Point Security Management Server - The Hacker NewsWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has released fixes for CVE-2026-87902, a CVSS 9.2 core vulnerability affecting versions 4.7.0 through 7.1.1. An unauthenticated attacker could cause WordPress to load PHP files outside theme directories, which could lead to attacker-controlled code execution on certain server and theme configurations. Site owners should update to WordPress 7.1.2 or the applicable supported-branch release; no workaround is available.
PatchWordPress - The Hacker NewsCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
JFrog researchers released proof-of-concept details for CVE-2026-90898, a CVSS 9.8 flaw in Bifrost AI Gateway that lets unauthenticated attackers launch commands through MCP client registration when management authentication is disabled. All Bifrost HTTP transport versions before 2.1.0 are affected; operators should update to transports/v2.1.0 and rotate provider credentials if an exposed instance ran without authentication. The research also covers CVE-2026-86242, fixed in transports/v2.0.0, which can enable code execution on dynamically linked builds or SSRF on statically linked builds.
PoC publicBifrost AI Gateway - BleepingComputerCheck Point warns of Management Server zero-day exploited in attacks
Check Point has released R82.20 Security Hotfix for CVE-2026-93616, an actively exploited path traversal vulnerability affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Unauthenticated attackers can upload and run arbitrary scripts, so organizations should apply the hotfix, review indicators of compromise, and restrict management access to trusted IP addresses where immediate patching is not possible.
Reported exploitedCheck Point Security Management Server - The Hacker NewsResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A public proof of concept named BigDiskBuster can prevent Microsoft Defender from downloading platform and signature updates by exhausting free space on the C:\ drive. The tool has no assigned CVE and no Microsoft patch or advisory; it may leave Defender running with outdated detection content, although its claimed behavior has not been independently verified. It differs from the previously patched UnDefend issue, CVE-2026-45498, which Microsoft addressed in Antimalware Platform version 4.18.26040.7.
PoC publicMicrosoft Defender - PatchstackWordPress 7.1.2 Security Release: Unauthenticated LFI to RCE
WordPress 7.1.2 addresses CVE-2026-87902, an unauthenticated local file inclusion flaw in page template resolution affecting WordPress Core from 4.7.0 through 7.1.1. The issue can allow remote code execution under certain server configurations, so administrators should apply the available fixed release as soon as possible.
ResearchWordPress - BleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routers
D-Link has disclosed two unpatched vulnerabilities with public PoC code affecting legacy DIR-822A dual-band Wi-Fi routers: CVE-2026-86296 and CVE-2026-86510. CVE-2026-86296 is an unauthenticated DHCP server stack buffer overflow that could let an attacker on the local network crash the service or execute code, while CVE-2026-86510 can cause memory corruption on devices using L2TP or L2TPv6 WAN connectivity. D-Link is investigating and developing fixes; customers should keep these routers off the internet, limit remote management, and restrict administrative access to trusted systems.
PoC publicDIR-822A - The Hacker NewsNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Arista Networks says attackers are actively exploiting CVE-2026-93952, a CVSS 10.0 vulnerability in on-premises VeloCloud Orchestrator deployments using certificate-based Edge authentication. A remote unauthenticated attacker with network access to the VCO web interface and an Edge certificate's public portion could access privileged internal functions, compromise the orchestrator, and potentially reach managed Edge devices. Fixed releases are available for 5.2 and 6.4, while fixes for affected 6.1 and 7.0 releases are pending; organizations should restrict VCO web access and monitor for signs of compromise.
Reported exploitedVeloCloud Orchestrator - SecurityWeekRecent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Chinese threat actor Red Heron has exploited CVE-2026-7273, a CVSS 8.8 unauthenticated stack-based buffer overflow in ZyXEL GS1900-series switches. GreyNoise observed attacks in 48 countries that used crafted HTTP requests to run commands and steal hashed root credentials, device configurations, and network data from 996 systems. ZyXEL released updates for ten affected models in June, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog after the campaign exposed many devices still using factory-default credentials.
Reported exploitedGS1900-series switches - The Hacker NewsNew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
CVE-2026-89775 in Linux Kernel ARM64 KVM can let a guest virtual machine retain read-write access to freed host kernel memory when nested virtualization is enabled, potentially enabling a guest-to-host escape. The issue is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1; no exploitation or public exploit code has been reported, and ARM64 nested virtualization is disabled by default.
PatchLinux Kernel - The Hacker NewsSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Technical details and a public proof of concept show that CVE-2026-65660 in Microsoft SharePoint Server can enable authenticated remote code execution, despite initially being described as a spoofing issue. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition, where crafted web-part markup can bypass SafeControls checks and load arbitrary .NET classes. Microsoft patched the issue in its August 11 security updates; no in-the-wild exploitation has been reported.
