The CyberSec Intelligence team presents the daily security bulletin for September 20, 2026. Today we analyze a series of major vulnerabilities, including actively exploited flaws in the Linux kernel and enterprise equipment, alongside critical risks identified in software libraries and cloud platforms.
Actively exploited vulnerabilities
Linux Kernel (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Three actively exploited vulnerabilities have been identified in the Linux Kernel: a race condition in AF_ALG sockets (CVE-2025-39964), an out-of-bounds write in the ebtables SNAT component (CVE-2026-53266), and an improper verification in the TLS receive path (CVE-2025-39682). These can lead to inconsistent states or system compromise, potentially affecting end-of-life/end-of-support (EoL/EoS) versions as well. Details on NVD CVE-2025-39964, NVD CVE-2026-53266 and NVD CVE-2025-39682.
Cisco Identity Services Engine (CVE-2026-76460)
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) allows incorrect usage of privileged APIs. An unauthenticated, remote attacker can bypass the web administration interface to obtain unauthorized access. Details on NVD CVE-2026-76460.
Cisco Secure Email Gateway (CVE-2026-76461)
A SQL Injection vulnerability in Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) allows an unauthenticated attacker to execute arbitrary commands with root privileges on the underlying operating system. Details on NVD CVE-2026-76461.
Google Pixel (CVE-2026-58704)
Google Pixel devices are affected by an improper authorization error in the cellular modem, allowing an attacker to bypass permission checks and escalate privileges. Details on NVD CVE-2026-58704.
Acronis Backup (CVE-2026-87886)
The Acronis Backup plugin for cPanel & WHM and the extension for Plesk contain a vulnerability related to incorrect default permissions, which can facilitate privilege escalation. Details on NVD CVE-2026-87886.
New critical vulnerabilities
vm2 (CVE-2026-93603, CVE-2026-93605)
The vm2 library (up to version 3.12.0) is affected by extremely severe sandbox escape vulnerabilities (CVSS score 10.0). CVE-2026-93603 allows running arbitrary code on the host by manipulating the ‘this’ receiver in non-strict calls. Also, CVE-2026-93605 (in versions prior to 3.12.1) allows escape by omitting the ‘child_process’ module from the DANGEROUS_BUILTINS blacklist. Details on NVD CVE-2026-93603 and NVD CVE-2026-93605.
Totolink A3002MU (CVE-2026-93738, CVE-2026-93739, CVE-2026-93740, CVE-2026-93741, CVE-2026-93742)
Totolink A3002MU devices (version Hh-B20211125.1046) present multiple critical vulnerabilities (CVSS between 9.9 and 10.0), including buffer overflows in the formSchedule, formWlAc, formWlEncrypt, formWlWds functions, and a command injection in formWsc. Exploits are public and can be executed remotely. Details on NVD CVE-2026-93738, NVD CVE-2026-93739, NVD CVE-2026-93740, NVD CVE-2026-93741 and NVD CVE-2026-93742.
Hongjing e-HR (CVE-2023-54399)
A SQL Injection vulnerability (CVSS 9.8) affects Hongjing e-HR before version 8.2 in the /servlet/codesettree endpoint, allowing unauthenticated attackers to read sensitive data from the database. Details on NVD CVE-2023-54399.
IBM Guardium Data Protection (CVE-2026-81657)
Version 12.2 of IBM Guardium Data Protection contains an untrusted data deserialization vulnerability (CVSS 9.8), which allows unauthenticated remote attackers to execute arbitrary code. Details on NVD CVE-2026-81657.
LightLLM (CVE-2026-93839)
The LightLLM platform (up to version 1.2.0) presents an authentication bypass vulnerability (CVSS 9.8) in the WebSocket /pd_register endpoint, which allows registering arbitrary nodes and intercepting user data. Details on NVD CVE-2026-93839.
OpenShift console (CVE-2026-75885)
A vulnerability in the OpenShift console allows unauthenticated access to devfile endpoints, causing Server-Side Request Forgery (SSRF) and potential Denial of Service (DoS) attacks through massive memory consumption. Details on NVD CVE-2026-75885.
OpenPanel (CVE-2026-93985)
A sandbox escape vulnerability in the js-runtime engine of OpenPanel allows attackers with write access to projects to execute arbitrary code in the worker process by using computed properties in webhook templates. Details on NVD CVE-2026-93985.
From the security press
Azure AI Foundry (CVE-2026-85889)
Microsoft has fixed a critical vulnerability (CVSS score 10.0) in Azure AI Foundry. This allowed an unauthorized attacker to escalate network privileges due to the lack of authentication for a critical function. Fortunately, the update was applied directly in the cloud, requiring no action on the part of users. Details on The Hacker News.
Orkes Conductor (CVE-2026-58138)
According to Fortinet reports, a critical pre-authentication Remote Code Execution (RCE) vulnerability affects the Orkes Conductor workflow platform (versions 3.21.21 through 3.30.2) and is actively exploited in the wild. Details on The Hacker News.
SolarWinds Access Rights Manager (CVE-2026-28326)
SolarWinds has released security updates to address a severe vulnerability (CVSS 8.8) in Access Rights Manager (ARM) caused by the use of a hard-coded key, which could allow unauthenticated attackers to execute remote code. Details on The Hacker News.
What we recommend
- Patch Management (Patch Management): Urgently apply updates provided by vendors for the affected systems, especially to remediate active vulnerabilities in the Linux kernel, Cisco, and backup platforms.
- Asset Inventory (Asset Inventory): Identify all network equipment and software libraries, paying special attention to vm2 versions, Totolink network equipment, or open-source integrations at the end of life (EoL).
- Traffic and API Call Monitoring: Consolidate security policies on gateway equipment and implement strict rules for monitoring access to Cisco administrative APIs and sensitive endpoints (such as WebSockets).
- Zero-Trust and Least Privilege Policy: Restrict default permissions of backup modules and block unauthenticated access to sensitive network or cloud functions by properly configuring access control mechanisms.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




