F5 released updates for a critical BIG-IP Access Policy Manager zero-day that it confirms is being exploited in remote code execution attacks. Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server, where a BIG-IP APM access policy and an OAuth profile sit on the same virtual server. Deployments using APM strictly as an OAuth client or resource server are not affected. F5 told customers to hunt for multiple OAuth authentication failures and suspicious commands followed by a TMM SIGABRT, and offered an iRule mitigation for those who cannot patch immediately. Shadowserver tracks over 14,700 exposed BIG-IP APM instances, and CISA added the flaw to its catalog.
JFrog disclosed a critical flaw in Bifrost, an open-source AI gateway routing to over twenty LLM providers, that lets an unauthenticated attacker run arbitrary commands on the gateway with a single HTTP request. Tracked as CVE-2026-90898 and rated 9.8, it affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled, which is the default. An attacker registers a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the command immediately, before any handshake, as the gateway user. Because the gateway stores API keys for every connected provider, command execution also exposes those credentials, and the official Docker image binds its management API to all interfaces.
Vercel patched a critical flaw in Next.js ImageResponse, the feature that generates Open Graph and social preview images, that can let attackers run code on the server. Tracked as CVE-2026-94545 and rated 9.5, it affects Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the default Node.js runtime, and is fixed in 16.3.6. The Edge runtime and Next.js 15 are not affected. ImageResponse uses the Satori library to convert layouts into SVG before rendering, and apps are exposed when they pass attacker-controlled values, such as text from a request URL, into SVG content, attributes, or styles. As of disclosure there were no public exploits or reports of attacks.
Arista disclosed on September 22 that attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator, the server that manages Edge devices across a VeloCloud SD-WAN. Tracked as CVE-2026-93952 and rated 10.0, it lets a remote attacker with no login reach internal functions and affect the orchestrator host, but only where Edges authenticate using certificates. A compromised orchestrator exposes the data it manages and can give access to the Edge devices under it. Arista says the flaw was found externally and is known to be actively exploited. Fixed releases exist for the 5.2 and 6.4 trains, with 6.1 and 7.0 still pending.
CISA added a Zyxel GS1900 series switch flaw to its Known Exploited Vulnerabilities catalog, citing active exploitation. Tracked as CVE-2026-7273 and rated 8.8, it is a stack-based buffer overflow in the switch firmware's CGI program that lets a LAN-based, unauthenticated attacker run operating system commands through a crafted HTTP request. Zyxel patched it in June across the GS1900-8 through GS1900-48HPv2 models. GreyNoise reported that a suspected Chinese-speaking actor has weaponized the flaw since August 17, successfully exploiting and exfiltrating data from 996 Zyxel switches across 48 countries. Federal agencies must patch under the KEV directive, and other operators should treat exposed management interfaces as a priority.
A flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave freed host memory exposed to a guest virtual machine when nested virtualization is enabled. Tracked as CVE-2026-89775, it lets a guest read and write host kernel memory, and the reporter says it can be used to escape the guest and run code on the host. A size calculation reaching zero skips a TLB invalidation, leaving a freed page mapped and writable with no hardware trap. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1. Nested virtualization is off by default and needs specific ARM hardware, and no exploitation is reported.
Accomplish AI researcher Oren Yomtov disclosed two OpenAI Codex sandbox escapes, the more serious dubbed Heapjack. Codex Desktop installs a node_repl component into the global config with no opt-in, and plain Codex CLI users inherit it. That process runs trusted OpenAI code and untrusted agent code in one Node instance sharing a heap, where a random authorization token sits in memory. Untrusted code snapshots the heap, recovers the token, and writes requests onto the pipe to an unsandboxed parent process, reaching any Unix socket including a Docker daemon. Opening a malicious repository and asking about the code yields unsandboxed execution with no prompt.
SolarWinds patched a high-severity flaw in Access Rights Manager, tracked as CVE-2026-28326 and rated 8.8, that stems from a hard-coded static key and can lead to unauthenticated remote code execution. The issue affects all Access Rights Manager 2026.2 and prior releases and is fixed in 2026.2.1. SolarWinds credited Armadin researcher Kai Huang and reported no evidence of exploitation in the wild. The advisory arrives alongside separate fixes: a Web Help Desk SAML authentication bypass, a Web Help Desk denial-of-service issue, and sixteen Serv-U flaws that could allow privilege escalation, code execution, and creation of administrator accounts.
Researcher Asim Manizada published working exploit code on September 18 for four Linux kernel local privilege escalation flaws, each letting a local user gain root. The bugs are DirtyAH6 in IPsec AH6, TUNderflow in TUN/TAP, PPPoEject in PPPoE, and DiagSpill in SCTP diagnostics. Kernel maintainers fixed all four in recent weeks after a coordinated hold with distributions, and no in-the-wild abuse has been reported. Three require unprivileged user namespaces, which many distributions enable by default, while DiagSpill needs only an available SCTP module. The exploits are tuned to specific builds and can crash machines, but public code raises risk on shared multi-user systems.
WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.