Daily briefing: Wednesday, September 23, 2026

Unauthenticated attackers are exploiting CVE-2026-94127 in F5 BIG-IP APM to run code on OAuth authorization servers, and the vendor reports active exploitation with indicators of compromise available. ShinyHunters claims it breached the FBI and stole employee data, while the FBI says it is investigating activity affecting FBIjobs.gov. Multiple vulnerabilities in SolarWinds Observability Self-Hosted allow remote code execution, including critical CVE-2026-28324 and high CVE-2026-28325.

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Unauthenticated attackers are exploiting CVE-2026-94127 in F5 BIG-IP APM to run code on OAuth authorization servers, and the vendor reports active exploitation with indicators of compromise available.

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ShinyHunters claims it breached the FBI and stole employee data, while the FBI says it is investigating activity affecting FBIjobs.gov.

Vulnerability in WordPress

A WordPress vulnerability allowing remote code execution is being exploited in the wild, identified as CVE-2026-87902.

Multiple vulnerabilities in SolarWinds Observability Self-Hosted

Multiple vulnerabilities in SolarWinds Observability Self-Hosted allow remote code execution, including critical CVE-2026-28324 and high CVE-2026-28325.

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Attackers chained two RouterOS SSH flaws to gain full admin access on Internet-exposed MikroTik routers before patches were available.

Multiple vulnerabilities in Google Chrome

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Multiple vulnerabilities in Adobe products including Bridge and Connect could allow arbitrary code execution.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.