The CyberSec Intelligence team presents the daily security bulletin for September 24, 2026. Today’s analysis covers a series of actively exploited vulnerabilities in network equipment and the Linux kernel, new critical breaches identified in enterprise software solutions, as well as alarming news from the industry press regarding active attack campaigns and zero-day tools.
Actively Exploited Vulnerabilities
- CVE-2026-93952 (Arista VeloCloud Orchestrator): Incorrect input validation in on-prem versions, allowing a remote attacker to access internal privileged functionalities and compromise the confidentiality, integrity, and availability of the orchestrator. Details in NVD CVE-2026-93952.
- CVE-2026-94127 (F5 BIG-IP APM): Heap-based buffer overflow when an access policy and an OAuth profile are configured on a virtual server, potentially facilitating remote code execution by an unauthenticated attacker. Details in NVD CVE-2026-94127.
- CVE-2026-93616 (Check Point Multiple Products): Path traversal vulnerability in Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, allowing an unauthenticated attacker to upload and execute arbitrary scripts. Details in NVD CVE-2026-93616.
- CVE-2026-85102 (Check Point Multiple Products): Improper certificate validation in Check Point Security Gateway and Spark Firewall (when using Site-to-Site VPN or Remote Access VPN), allowing an unauthenticated remote attacker to execute arbitrary code on the gateway. Details in NVD CVE-2026-85102.
- CVE-2026-7273 (Zyxel GS1900 Series Switches): Stack-based buffer overflow in the CGI program, allowing an unauthenticated attacker on the local network to execute OS commands via a modified HTTP request. Details in NVD CVE-2026-7273.
- CVE-2025-39964 (Linux Kernel): Race condition at the AF_ALG socket level that allows concurrent writes, causing unpredictable data interleaving and inconsistencies in the internal state. Details in NVD CVE-2025-39964.
- CVE-2026-53266 (Linux Kernel): Out-of-bounds write in ebtables SNAT target, allowing the ARP sender’s hardware address to be rewritten directly into a non-linear socket-buffer fragment. Users are advised to transition to active versions, as products may be EoL. Details in NVD CVE-2026-53266.
- CVE-2025-39682 (Linux Kernel): Incorrect verification of exceptional conditions on the TLS receive path, allowing a zero-length record in rx_list to bypass recvmsg() processing and affect zero-copy assumptions. Affected products may be at the end of their lifecycle. Details in NVD CVE-2025-39682.
New Critical Vulnerabilities
Lantronix Devices
A suite of critical severity vulnerabilities has been reported for Lantronix terminals (SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, SLCx-02):
- CVE-2026-80155 (CVSS Score 10): Authentication bypass in the web management portal, allowing unauthenticated attackers to read sensitive configuration files and upload files to disk to achieve remote code execution. Details in NVD CVE-2026-80155.
- CVE-2026-80144 and CVE-2026-80146 (CVSS Score 9.9): Command injection and stack-based buffer overflow by exploiting undocumented mfc eeprom write/read commands, facilitating the execution of shell commands as root by authenticated users. Details in CVE-2026-80144 and CVE-2026-80146.
- CVE-2026-80151 and CVE-2026-80152 (CVSS Score 9.1): Command injection vulnerabilities in NFS download system calls and script scheduling, offering authenticated users with service privileges the permission to execute shell commands as root. Details in CVE-2026-80151 and CVE-2026-80152.
Adobe Campaign Classic (ACC)
The Adobe Campaign Classic platform is affected by numerous high-risk security flaws:
- CVE-2026-75699, CVE-2026-75721 and CVE-2026-89276 (CVSS Score up to 10): Code Injection vulnerabilities that can lead to arbitrary code execution in the context of the current user without their interaction. Details in CVE-2026-75699, CVE-2026-75721 and CVE-2026-89276.
- CVE-2026-82009 (CVSS Score 9.1): SQL Injection that allows an attacker with elevated privileges to execute arbitrary SQL commands and implicitly code on the server. Details in CVE-2026-82009.
- CVE-2026-82013, CVE-2026-82443 and CVE-2026-83660 (CVSS Score up to 9.9): Server-Side Request Forgery (SSRF) flaws that can be exploited by an attacker with low privileges to achieve privilege escalation in internal resources. Details in CVE-2026-82013, CVE-2026-82443 and CVE-2026-83660.
From the Security Press
- Active campaign with the CLEANGULP malware: A Chinese threat group (UTA0565) has been observed exploiting a chain of zero-day vulnerabilities in Google Chrome (including CVE-2026-85046 and CVE-2026-87491) and Windows ALPC (CVE-2026-85880) to distribute the CLEANGULP malware through fake websites. Details in The Hacker News.
- Server-side code execution in Next.js ImageResponse: A vulnerability in Next.js allows server-side code execution via the ImageResponse component when applications integrate attacker-controlled values, such as URL text, into images. Vercel released a fix on September 22. Details in The Hacker News.
- Critical update for WordPress core: WordPress has patched a critical vulnerability that allows an unauthenticated attacker to cause a site to load PHP files from outside the theme directories, potentially leading to arbitrary code execution on certain servers. The patch was included in version 7.1.2. Details in The Hacker News.
- Unauthenticated command execution in Bifrost AI Gateway (CVE-2026-90898): A critical vulnerability (CVSS 9.8) in the open-source Bifrost gateway allows an unauthenticated attacker to execute arbitrary commands on the server via a single HTTP request, affecting versions prior to version 2.1.0 when authentication is disabled. Details in The Hacker News.
- Zero-day tool published against Microsoft Defender (BigDiskBuster): A Proof-of-Concept named BigDiskBuster, created by researcher Abdelhamid Naceri, has been released on GitHub. It prevents Defender platform and signature updates by filling disk space, with no official patch currently available. Details in The Hacker News.
Recommendations
- Strict and immediate patch management: Urgently apply updates to exposed systems, paying close attention to WordPress servers (update to 7.1.2), the Next.js framework, Adobe Campaign Classic, and firmware patches provided by Lantronix and network equipment manufacturers.
- Inventory and replacement of EoL assets: Identify Linux kernel versions used in production and replace or update systems running End-of-Life versions that no longer receive active fixes for the reported vulnerabilities.
- Securing management interfaces: Limit remote access to management consoles (web and CLI) for Arista and Lantronix devices and Bifrost gateways, prohibiting direct internet exposure and using exclusively secure VPNs and multi-factor authentication.
- Rigorous monitoring of storage space and logs: Configure automatic alerts for disk status (to prevent disk exhaustion attacks such as BigDiskBuster) and monitor event logs to intercept path traversal attempts and suspicious script executions.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




