Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

F5 patches exploited BIG-IP APM zero-day allowing remote code execution on access proxies

F5 released updates for a critical BIG-IP Access Policy Manager zero-day that it confirms is being exploited in remote code execution attacks. Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server, where a BIG-IP APM access policy and an OAuth profile sit on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected. F5 told customers to hunt for multiple OAuth authentication failures and suspicious commands followed by a TMM SIGABRT, and offered an iRule mitigation for those who cannot patch immediately. Shadowserver tracks over 14,700 exposed BIG-IP APM instances, and CISA added the flaw to its catalog.

Check
Identify BIG-IP APM virtual servers configured as OAuth Authorization Servers, apply F5's update now, or deploy the iRule mitigation and check for compromise indicators.
Affected
BIG-IP APM instances acting as an OAuth Authorization Server with an access policy and OAuth profile on one virtual server face active remote code execution attacks.
Fix
Patch to F5's fixed BIG-IP releases, apply the iRule workaround if patching is delayed, and review logs for OAuth failures preceding a TMM SIGABRT.

Critical Bifrost AI gateway flaw lets unauthenticated attackers run commands and steal provider keys

JFrog disclosed a critical flaw in Bifrost, an open-source AI gateway routing to over twenty LLM providers, that lets an unauthenticated attacker run arbitrary commands on the gateway with a single HTTP request. Tracked as CVE-2026-90898 and rated 9.8, it affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled, which is the default. An attacker registers a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the command immediately, before any handshake, as the gateway user. Because the gateway stores API keys for every connected provider, command execution also exposes those credentials, and the official Docker image binds its management API to all interfaces.

Check
Upgrade Bifrost to transports 2.1.0, enable management authentication, keep the management listener off untrusted networks, and rotate any provider keys the gateway held.
Affected
Bifrost gateways before 2.1.0 with default disabled management auth let an unauthenticated attacker run commands and read every connected provider API key.
Fix
Update to 2.1.0, set governance.auth_config.is_enabled to true with strong credentials, avoid publishing the management port, and treat exposed instances as compromised.

Critical Next.js ImageResponse flaw enables server code execution through crafted SVG input

Vercel patched a critical flaw in Next.js ImageResponse, the feature that generates Open Graph and social preview images, that can let attackers run code on the server. Tracked as CVE-2026-94545 and rated 9.5, it affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the default Node.js runtime, and is fixed in 16.3.6. The Edge runtime and Next.js 15 are not affected. ImageResponse uses the Satori library to convert layouts into SVG before rendering, and apps are exposed when they pass attacker-controlled values, such as text from a request URL, into SVG content, attributes, or styles. As of disclosure there were no public exploits or reports of attacks.

Check
Search code for ImageResponse imported from next/og in route handlers and opengraph-image files, then upgrade affected apps to Next.js 16.3.6.
Affected
Next.js apps on 16.2.0 through 16.3.5 using Node runtime ImageResponse with attacker-controlled values in generated SVG can be driven to server code execution.
Fix
Update to Next.js 16.3.6, avoid placing request-derived values into image content, and consider the Edge runtime where feasible for image generation.

VeloCloud Orchestrator flaw under active exploitation lets remote attackers compromise SD-WAN management servers

Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.

Check
Identify on-premises VeloCloud Orchestrator instances using certificate-based Edge authentication, then apply the fixed 5.2 or 6.4 release and restrict web interface access.
Affected
On-premises orchestrators configured for certificate-based Edge authentication let unauthenticated remote attackers reach internal functions, compromise the host, and pivot to managed Edge devices.
Fix
Upgrade to fixed 5.2 or 6.4 releases, limit orchestrator web access to trusted networks, and monitor for the July flaw already reported exploited.

CISA flags exploited Zyxel switch flaw enabling unauthenticated command execution over the LAN

CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.

Check
Inventory Zyxel GS1900 switches, confirm firmware against the fixed versions, and update immediately while removing switch management interfaces from untrusted LAN segments.
Affected
Unpatched GS1900 switches let a LAN-based unauthenticated attacker run operating system commands via crafted HTTP requests, and active campaigns are already exfiltrating data.
Fix
Apply Zyxel's June firmware fixes, segment and restrict switch management access, and hunt for signs of prior compromise on exposed devices.

