Overview
Description
Statistics
- 9 Posts
- 7 Interactions
Fediverse
CISA warned of an exploited Zyxel switch vulnerability in GS1900 devices. Patch the Zyxel switch vulnerability now to prevent network compromise.
#Zyxel #CVE20267273 #CISAKEV #BufferOverflow #NetworkSecurity #Infosec
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
Bluesky
Overview
Description
Statistics
- 9 Posts
- 4 Interactions
Fediverse
🚨 Check Point patches Management Server zero-day exploited in attacks
⠀
Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.
⠀
The company says a small number of customers have already been attacked.
⠀
Affected products include:
• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent
⠀
The vulnerability carries a CVSS score of 9.8.
⠀
Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.
⠀
LivePatch Take 28/29 does not fix this vulnerability.
Check Point Quantum Security Management is affected by CVE-2026-93616 (CRITICAL, CVSS 9.8): unauthenticated attackers can upload & execute scripts via path traversal. Restrict access & monitor activity until patch info is released. https://radar.offseq.com/threat/cve-2026-93616-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-4344dfa6a4d98182 #OffSeq #CheckPoint #CyberAlert
A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now.
#CheckPoint #CVE202693616 #Cybersecurity #InfoSec #Vulnerability #RCE
Check Point Fixes a New Actively Exploited Critical Security Flaw
Bluesky
Overview
- D-Link
- DIR-822A
Description
Statistics
- 6 Posts
- 26 Interactions
Fediverse
D-Link warns of two major bugs with public POCs
CVE-2026-86296: https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10516
CVE-2026-93958: https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10518
Public PoC exploit details emerge for critical D-Link DIR-822A vulnerabilities. Learn how these D-Link DIR-822A vulnerabilities impact unpatched devices.
#DLink #DIR822A #CVE202686296 #CVE202686510 #RouterSecurity #Cybersecurity #Infosec
Bluesky
Overview
Description
Statistics
- 4 Posts
- 15 Interactions
Fediverse
When it rains, it pours. F5 BIG-IP APM also has an exploited CVE!
https://ifin.network/t/f5-big-ip-cve-2026-94127-rce-exploited/855
EITW 0day in F5 APM.
https://my.f5.com/manage/s/article/K000162605
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). (CVE-2026-94127)
This vulnerability allows an unauthenticated attacker to perform RCE. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes.
#F5 #BIGIP #CVE202694127 #Cybersecurity #InfoSec #RCE #Vulnerability
Overview
Description
Statistics
- 4 Posts
- 5 Interactions
Fediverse
CVE-2026-93952 (CRITICAL, CVSS 10) impacts Arista VeloCloud Orchestrator (On-Prem) via improper input validation. Remote, unauthenticated access may lead to full system compromise. Patch urgently. https://radar.offseq.com/threat/cve-2026-93952-cwe-20-improper-input-validation-in-arista-networks-velocloud-orchestrator-vco-on-prem-25dafe8f246f1077 #OffSeq #CVE #infosec #Vulnerability
An exploited VeloCloud vulnerability with a 10.0 CVSS score hits Arista appliances. Patch the critical VeloCloud vulnerability to stop active attacks.
#VeloCloud #Arista #CVE202693952 #ZeroDay #Cybersecurity #Infosec
Bluesky
Overview
Description
Statistics
- 4 Posts
- 7 Interactions
Fediverse
An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks.
#CheckPoint #CVE202685102 #VPN #Cybersecurity #Infosec #ZeroDay
Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Service notice: all hosted/maintained WP websites have been updated to the latest minor version of your current major branch (security release, CVE-2026-87902). No action needed from you!
I don't host or maintain your website? Be sure to update your WordPress ASAP. This one is critical.
Release notes → https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
WordPress 7.1.2 patches a critical WordPress RCE vulnerability (CVE-2026-87902). Update your site to prevent conditional remote code execution.
#WordPress #CVE202687902 #RCE #Cybersecurity #Infosec #WordPressSecurity
Overview
Description
Statistics
- 2 Posts
- 6 Interactions
Fediverse
https://www.netspi.com/blog/technical-blog/web-application-pentesting/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/
Overview
- Microsoft
- Microsoft SharePoint Enterprise Server 2016
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE
CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixeshttps://thecybersecguru.com/news/cve-2026-65660-sharepoint-rce/
Overview
- VMware
- Cloud Foundation
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
Pre-Auth vCenter RCE #threatintel #vmwarw
https://mobeta.fr/blog/vcenter-cve-2026-59309-cve-2026-59310/