Today, September 26, 2026, the CyberSec Intelligence team presents the daily security bulletin. We monitor emerging threats and provide updated information about active vulnerabilities to help you protect your digital assets and IT infrastructure.
Actively exploited vulnerabilities
The following security flaws have been added to the CISA KEV catalog, with clear evidence of their active exploitation in real-world attacks:
- CVE-2026-67279 (MikroTik RouterOS): An improper behavioral workflow enforcement issue allows an unauthenticated client to open a session channel and send an execution request, risking a chain attack. Details: NVD CVE-2026-67279.
- CVE-2026-65660 (Microsoft SharePoint): A code injection vulnerability allows an authorized attacker to execute malicious code over the network. Details: NVD CVE-2026-65660.
- CVE-2026-87902 (WordPress Core): Remote File Inclusion (RFI) vulnerability that allows unauthenticated attackers to include local PHP files from outside the active theme directories, leading to remote code execution (RCE). Details: NVD CVE-2026-87902.
- CVE-2026-5430 (WSO2 Multiple Products): Path Traversal in API Control Plane, API Manager, Traffic Manager and Universal Gateway which can facilitate unrestricted file upload and RCE. Details: NVD CVE-2026-5430.
- CVE-2026-71362 (Adobe Commerce and Magento): Improper authorization flaw through which attackers can obtain privileged access to sensitive resources, without user interaction. Details: NVD CVE-2026-71362.
- CVE-2026-93952 (Arista VeloCloud Orchestrator): Improper input validation on on-prem systems allows a remote attacker to access internal functionalities and compromise the orchestrator. Details: NVD CVE-2026-93952.
- CVE-2026-94127 (F5 BIG-IP APM): Heap-based buffer overflow when an access policy and an OAuth profile are configured on a virtual server, allowing unauthenticated attackers RCE. Details: NVD CVE-2026-94127.
- CVE-2026-93616 (Check Point Multiple Products): Path Traversal in Security Management Server, Multi-Domain Security Management Server and other affected servers, allowing the upload and execution of arbitrary scripts. Details: NVD CVE-2026-93616.
- CVE-2026-85102 (Check Point Multiple Products): Incorrect certificate validation in Security Gateway and Spark Firewall, which can allow an unauthenticated attacker to execute code on the Gateway via VPN. Details: NVD CVE-2026-85102.
- CVE-2026-7273 (Zyxel GS1900 Series Switches): Stack-based buffer overflow in the CGI utility, allowing local area network (LAN) attackers to execute operating system commands via modified HTTP requests. Details: NVD CVE-2026-7273.
New critical vulnerabilities
Recently identified by security researchers, these breaches represent a critical risk to the affected systems:
- CVE-2026-97359 (HFS2): A critical Template Injection vulnerability (CVSS 10) in the multipart upload module that allows unauthenticated attackers to execute code by entering malicious syntax in the file name. Details: NVD CVE-2026-97359.
- CVE-2026-93399 (WordPress Bookly Plugin): Critical Insecure Direct Object Reference (IDOR) vulnerability in versions up to and including 28.2, which allows unauthenticated attackers to hijack other customers’ tokens and delete bookings. Details: NVD CVE-2026-93399.
- CVE-2026-97063 (X-SpringBoot): Unencrypted return of authentication codes directly in HTTP responses allows account compromise via the API. Details: NVD CVE-2026-97063.
- CVE-2026-97064 (X-SpringBoot): The presence of a predefined and hardcoded master verification code (172839) allows attackers to authenticate as any user, knowing only the associated email or phone number. Details: NVD CVE-2026-97064.
From the security press
We monitor industry publications to highlight active exploitation campaigns:
- CVE-2026-48842 (Roundcube Webmail): The Canadian Centre for Cyber Security warned about the active exploitation of a pre-authentication SQL Injection vulnerability in the virtuser_query plugin of Roundcube Webmail (versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1). Details: The Hacker News.
Our recommendations
To reduce your organization’s exposure, we recommend swiftly implementing the following preventive measures:
- Patch Management: Urgently update the operating systems and applications mentioned in this bulletin, prioritizing platforms directly exposed to the internet such as WordPress, Roundcube, MikroTik, and F5.
- Asset inventory: Maintain an accurate inventory of all technologies deployed across the network to quickly map new CVEs to your own infrastructure elements.
- Disabling unsecure configurations: Ensure you disable any default master credentials or predefined access codes in databases, especially in custom solutions based on frameworks like X-SpringBoot.
- Traffic monitoring: Implement strict rules in SIEM / IDS solutions to detect anomalous queries, Path Traversal attempts, and unusual behaviors on management interfaces.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