PoC publicSharePoint Server - Help Net SecurityAttacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and stealing configurations, network details, and hashed root credentials. The stack-based buffer overflow affects firmware 2.90(XXXX.1)C0 and earlier and enables unauthenticated command execution over LAN; CISA has listed it as exploited, while CVE-2026-32996 in Veeam Agent for Windows is also under active attack and should be remediated by upgrading Veeam Backup & Replication to 13.0.2.29 or later.
Reported exploitedZyXEL GS1900 - BleepingComputerNew Windows Defender zero-day blocks Microsoft antivirus updates
Researcher Abdelhamid Naceri released BigDiskBuster, a proof of concept that can prevent Windows Defender from receiving platform and signature updates on supported Windows versions while it runs in the background. The update-blocking issue has no CVE ID or vendor patch yet; it follows other Defender flaws, including ShieldBreak, tracked as CVE-2026-69414.
PoC publicWindows Defender - BleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theft
CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in ZyXEL GS1900 switches, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply fixes by Thursday. Crafted HTTP requests can allow an unauthenticated attacker on the LAN to execute operating-system commands, creating a path to device compromise and data theft. GreyNoise reports that a suspected Chinese-speaking actor exploited the flaw to steal data from 996 ZyXEL switches across 48 countries; organizations using affected GS1900 models should update to Zyxel's patched firmware releases.
Reported exploitedZyXEL GS1900 - The Hacker NewsWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
WordPress has fixed CVE-2026-93485, known as Comment2Shell, an issue that could let an anonymous commenter inject script into a page. If a logged-in administrator viewed the affected comment, the script could abuse that session to upload a malicious plugin and execute code on the server. The flaw affects WordPress 4.7 through 7.1; update to WordPress 7.1.1 or the fixed release for the supported branch. No exploitation has been reported.
PatchWordPress - The Hacker NewsZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in Zyxel GS1900 series switch firmware, to its KEV catalog. The flaw affects specified GS1900 models through their listed 2.90 firmware releases and can let an unauthenticated LAN attacker run operating-system commands through a crafted HTTP request; federal agencies must apply fixes by September 24, 2026. Arctic Wolf also reported active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows, where a local attacker can reuse exposed elevated session identifiers to execute commands with SYSTEM privileges.
Reported exploitedZyxel GS1900 series switches
Monday, Sep 217 stories
- Check Point Research21st September – Threat Intelligence Report
Check Point's weekly report says Cisco is aware of active exploitation of CVE-2026-76460 in Cisco Identity Services Engine, which can give unauthenticated remote attackers access to the management interface; Cisco also fixed CVE-2026-76461 in Secure Email Gateway. Check Point patched CVE-2026-91843 in Security Management and Log Servers, Oracle addressed more than 800 flaws including in Oracle E-Business Suite, and ISC updated BIND 9 for 14 issues, including CVE-2026-77692; the roundup also covers breaches affecting Japan Digital Agency Government Solution Service, Brevo, and Gyazo, plus the WaterPlum campaign.
Reported exploitedJapan Digital Agency Government Solution Service - BleepingComputerCISA alerts of active exploitation of three Linux kernel flaws
CISA has added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux Kernel to its Known Exploited Vulnerabilities catalog after confirming their use in attacks. The flaws involve AFALG cryptographic sockets, ebtables SNAT, and the kTLS receive path, with potential consequences including memory corruption, system crashes, altered cryptographic behavior, and privilege escalation. Federal agencies must apply available mitigations and updates and perform forensic triage on affected assets.
Reported exploitedLinux Kernel - Dark ReadingShinyHunters Hacked Clop. Now What About Clop's Victims?
ShinyHunters claims it compromised rival ransomware group Clop's leak-site server by abusing an unauthenticated file-upload flaw in Grav CMS, though the alleged theft of server data has not been independently confirmed. The group has threatened to disclose information about organizations that paid Clop, including companies targeted in the Oracle E-Business Suite campaign tied to CVE-2025-61882. If victim records were obtained, affected organizations could face further data exposure or renewed extortion even after dealing with Clop.
IncidentGrav CMS - The Hacker News⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Cisco disclosed active exploitation of CVE-2026-76460, a CVSS 10.0 authentication-bypass flaw in Identity Services Engine (ISE) that can give remote unauthenticated attackers access to affected devices. The weekly roundup also covers Plugin4Shell, a SHA-pinning bypass enabling zero-click RCE in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI, alongside CVE-2026-32882 in Discourse community forum, fixed upstream in libheif 1.22.0. Other incidents include ClickFix campaigns, Brevo's supply-chain compromise, and KREMLIN malware targeting Google Chrome and Microsoft Edge credentials.
Reported exploitedCisco Identity Services Engine - SecurityWeekOrganizations Warned of 3 Exploited Linux Kernel Vulnerabilities
CISA has added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its Known Exploited Vulnerabilities catalog, confirming exploitation of three Linux kernel flaws. The issues can enable denial of service, memory disclosure or corruption, unpredictable cryptographic results, and unauthorized memory modification through affected TLS, AFALG socket, and bridge Netfilter ebtables SNAT code. Federal agencies have been directed to remediate all three vulnerabilities within three days.
