Buletin de securitate cibernetică – 21 septembrie 2026

Cybersecurity Bulletin – September 21, 2026

The daily CyberSec Intelligence bulletin analyzes major vulnerabilities from September 21, 2026, including actively exploited flaws in Linux, Cisco, and Google Pixel, plus new critical risks in network equipment.

The CyberSec Intelligence team presents the daily analysis of cybersecurity threats and vulnerabilities identified on September 21, 2026. In the current context, continuous monitoring and rapid patch application are essential for protecting IT infrastructures against complex attacks.

Actively Exploited Vulnerabilities

The following vulnerabilities have been included in the CISA KEV (Known Exploited Vulnerabilities) catalog due to evidence of their active exploitation in real-world attacks:

  • CVE-2025-39964 (Linux Kernel): A race condition vulnerability in the AF_ALG socket that allows concurrent writes, causing inconsistencies in the internal state of the socket. Additional details: NVD CVE-2025-39964.
  • CVE-2026-53266 (Linux Kernel): An out-of-bounds write vulnerability in the ebtables SNAT component, allowing the rewriting of an ARP sender’s hardware address directly into a socket buffer fragment. Affected devices may be at the end of life (EoL/EoS). Additional details: NVD CVE-2026-53266.
  • CVE-2025-39682 (Linux Kernel): Improper verification for exceptional conditions in the TLS receive path, allowing the bypass of correct record type handling. Affected devices may be EoL/EoS. Additional details: NVD CVE-2025-39682.
  • CVE-2026-58704 (Google Pixel): A logic error in the cellular modem causes improper authorization, allowing attackers to bypass permission checks and escalate their privileges. Additional details: NVD CVE-2026-58704.
  • CVE-2026-76460 (Cisco Identity Services Engine): Incorrect use of privileged APIs in Cisco ISE and ISE-PIC allows an unauthorized remote attacker to bypass the web management interface. Additional details: NVD CVE-2026-76460.
  • CVE-2026-87886 (Acronis Backup): Incorrect default permissions in the Acronis Backup plugin for cPanel & WHM and the extension for Plesk, allowing privilege escalation. Additional details: NVD CVE-2026-87886.
  • CVE-2026-76461 (Cisco Secure Email Gateway): A SQL Injection vulnerability in Cisco AsyncOS software for Cisco SEG, allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges. Additional details: NVD CVE-2026-76461.

New Critical Vulnerabilities

In the last 24 hours, technical details have been published for a series of critical vulnerabilities with maximum CVSS scores, mostly affecting network equipment without an official response from some of the manufacturers:

  • CVE-2026-93741 (Totolink A3002MU): Buffer overflow in the formWlWds function due to faulty handling of the submit-url argument. The attack can be launched remotely, and the exploit is public (CVSS 10). Additional details: NVD CVE-2026-93741.
  • CVE-2026-93742 (Totolink A3002MU): Command injection in the formWsc function via the localPin argument, allowing remote command execution (CVSS 9.9). Additional details: NVD CVE-2026-93742.
  • CVE-2026-93985 (OpenPanel js-runtime): Sandbox escape in the JavaScript webhook template validator. Attackers with write access can execute arbitrary code in the worker process (CVSS 9.9). Additional details: NVD CVE-2026-93985.
  • CVE-2026-93958 (D-Link R95 BE9500): OS command injection in the system function of /bin/ssi of the DHMAPI component, via the NTPServer argument (CVSS 9.1). Additional details: NVD CVE-2026-93958.
  • CVE-2026-94003 (Comfast CF-N1-S): Stack-based buffer overflow in get_css_path_from_uri of the Web Management Interface component (CVSS 10). Additional details: NVD CVE-2026-94003.
  • CVE-2026-94089 (D-Link DIR-868L): Stack-based buffer overflow via unsafe use of strcpy in /webfa_authentication.cgi when processing id/password (CVSS 10). Additional details: NVD CVE-2026-94089.
  • CVE-2026-94095 (Netcore NBR200V2): Command injection in network_tools via the url argument (CVSS 9.9). The vendor has not provided a response. Additional details: NVD CVE-2026-94095.
  • CVE-2026-94096 (Netcore NBR200V2): Command injection in LAN IP Configuration Handler via the ipv4 argument (CVSS 9.9). The vendor has not provided a response. Additional details: NVD CVE-2026-94096.
  • CVE-2026-94097 (Netcore NBR200V2): Command injection in CGI Diagnostic Endpoint via the param/key/val arguments (CVSS 10). The vendor has not responded. Additional details: NVD CVE-2026-94097.
  • CVE-2026-94098 (Netcore NBR200V2): Command injection in Firmware Upgrade CGI Endpoint via QUERY_STRING (CVSS 9.1). The vendor has not responded. Additional details: NVD CVE-2026-94098.
  • CVE-2026-94099 (Netcore NBR200V2): Command injection in Backup Restore (restore.cgi) via QUERY_STRING (CVSS 9.9). The vendor has not provided a response. Additional details: NVD CVE-2026-94099.
  • CVE-2026-94100 (Netcore NBR200V2): Buffer overflow in routerd (WAN VLAN Reconfiguration) via vlan_wanX.ports (CVSS 9.9). The vendor has not responded. Additional details: NVD CVE-2026-94100.

From the Security Press

The Hacker News publication reports major incidents and vulnerabilities recently patched by vendors or actively exploited online:

  • CVE-2026-28326 (SolarWinds Access Rights Manager): A vulnerability with a CVSS score of 8.8 caused by a hardcoded key, which allows remote code execution by unauthenticated users in versions 2026.2 and earlier. Original article: The Hacker News.
  • CVE-2026-58138 (Orkes Conductor): Fortinet warns of the active exploitation of a critical pre-auth RCE vulnerability (CVSS 9.8) in the Orkes Conductor platform (versions 3.21.21 through 3.30.2). Original article: The Hacker News.

What We Recommend

To ensure network and system resilience in the face of these emerging threats, CyberSec Intelligence specialists recommend implementing the following practical measures:

  • Patch Management: Urgently update the Linux kernel (especially that used in production environments), Cisco equipment (ISE and SEG), and the SolarWinds ARM platform to the latest secure versions.
  • Inventory and Removal of EoL Equipment: Identify D-Link, Totolink, Comfast, and Netcore devices in the network. Given that Netcore has not responded to notifications, it is recommended to replace them with current alternatives that benefit from active support.
  • Monitoring and Isolation: Restrict public access to the web management interfaces of all network equipment and ensure rigorous network segmentation to limit the lateral propagation of potential attacks.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *