Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: exploited-in-wild (8 articles)Clear

Apple patches exploited CoreGraphics zero-day enabling code execution from a malicious file

Apple released updates for a zero-day it says was used in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 27. Tracked as CVE-2026-20700, the flaw is an out-of-bounds write in CoreGraphics, the framework for two-dimensional graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS, and was reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple addressed it with improved bounds checking. The affected device list is broad, spanning iPhone 11 and later, many iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple did not attribute the attacks or name the targeted individuals.

Check
Push the latest iOS, iPadOS, and macOS updates to all managed Apple devices now, prioritizing individuals at elevated risk of targeted attacks.
Affected
Apple devices before the fixed versions can be driven to arbitrary code execution by opening a maliciously crafted file through the CoreGraphics out-of-bounds write.
Fix
Apply the CoreGraphics fixes across iOS, iPadOS, and macOS, enforce update deadlines via MDM, and consider Lockdown Mode for high-risk users.

Citrix confirms two NetScaler remote code execution zero-days exploited in active attacks

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks, and released fixes. These are the same zero-days that researchers, IT providers, and national cyber agencies warned about privately over the weekend, with some advising immediate NetScaler shutdowns. Organizations commonly deploy NetScaler as internet-facing edge devices for remote access and application delivery, so compromising one gives attackers a foothold at the network perimeter and a potential path to internal systems without first landing on an internal endpoint. CISA added the flaws to its Known Exploited Vulnerabilities catalog with a near-term federal patch deadline.

Check
Identify all internet-facing NetScaler appliances, apply Citrix's fixed builds immediately, and hunt for compromise indicators given confirmed active exploitation.
Affected
Unpatched internet-facing NetScaler appliances face active exploitation of two remote code execution zero-days, handing attackers a foothold at the network perimeter.
Fix
Patch NetScaler to Citrix's fixed versions now, restrict management exposure, review sessions and logs, and treat exposed devices as potentially compromised.

Critical Roundcube webmail SQL injection now actively exploited to bypass authentication and steal data

The Canadian Centre for Cyber Security updated its May advisory to warn that attackers are now actively exploiting a Roundcube Webmail flaw, CVE-2026-48842, four months after it was patched. Roundcube is a browser-based IMAP client used as the default mail interface by thousands of services and pre-installed with the cPanel hosting control panel. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that handles database-driven user lookups. Exploitation lets an unprivileged attacker bypass authentication, inject and run database commands, and steal data from Roundcube's database, without user interaction in high-complexity attacks. Roundcube fixed it in versions 1.6.16 and 1.7.1, and Shadowserver tracks over 523,000 exposed instances online.

Check
Inventory internet-facing Roundcube instances, including those bundled with cPanel, and upgrade to 1.6.16 or 1.7.1 immediately while checking for signs of compromise.
Affected
Unpatched Roundcube servers let an unauthenticated attacker exploit the virtuser_query SQL injection to bypass login and read the webmail database.
Fix
Update Roundcube to 1.6.16 or 1.7.1, restrict webmail exposure, and review database and authentication logs for injection attempts.

Chained MikroTik RouterOS SSH flaws let attackers seize exposed routers without authentication

CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.

Check
Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, remove SSH from public interfaces, and check exposed routers for signs of takeover.
Affected
Internet-exposed MikroTik routers on unpatched RouterOS let an unauthenticated attacker chain the two SSH flaws into full administrative control.
Fix
Patch RouterOS to the fixed releases, restrict SSH to management networks or disable it, and rotate credentials on any reachable device.

Attackers exploit unauthenticated WordPress code execution flaw within hours of its disclosure

Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.

Check
Update WordPress to the patched release now, then check whether active themes contain page- prefixed directories and review web logs for pearcmd.php requests.
Affected
WordPress sites meeting the theme and server preconditions let an unauthenticated attacker chain local file inclusion into remote code execution, already seen in the wild.
Fix
Apply the WordPress patch, harden PHP to disable pearcmd.php inclusion, and block the observed exploit indicators at the web tier.

F5 patches exploited BIG-IP APM zero-day allowing remote code execution on access proxies

F5 released updates for a critical BIG-IP Access Policy Manager zero-day that it confirms is being exploited in remote code execution attacks. Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server, where a BIG-IP APM access policy and an OAuth profile sit on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected. F5 told customers to hunt for multiple OAuth authentication failures and suspicious commands followed by a TMM SIGABRT, and offered an iRule mitigation for those who cannot patch immediately. Shadowserver tracks over 14,700 exposed BIG-IP APM instances, and CISA added the flaw to its catalog.

Check
Identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply F5's update now, or deploy the iRule mitigation and check for compromise indicators.
Affected
BIG-IP APM instances acting as an OAuth Authorization Server with an access policy and OAuth profile on one virtual server face active remote code execution attacks.
Fix
Patch to F5's fixed BIG-IP releases, apply the iRule workaround if patching is delayed, and review logs for OAuth failures preceding a TMM SIGABRT.

VeloCloud Orchestrator flaw under active exploitation lets remote attackers compromise SD-WAN management servers

Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.

Check
Identify on-premises VeloCloud Orchestrator instances using certificate-based Edge authentication, then apply the fixed 5.2 or 6.4 release and restrict web interface access.
Affected
On-premises orchestrators configured for certificate-based Edge authentication let unauthenticated remote attackers reach internal functions, compromise the host, and pivot to managed Edge devices.
Fix
Upgrade to fixed 5.2 or 6.4 releases, limit orchestrator web access to trusted networks, and monitor for the July flaw already reported exploited.

CISA flags exploited Zyxel switch flaw enabling unauthenticated command execution over the LAN

CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.

Check
Inventory Zyxel GS1900 switches, confirm firmware against the fixed versions, and update immediately while removing switch management interfaces from untrusted LAN segments.
Affected
Unpatched GS1900 switches let a LAN-based unauthenticated attacker run operating system commands via crafted HTTP requests, and active campaigns are already exfiltrating data.
Fix
Apply Zyxel's June firmware fixes, segment and restrict switch management access, and hunt for signs of prior compromise on exposed devices.