Reported exploitedLinux Kernel - ESET WeLiveSecurityThe SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
ESET says SMBs adopting AI agents face new risks from excessive permissions, malicious skills, supply-chain changes, and prompt injection. The report highlights Microsoft 365 Copilot and CVE-2025-32711, where indirect prompt injection could expose data, while warning that AI is also accelerating phishing, vulnerability exploitation, and ransomware activity.
Reported exploitedAI Agents - Google Project ZeroWindows Exploitation Techniques: Dangling COM Object Registrations
Microsoft has fixed CVE-2026-66804, a Windows privilege-escalation flaw involving a dangling registration for the CrossDevice COM object. The issue, an incomplete remediation for CVE-2026-50343, could let a local user place a DLL in a writable ProgramData path and have it loaded by a privileged COM service. Google Project Zero shows how custom COM marshaling and the Shell Create Object Handler could be used to reach SYSTEM-level code execution.
ResearchWindows COM
Sunday, Sep 201 story
- Help Net SecurityWeek in review: Cisco patches exploited email gateway 0-day, Revolut breach
This week’s security news includes Cisco patches for actively exploited flaws in Cisco Secure Email Gateway (CVE-2026-76461) and Cisco Identity Services Engine (ISE) (CVE-2026-76460), as well as targeted exploitation of an Acronis backup plugin issue (CVE-2026-87886). Researchers also disclosed that Parallels Desktop flaw CVE-2026-90894 can let a local Mac user obtain root access, while Revolut confirmed a breach involving customer records obtained through government-agency impersonation.
Reported exploitedRevolut
Saturday, Sep 196 stories
- BleepingComputerBragJack attacks hijack AI browser agents through malicious extensions
Researcher Gal Weizman demonstrated BragJack, a proof-of-concept technique in which an already-installed malicious extension can take over AI browser assistants in Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. The flaws can enable access to sensitive browser data and cause agents to perform actions for victims; Google fixed CVE-2026-0628 and Microsoft fixed CVE-2026-55945. Users should update their browsers and review extensions with broad site-data permissions.
PoC publicGoogle Chrome - BleepingComputerShinyHunters hacks Clop leak site, threatens to extort ransomware gang
ShinyHunters breached and defaced the Clop (Cl0p) ransomware group's Tor leak site after claiming to exploit an unauthenticated file upload flaw in Grav CMS. The group says it took server logs, source code, Grav CMS plugins, and onion-service private keys, although only the uploaded file and defacement have been independently confirmed. The incident follows a dispute tied to Clop's Oracle E-Business Suite campaign, which exploited CVE-2025-61882, and ShinyHunters says it intends to extort Clop over the alleged theft.
Reported exploitedGrav CMS - The Hacker NewsClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Hacktron researchers used Claude Opus 5 to combine CVE-2026-32882 in libheif with an OpenAI single sign-on flaw, gaining access to ChatGPT and Codex accounts belonging to OpenAI employees. The controlled research led to a harmless pull request in an internal OpenAI repository; the team reported the issues, and OpenAI fixed its login-side flaw and paid a $6,500 bounty. Discourse instances running unpatched libheif 1.19.7 should rebuild with a fixed release, as image-processing exposure and shared SSO can turn a public-service compromise into broader account access.
ResearchDiscourse - The Hacker NewsSolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has fixed CVE-2026-28326, an 8.8-severity hard-coded static key issue in Access Rights Manager (ARM) that could allow unauthenticated remote code execution. All versions of Access Rights Manager 2026.2 and prior are affected; the company addressed the flaw in ARM 2026.2.1 and has not reported active exploitation. SolarWinds also recently resolved Web Help Desk flaws CVE-2026-28323 and CVE-2026-28299 in WHD 2026.2.1, and released Serv-U fixes for CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323.
PatchSolarWinds Access Rights Manager - The Hacker NewsCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Crafted workflow definitions can abuse unsandboxed JavaScript or Python evaluation to run operating-system commands as the Conductor process; organizations should upgrade to Conductor 3.30.2 or later and restrict access to workflow API endpoints.
Reported exploitedOrkes Conductor - The Hacker NewsCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec says an attacker used a former employee's GitHub OAuth token to copy about 170 private repositories after the TanStack npm supply-chain attack tracked as CVE-2026-45321. Malicious TanStack npm packages stole developer credentials, and CrowdSec had not yet removed the former employee's GitHub access when the repositories were copied. The archive later published online included private source code, 83 user email addresses, and information on 51 potential investors; CrowdSec says its infrastructure and databases were not accessed and exposed credentials have been rotated.
Reported exploitedTanStack