Linux kernel ARM64 virtualization flaw lets guest machines read and write host memory

A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave freed host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, it lets a guest read and write host kernel memory, and the reporter says it can be used to escape the guest and run code on the host. A size calculation reaching zero skips a TLB invalidation, leaving a freed page mapped and writable with no hardware trap. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization is off by default and needs specific ARM hardware, and no exploitation is reported.

Check
Determine whether ARM64 KVM hosts enable experimental nested virtualization, then update to the patched kernel builds before relying on guest isolation there.
Affected
ARM64 KVM hosts running nested virtualization on affected kernels let a guest read and write freed host memory and potentially escape to the host.
Fix
Patch to Linux 6.18.51, 7.2.5, or 7.3-rc1, keep nested virtualization disabled where unneeded, and restrict access to /dev/kvm.

Researchers escape OpenAI Codex sandbox to run commands on developer machines

Accomplish AI researcher Oren Yomtov disclosed two OpenAI Codex sandbox escapes, the more serious dubbed Heapjack. Codex Desktop installs a node_repl component into the global config with no opt-in, and plain Codex CLI users inherit it. That process runs trusted OpenAI code and untrusted agent code in one Node instance sharing a heap, where a random authorization token sits in memory. Untrusted code snapshots the heap, recovers the token, and writes requests onto the pipe to an unsandboxed parent process, reaching any Unix socket including a Docker daemon. Opening a malicious repository and asking about the code yields unsandboxed execution with no prompt.

Check
Update Codex CLI and Desktop to the fixed builds, then review whether developers opened untrusted repositories in Codex during the exposure window.
Affected
Any Codex user, including CLI users who never enabled it, could be handed host command execution by opening someone else's repository and querying it.
Fix
Apply OpenAI's patches, isolate coding agents from Docker sockets and credentials, and treat opening untrusted repositories in an agent as code execution.

SolarWinds Access Rights Manager hard coded key enables unauthenticated remote code execution

SolarWinds patched a high-severity flaw in Access Rights Manager, tracked as CVE-2026-28326 and rated 8.8, that stems from a hard-coded static key and can lead to unauthenticated remote code execution. The issue affects all Access Rights Manager 2026.2 and prior releases and is fixed in 2026.2.1. SolarWinds credited Armadin researcher Kai Huang and reported no evidence of exploitation in the wild. The advisory arrives alongside separate fixes: a Web Help Desk SAML authentication bypass, a Web Help Desk denial-of-service issue, and sixteen Serv-U flaws that could allow privilege escalation, code execution, and creation of administrator accounts.

Check
Inventory SolarWinds Access Rights Manager instances, confirm versions at or below 2026.2, and upgrade to 2026.2.1 on an emergency schedule.
Affected
Access Rights Manager 2026.2 and earlier ship a hard-coded static key that an unauthenticated attacker can use to reach remote code execution.
Fix
Patch to 2026.2.1, restrict management interfaces to trusted networks, and separately update Web Help Desk and Serv-U to their fixed builds.

Public exploits released for four Linux kernel flaws that grant local root

Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.

Check
Update to the patched kernel across multi-user and shared hosts, then verify the running kernel version rather than the installed package alone.
Affected
Any low-privileged local account on an unpatched kernel can escalate to root, especially where unprivileged user namespaces or the SCTP module are available.
Fix
Apply kernel updates, disable unprivileged user namespaces and blacklist the SCTP module where not needed, and prioritize shared servers with local users.

WordPress flaw forces theme installs and can chain to server code execution

WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.

Check
Update all WordPress sites to 7.1.1 immediately, then audit installed themes for unexpected additions and remove any that administrators did not intend.
Affected
Sites where an administrator opens a crafted link can silently install an attacker-chosen theme, which can chain with a vulnerable theme to code execution.
Fix
Apply 7.1.1, remove unused themes, and warn administrators against opening untrusted links while authenticated to the WordPress dashboard.