Today, September 23, 2026, cybersecurity specialists from CyberSec Intelligence (csint.ro) present the daily analysis of threats in the digital environment. Continuous risk assessment and the prompt application of patches are essential to maintain the integrity and availability of your organization’s IT infrastructure.
Actively Exploited Vulnerabilities
The following vulnerabilities are reported as actively exploited in cyberattacks and have been included in the CISA KEV catalog:
- Arista VeloCloud Orchestrator (CVE-2026-93952): Incorrect validation of input data in the on-premise VCO platform allows a remote attacker to access privileged internal features, endangering the confidentiality, integrity, and availability of the managed data. Source: CVE-2026-93952.
- F5 BIG-IP APM (CVE-2026-94127): A heap-based buffer overflow, occurring when the access policy and OAuth profile are configured on a virtual server, allows an unauthenticated attacker to execute remote code. Source: CVE-2026-94127.
- Check Point (CVE-2026-93616): A path traversal vulnerability in Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products allows an attacker to upload and execute arbitrary scripts. Source: CVE-2026-93616.
- Check Point (CVE-2026-85102): Improper validation of certificates in Security Gateway and Spark Firewall (when using Site-to-Site VPN or Remote Access VPN) allows an unauthenticated attacker to run arbitrary code on the gateway. Source: CVE-2026-85102.
- Zyxel GS1900 Series Switches (CVE-2026-7273): A stack-based buffer overflow in the CGI program allows an unauthenticated local area network (LAN) attacker to execute operating system commands via malicious HTTP requests. Source: CVE-2026-7273.
- Linux Kernel (CVE-2025-39964): A race condition in concurrent writing to the AF_ALG socket can corrupt its internal state and cause data inconsistencies. Source: CVE-2025-39964.
- Linux Kernel (CVE-2026-53266): An out-of-bounds write vulnerability in the ebtables SNAT target allows direct writing to the socket buffer fragments. Affected products may be at the end of their lifecycle (EoL/EoS). Source: CVE-2026-53266.
- Linux Kernel (CVE-2025-39682): Incorrect verification of exceptional conditions on the TLS receive path can lead to bypassing the handling logic, affecting the processing of subsequent data packets. Products may be EoL/EoS. Source: CVE-2025-39682.
- Google Pixel (CVE-2026-58704): Improper authorization in the cellular modem allows bypassing checks and privilege escalation. Source: CVE-2026-58704.
- Cisco Identity Services Engine (CVE-2026-76460): Incorrect use of privileged APIs in Cisco ISE and ISE-PIC allows an unauthenticated attacker to bypass the web management interface to obtain unauthorized access. Source: CVE-2026-76460.
- Acronis Backup (CVE-2026-87886): Misconfigured default permissions in the plugin for cPanel & WHM and the extension for Plesk can be exploited for privilege escalation. Source: CVE-2026-87886.
New Critical Vulnerabilities
In the past 24 hours, technical details have been published for a series of new critical vulnerabilities:
- Gigatech PDV5701 (CVE-2026-94493): A complete lack of authentication in the WebSocket Service (/index.html) exposes the product to remote attacks. A public exploit is already available, and the manufacturer has not provided an official response. Source: CVE-2026-94493.
- Lantronix Series (CVE-2026-80144, CVE-2026-80145, CVE-2026-80146, CVE-2026-80151, CVE-2026-80152, CVE-2026-80155, CVE-2026-80156): Lantronix SLC8000, EMG8500, EMG7500, SLB882, and SLCx models are affected by multiple critical-severity vulnerabilities. These include command injections (via mfc eeprom write/read, set nfs download, set script schedule, set cifs password) and a critical web portal authentication bypass (CVE-2026-80155) based on file name truncation and path traversal, leading to remote code execution as root. Source: CVE-2026-80155.
- Softaculous Virtualizor (CVE-2026-43641): An OS command injection in the billing module allows remote attackers to take complete control over the host and managed VPSs through deserialization of modified data in the billing_data POST field. Source: CVE-2026-43641.
- Adobe Campaign Classic (CVE-2026-73369, CVE-2026-75699, CVE-2026-75721): Critical code injection vulnerabilities that can lead to arbitrary code execution in the context of the current user, without requiring any interaction from them. Source: CVE-2026-73369.
From the Security Press
Relevant information recently published in the specialty press:
- WordPress core patch: A major update (WordPress 7.1.2, with fixes retroactively applied down to version 4.7) has been released to patch a critical security flaw. Unauthenticated attackers could cause sites to load PHP files from outside authorized theme directories, allowing code execution on certain servers. Source: The Hacker News.
- Bifrost AI Gateway (CVE-2026-90898): A critical RCE vulnerability with a CVSS score of 9.8 affects the Bifrost artificial intelligence gateway, allowing unauthenticated attackers to execute commands by sending a single HTTP request when authentication is disabled. Source: The Hacker News.
- PoC BigDiskBuster: A zero-day disk space exhaustion vulnerability was disclosed on GitHub that prevents the installation of signature and platform updates for Microsoft Defender. Currently, there is no official patch. Source: The Hacker News.
- Weekly recap: The report highlights a rise in ClickFix attacks, the emergence of zero-day vulnerabilities on Cisco devices, and severe issues in AI agent systems. Source: The Hacker News.
What We Recommend
To protect the infrastructure and prevent potential compromises, the CyberSec Intelligence team recommends implementing the following measures:
- Rigorous patch management: Immediately update all systems directly exposed to the internet, prioritizing critical platforms such as WordPress, F5 servers, Check Point, Cisco, and Adobe suites. Replace or isolate Linux systems and IoT devices declared End-of-Life (EoL/EoS) that no longer receive security patches.
- Isolation and auditing of management interfaces: Ensure that access to management panels (Lantronix, Zyxel, AI platforms) is not publicly exposed, but is protected behind a secure VPN connection and a properly configured firewall.
- Continuous monitoring and access control: Monitor connection logs of critical web applications and services to identify suspicious transactions, authentication bypass attempts, or unauthorized disk writes.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




