24h | 7d | 30d

Overview

  • F5
  • BIG-IP

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.39%

Description

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 11 Posts
  • 11 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch")

F5 gibt an, dass die Schwachstelle bereits aktiv ausgenutzt wird. IT-Sicherheitsverantwortliche sollten unverzüglich die Patchstände prüfen und, sofern erforderlich, die verfügbaren Engineering Hotfixes einspielen.

👉️ bsi.bund.de/dok/1209384

  • 4
  • 0
  • 0
  • 13h ago
Profile picture fallback

CVE-2026-94127: Critical zero-day in F5 BIG-IP APM exploited for RCE on OAuth Authorization Servers. Patch urgently or use F5's iRule mitigation. Monitor for OAuth auth failures and TMM SIGABRTs. radar.offseq.com/threat/f5-pat

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: radar.offseq.com/threat/critic

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE

F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/f5

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated […]
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
📢❗️ Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch") 👉️ https://www.bsi.bund.de/dok/1209384
  • 1
  • 6
  • 0
  • 13h ago
Profile picture fallback
~Certeu~ Actively exploited unauthenticated RCE affects BIG-IP APM; patch urgently. - IOCs: CVE-2026-94127 - #CVE202694127 #F5 #ThreatIntel
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Threat actors exploit CVE-2026-94127 in BIG-IP APM OAuth Authorization Server setups to gain unauthenticated remote code execution, prompting urgent patching.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
CVE-2026-94127 enables unauthenticated remote code execution on F5 BIG-IP APM when APM functions as an OAuth authorization server, requiring hotfixes.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
F5 and CISA say CVE-2026-94127, a critical BIG-IP APM flaw with CVSS 9.8, is being used as a zero-day for unauthenticated remote code execution. Hotfixes are available. #F5 #BIGIPAPM #CVE202694127
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
F5 has patched a critical BIG-IP APM zero-day, CVE-2026-94127, exploited in remote code execution attacks on systems with OAuth authorization server settings enabled. #F5 #BIGIPAPM #CVE202694127
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.42%

KEV

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 9 Posts
  • 6 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.

GitHub: github.com/abraxas/CVE-2026-87

Credit: @abraxas_null (X)

  • 0
  • 2
  • 0
  • 3h ago
Profile picture fallback
WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), which stems of how the CMS resolves page templates, with a real path to remote code execution. […]
CVE-2026-87902: how close is your WordPress to remote code execution? - Security Affairs
  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
  • 1
  • 3
  • 0
  • 3h ago
Profile picture fallback
2026年9月23日,WordPress 爆出 9.2 分的严重安全漏洞,攻击者无需登录即可在服务器上运行代码。漏洞编号 CVE-2026-87902,请务必升级至最新版本 7.1.2。@Appinn 根据 W3Techs 2026 年 9 月 22 日的最新统计,全球约 40.2% 的网站都在使用
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) 📖 Read more: www.helpnetsecurity.com/2026/09/23/c... #cybersecurity #cybersecuritynews #securityupdate #vulnerability #websecurity #CMS #CVE @wordpress.org @wordpress.com
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
WordPress corregge una falla critica sfruttabile senza login: quando può portare a RCE Una falla critica nel Core di WordPress consente a un attaccante non autenticat... https://www.ilsoftware.it/wordpress-falla-critica-rce-cve-2026-87902-senza-login/
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
WordPress 7.1.2 patches CVE-2026-87902, a critical unauthenticated path traversal bug in get_page_template() affecting 4.7.0-7.1.1. The flaw could load arbitrary PHP files and may lead to code execution. #WordPress #CVE202687902 #PHP
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Hackers are exploiting CVE-2026-87902 in WordPress, using a path traversal flaw to write PHP files and enable remote code execution. WordPress 7.1.2 fixes the issue. #WordPress #CVE202687902 #Patchstack
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
~Cybergcca~ WordPress CVE-2026-87902 is exploited in the wild; SolarWinds and HPE also require updates. - IOCs: CVE-2026-87902, CVE-2026-28325, CVE-2026-28324 - #CVE202687902 #ThreatIntel #WordPress
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • checkpoint
  • Quantum Security Management

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.42%

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Statistics

  • 6 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack

CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow

🔗 cyber.netsecops.io/articles/ch

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
⚠️ #CheckPoint signale une faille zero-day (CVE-2026-93616) exploitée le 23/07, permettant l'exécution de scripts sans connexion sur son serveur de gestion. Patch dispo depuis le 22/09. #CyberSecurity #Automatisation
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
CVE-2026-93616 is a critical, exploited-in-the-wild directory traversal and file upload flaw enabling unauthenticated script execution on Check Point Management Servers.
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
CVE-2026-93616: Directory Traversal and File upload allows execution of arbitrary script on the Management Server #patchmanagement
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
CVE-2026-93616: Check Point Management Server Zero-Day Exploited in Targeted Attacks socprime.com/blog/cve-202...
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-85102, CVE-2026-93616, CVE-2026-93952 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Arista Networks
  • VeloCloud Orchestrator (VCO) On-Prem

