Buletin de securitate cibernetică – 22 septembrie 2026

Cybersecurity Bulletin – September 22, 2026

The csint.ro bulletin from September 22, 2026 highlights actively exploited vulnerabilities in Linux Kernel, Cisco, and Acronis, alongside new critical security breaches with maximum impact and news from the press.

The CyberSec Intelligence (csint.ro) team presents the daily cybersecurity bulletin for September 22, 2026. In this edition, we analyze a series of actively exploited vulnerabilities in critical systems from Cisco, Acronis, and Google Pixel, alongside newly identified critical breaches in network equipment from D-Link, Netcore, and Gigatech, as well as a summary of the main threats from the specialized press.

Actively exploited vulnerabilities

The following vulnerabilities have been added to the CISA KEV (Known Exploited Vulnerabilities) catalog, confirming their active use in attacks:

  • CVE-2026-7273: Affects Zyxel GS1900 Series Switches. A stack-based buffer overflow vulnerability in the CGI program allows an unauthorized attacker from the local area network (LAN) to execute commands on the operating system through malicious HTTP requests. Details: CVE-2026-7273.
  • CVE-2025-39964: Affects Linux Kernel. A race condition vulnerability in the handling of AF_ALG sockets allows concurrent writes to the same socket, which can lead to corruption of the internal state and data inconsistencies. Details: CVE-2025-39964.
  • CVE-2026-53266: Affects Linux Kernel. An out-of-bounds write vulnerability in the ebtables SNAT target component allows overwriting the hardware addresses of ARP senders directly into a non-linear socket buffer fragment. Users of affected systems, possibly at end-of-life (EoL), are advised to upgrade to supported versions. Details: CVE-2026-53266.
  • CVE-2025-39682: Affects Linux Kernel. An incorrect check of exceptional conditions on the TLS receive path allows bypassing the correct processing of recvmsg() type records, leading to the misprocessing of subsequent TLS packets. Migrating from EoL products to active versions is recommended. Details: CVE-2025-39682.
  • CVE-2026-58704: Affects Google Pixel devices. A logic error in the cellular modem causes an improper authorization vulnerability, allowing attackers to bypass security checks and escalate their privileges. Details: CVE-2026-58704.
  • CVE-2026-76460: Affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Incorrect use of privileged APIs allows unauthorized remote attackers to bypass the web management interface and obtain unauthorized access to the device. Details: CVE-2026-76460.
  • CVE-2026-87886: Affects the Acronis Backup plugin for cPanel & WHM and the extension for Plesk. Incorrect default permissions create a vulnerability that can be exploited for privilege escalation on affected systems. Details: CVE-2026-87886.

New critical vulnerabilities

New maximum severity vulnerabilities (CVSS scores of 9.9 and 10.0) have been reported, with most already having public exploits:

  • CVE-2026-94003: Affects Comfast CF-N1-S routers (version 2.6.0.1). A stack-based buffer overflow vulnerability in the get_css_path_from_uri function in the web administration interface (/cgi-bin/mbox-config) allows remote attacks. Details: CVE-2026-94003.
  • CVE-2026-94089: Affects D-Link DIR-868L routers (version 2.01b05). A stack-based buffer overflow error in the strcpy function in /webfa_authentication.cgi can be exploited remotely by manipulating authentication arguments (id/password). Details: CVE-2026-94089.
  • CVE-2026-94097: Affects Netcore NBR200V2 devices (version 1.3.241127.071246). A command injection vulnerability in the CGI diagnostic endpoint (/www/cgi-bin/network_tools) allows remote attackers to execute arbitrary commands. The manufacturer has not provided a response. Details: CVE-2026-94097.
  • CVE-2026-94099: Also affects Netcore NBR200V2. Another command injection vulnerability in the Backup Restore component (restore.cgi) allows command execution by manipulating the query string remotely. Details: CVE-2026-94099.
  • CVE-2026-94493: Affects Gigatech PDV5701 devices (version 1.0.31_240305_112640). The lack of authentication in the WebSocket service associated with the /index.html page allows unauthorized remote control. Details: CVE-2026-94493.

From the security press

The Hacker News publication highlighted in its weekly recap a series of emerging risks associated with the abuse of trust in legitimate infrastructure elements:

  • Weekly recap: Recent attacks targeting zero-day vulnerabilities in Cisco devices, remote code execution (RCE) via AI agents, ClickFix campaigns, and browser hijackings are analyzed. The material draws attention to how attackers utilize exposed systems and weak verification mechanisms to compromise trusted workflows. Source: The Hacker News.

What we recommend

To protect your infrastructure against these active and critical threats, CyberSec Intelligence specialists recommend the following practical measures:

  • Strict Patch Management: Prioritize applying security updates provided by manufacturers for operating systems (Linux Kernel), Cisco devices, and backup solutions (Acronis).
  • Network Equipment Inventory: Identify and isolate router or switch devices (D-Link, Comfast, Netcore, Zyxel) that are no longer supported by the manufacturer (EoL) or are running vulnerable firmware.
  • Restricting Access to Management Interfaces: Disable direct internet exposure of web administration interfaces and WebSocket services for all network equipment, using secure VPN connections or strict IP-based access policies.
  • Monitoring and Log Analysis: Configure detection rules for unusual connection attempts or suspicious HTTP requests addressed to CGI interfaces on routers and switches.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *