Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.
bleepingcomputer.com
· 2026-09-23
Security firm Patchstack says threat actors began exploiting a critical WordPress path traversal flaw, CVE-2026-87902, to write files that execute shell commands, after initial reconnaissance traffic surged tenfold. The bug, discovered by researcher Robert Ressl and rated 9.2/10 in severity, allows unauthenticated attackers to trick get_page_template() into loading arbitrary local PHP files under certain theme and server configurations. WordPress patched the issue in version 7.1.2 and backported fixes to branches as old as 4.7.
bleepingcomputer.com
· 2026-09-23
Eclypsium's September InfraTrust Pulse report logged 158 new security advisories across 17 vendors between August 25 and September 17, covering 1,699 vulnerabilities. Of these, 42 were rated critical, eight scored a maximum 10.0 severity, 71 could be exploited remotely without authentication, and five advisories included flaws later added to CISA's Known Exploited Vulnerabilities catalog. The report singles out a maximum-severity Cisco Secure Firewall Management Center authentication bypass, CVE-2026-20079, which Cisco confirmed on September 9 was being actively exploited, allowing attackers to run commands as root without credentials.
bleepingcomputer.com
· 2026-09-23
Arista Networks has issued patches for CVE-2026-93952, a maximum-severity flaw in on-premises deployments of VeloCloud Orchestrator, the centralized management platform for VeloCloud SD-WANs. The bug, an improper input validation issue affecting setups using certificate-based authentication between edge devices and the orchestrator, lets remote attackers gain privileged internal access without credentials or user interaction, and Arista says it is already being exploited in the wild.
bleepingcomputer.com
· 2026-09-23
F5 issued patches for a critical zero-day in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127, which is being exploited to achieve remote code execution on systems configured as an OAuth Authorization Server. F5 says setups using APM only as an OAuth Client or Resource Server are unaffected, and offered an iRule-based mitigation for those unable to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it by Friday.
bleepingcomputer.com
· 2026-09-23
Security researchers have identified a high-severity vulnerability in WordPress that carries a CVSS score of 9.2 out of 10, indicating it can be exploited with relatively low complexity and minimal attacker privileges. The flaw has reportedly existed in every version of the platform released since 2016, meaning it has gone undetected or unpatched for nearly a decade.
github.com
· 2026-09-22
Check Point Software has issued emergency hotfixes for CVE-2026-93616, a critical path traversal vulnerability in its Security Management Server that lets unauthenticated attackers upload and run arbitrary scripts. The company confirmed the flaw is being actively exploited, with a handful of customers already compromised, and released a fix in R82.20 Security Hotfix covering Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
bleepingcomputer.com
· 2026-09-22
D-Link disclosed a maximum-severity vulnerability, CVE-2026-86296, affecting its legacy DIR-822A dual-band routers, caused by a stack-based buffer overflow in the DHCP server component. The bug requires no authentication and can be triggered by sending crafted DHCP packets over the local network, potentially crashing the device or enabling remote code execution. A proof-of-concept exploit is already public, and D-Link has not yet released a patch. The company is also probing a second flaw, CVE-2026-86510, an out-of-bounds write in the L2TP parser reported by the same researcher.
bleepingcomputer.com
· 2026-09-22
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw allows unauthenticated LAN attackers to run OS commands via crafted HTTP requests, and federal agencies must secure affected devices by Thursday under Binding Operational Directive 26-04. Zyxel issued firmware fixes on June 16 but has not yet updated its advisory to acknowledge exploitation.
bleepingcomputer.com
· 2026-09-22
CISA has added three Linux kernel security flaws to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting them in the wild. The bugs include CVE-2025-39964, a 14-year-old race condition in the AF_ALG crypto socket interface; CVE-2026-53266, an out-of-bounds write in ebtables SNAT; and CVE-2025-39682, a flaw in the kernel's TLS receive path. Federal agencies were ordered to patch these by end of day, though CISA has not disclosed details on the attackers or specific incidents.
bleepingcomputer.com
· 2026-09-21
Major tech firms including Microsoft, Oracle and Google reported unprecedented numbers of security patches this year, with Microsoft issuing 974 CVE fixes this month alone and Oracle shipping 1,448 patches in July compared to 309 a year earlier. Analysts tracking cve.icu counted 66,401 confirmed vulnerabilities as of this week, nearly double last September's tally, a jump attributed largely to AI tools now used for automated bug discovery.
wired.com
· 2026-09-19
Intel has stopped its long-running bug bounty program that paid researchers up to $100,000 per vulnerability, replacing it with a new Intigriti-hosted disclosure process that offers no financial rewards. The bounty board remains visible but is marked as suspended, and Intel has not publicly explained the decision. The program had run since 2017 and accounted for roughly 105 of 231 CVEs Intel patched in 2020.
tomshardware.com
· 2026-09-19