22 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.74%

Description

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

Statistics

  • 6 Posts
  • 6 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Arista confirmed active exploitation of a CVSS 10 VeloCloud Orchestrator vulnerability (CVE-2026-93952) affecting certificate-based SD-WAN setups. Patch now.

meterpreter.org/arista-veloclo

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

CVE-2026-93952: CRITICAL zero-day in Arista VeloCloud Orchestrator (on-prem <5.2.3.16, <6.4.2.8) is actively exploited. Remote attackers can access privileged functions w/o creds. Patch now — review logs for signs of compromise. radar.offseq.com/threat/arista

  • 0
  • 0
  • 0
  • 13h ago

Bluesky

Profile picture fallback
Arista released urgent patches for a zero-day CVE-2026-93952 in on-prem VeloCloud Orchestrator that is actively exploited and enables remote access to privileged functionality.
  • 0
  • 0
  • 1
  • 13h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-85102, CVE-2026-93616, CVE-2026-93952 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.66%

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 5 Posts
  • 4 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack

CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow

🔗 cyber.netsecops.io/articles/ch

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
  • 1
  • 3
  • 0
  • 2h ago
Profile picture fallback
📢 CVE-2026-85102 : Bypass d'authentification et RCE critique dans les VPN Check Point (CVSS 9.8) Le 23 septembre 2026, Check Point a publié l'alerte de sécurité sk1000117 concernant la vulnérabilité CVE-2026-85102, affectant les… 🟢 vérification factuelle haute #CVSS98 #CheckPoint #Cyberveille
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-85102, CVE-2026-93616, CVE-2026-93952 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Canon Inc.
  • Satera MF750C Series

06 Feb 2024
Published
17 Jun 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.38%

KEV

Description

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2024-0244: Connor Ford details how he exploited the MF753Cdw printer back when he was a contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. zerodayinitiative.com/blog/202

  • 2
  • 0
  • 1
  • 2h ago
Profile picture fallback

CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer thezdi.com/blog/2026/9/23/cve-

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
CVE-2024-0244 is an unauthenticated heap buffer overflow in Canon MF753Cdw that enables arbitrary free() via fax-driver SOAP interactions.
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Linux
  • Linux

26 Aug 2026
Published
21 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: X -. A <-> B ^--' 2) Run the following concurrently: 2-1) send() sk-B to sk-B from sk-X 2-2) close() both A and B At 2-1), there is a small window where unix_add_edges() publishes a new edge (B <-> B) to GC but its skb is not queued by skb_queue_tail(). If 2-2) completes before skb_queue_tail() and GC is triggered, it judges A <-> B as dead, but B is not freed because GC cannot collect the not-yet-queued skb holding the B <-> B edge. X -. A <-> B -. This edge is visible ^--' ^..' but skb is not This itself is not a problem since the next GC run will judge B as dead as well and free it finally. X -. A <.> B -. ^--' ^--' However, X's SCC forces the next GC to call unix_walk_scc_fast(), and it iterates over A through B's scc_entry. Let's unlink scc_entry before freeing the vertex in unix_del_edge().

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Security researchers published a working exploit for CVE-2026-80521, a Linux AF_UNIX use-after-free that can escape a container and gain root on the host. Their PoC targets Ubuntu 26.04. The kernel fix landed upstream Aug. 6, but Canonical's tracker still lists 26.04 as vulnerable/work in progress and 24.04 as vulnerable. That raises urgency.

Again, Ubuntu is behind on security.

depthfirst.com/research/contai

#Linux #Ubuntu #Security #Containers

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
A Linux AF_UNIX use-after-free lets attackers escape containers and obtain host root via CVE-2026-80521, with Ubuntu LTS releases lacking the upstream fix.
  • 1
  • 0
  • 0
  • 9h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps.

securityonline.info/nextjs-rce

  • 0
  • 0
  • 0
  • 14h ago

Bluesky

Profile picture fallback
A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature […]
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
🚨 CVE-2026-94545: Critical RCE in Next.js 16.2.0–16.3.5 via SVG injection when attacker-controlled input reaches ImageResponse. Next.js 15 and Edge ImageResponse are unaffected. 👉 Update to 16.3.6. Details: buff.ly/74eZfz1
  • 0
  • 0
  • 0
  • Last hour

Overview

  • D-Link
  • DIR-822A

07 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.35%

KEV

Description

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.

meterpreter.org/dlink-dir-822a

  • 1
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
📢 [VULN] D-Link alerte sur une faille de gravité maximale dans l’un de ses routeurs, le code pour l’exploiter est déjà public CVE-2026-86296 D-Link enquête sur une faille critique qui touche ses routeurs DIR-822A. Exploitable sans authentification, elle dispose déjà d’un code d’… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Zohocorp
  • ManageEngine OpManager

23 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
Pending

KEV

Description

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.

securityonline.info/manageengi

  • 0
  • 0
  • 0
  • 7h ago
Showing 1 to 10 of 55 CVEs