Overview
Description
Statistics
- 11 Posts
- 11 Interactions
Fediverse
Der Hersteller F5 veröffentlichte ein Advisory zu einer ausgenutzten Zero-Day Schwachstelle in seinem Produkt BIG-IP Access Policy Manager (APM) zur sicheren Zugriffsteuerung und Anwendungszugriff: CVE-2026-94127, CVSS-Score 9.8/10 ("kritisch")
F5 gibt an, dass die Schwachstelle bereits aktiv ausgenutzt wird. IT-Sicherheitsverantwortliche sollten unverzüglich die Patchstände prüfen und, sofern erforderlich, die verfügbaren Engineering Hotfixes einspielen.
CVE-2026-94127: Critical zero-day in F5 BIG-IP APM exploited for RCE on OAuth Authorization Servers. Patch urgently or use F5's iRule mitigation. Monitor for OAuth auth failures and TMM SIGABRTs. https://radar.offseq.com/threat/f5-patches-big-ip-apm-zero-day-flaw-exploited-in-rce-attacks-191545153729ae57 #OffSeq #F5 #ZeroDay #RCE #Vuln
F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: https://radar.offseq.com/threat/critical-f5-big-ip-vulnerability-exploited-as-zero-day-024f528e7ee83eed #OffSeq #F5 #ZeroDay #Infosec
📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE
F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
Bluesky
Overview
Description
Statistics
- 9 Posts
- 6 Interactions
Fediverse
🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.
GitHub: https://github.com/abraxas/CVE-2026-87902
Credit: @abraxas_null (X)
CVE-2026-87902: how close is your WordPress to remote code execution? - Security Affairs
Bluesky
Overview
Description
Statistics
- 6 Posts
Fediverse
📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack
CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow
Bluesky
Overview
Description
Statistics
- 6 Posts
- 6 Interactions
Fediverse
Completing our tour of new known-exploited vulns today, here is Arista's perfect-10.
https://ifin.network/t/arista-cve-2026-93952-auth-bypass-exploited-in-the-wild/856
Arista confirmed active exploitation of a CVSS 10 VeloCloud Orchestrator vulnerability (CVE-2026-93952) affecting certificate-based SD-WAN setups. Patch now.
#VeloCloud #Arista #CVE202693952 #SDWAN #Vulnerability #CyberSecurity
CVE-2026-93952: CRITICAL zero-day in Arista VeloCloud Orchestrator (on-prem <5.2.3.16, <6.4.2.8) is actively exploited. Remote attackers can access privileged functions w/o creds. Patch now — review logs for signs of compromise. https://radar.offseq.com/threat/arista-urges-immediate-patching-of-exploited-vco-zero-day-0c28c2caa003025a #OffSeq #Arista #ZeroDay #Infosec
Bluesky
Overview
Description
Statistics
- 5 Posts
- 4 Interactions
Fediverse
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
📰 Check Point Zero-Days in Management Servers and VPNs Under Active Attack
CISA KEV Alert: Two critical Check Point zero-days (CVE-2026-93616 & CVE-2026-85102) are under active attack. Flaws in Management Servers & VPN gateways allow RCE. Patch immediately. #CyberSecurity #Vulnerability #CheckPoint #PatchNow
Bluesky
Overview
- Canon Inc.
- Satera MF750C Series
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
CVE-2024-0244: Connor Ford details how he exploited the #Canon MF753Cdw printer back when he was a #Pwn2Own contestant. Now he's on the judging side as a ZDI analyst, but Doom is still on the table. https://www.zerodayinitiative.com/blog/2026/9/23/cve-2024-0244-a-heap-buffer-overflow-in-the-canon-mf753cdw-printer
CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer https://www.thezdi.com/blog/2026/9/23/cve-2024-0244-a-heap-buffer-overflow-in-the-canon-mf753cdw-printer
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)
CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerablehttps://thecybersecguru.com/news/cve-2026-80521-ubuntu-kernel-container-escape/
Security researchers published a working exploit for CVE-2026-80521, a Linux AF_UNIX use-after-free that can escape a container and gain root on the host. Their PoC targets Ubuntu 26.04. The kernel fix landed upstream Aug. 6, but Canonical's tracker still lists 26.04 as vulnerable/work in progress and 24.04 as vulnerable. That raises urgency.
Again, Ubuntu is behind on security.
https://depthfirst.com/research/containers-are-no-longer-safe
Overview
Description
Statistics
- 3 Posts
Fediverse
Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps.
#Nextjs #CVE202694545 #RCE #Cybersecurity #WebSecurity #Vulnerability
Bluesky
Overview
- D-Link
- DIR-822A
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally.
Bluesky
Overview
- Zohocorp
- ManageEngine OpManager
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. https://radar.offseq.com/threat/cve-2026-19599-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-d62870fccbe1d229 #OffSeq #Vuln #InfoSec #RCE
ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network.
#ManageEngine #Cybersecurity #CVE202619599 #OpManager #Infosec #Vulnerability