Weekly briefing: September 21 to September 27, 2026

Unauthenticated attackers are exploiting CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, to run code on systems acting as OAuth authorization servers. Citrix confirmed that two critical unauthenticated RCE vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in NetScaler ADC and Gateway.

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Unauthenticated attackers are exploiting CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, to run code on systems acting as OAuth authorization servers.

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Citrix confirmed that two critical unauthenticated RCE vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in NetScaler ADC and Gateway.

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

CISA added the vulnerability to its KEV catalog on September 25, 2026 after open-source reports of active exploitation.

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Microsoft SharePoint CVE-2026-65660, a code injection flaw, allows authenticated attackers to execute arbitrary code on vulnerable servers. CISA added CVE-2026-65660 to its KEV catalog on September 25, 2026, and federal agencies must patch by September 28.

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

GitLab’s non-expiring incoming email token can allow holders to commit code with user permissions and trigger CI/CD jobs. CERT-FR reported multiple GitLab vulnerabilities, some enabling arbitrary code execution, data confidentiality breach, and remote XSS.

Update Chrome: 108 security fixes for desktop, new release for Android

Google released Chrome 154 for desktop and began rolling out Chrome 155 for Android, addressing 108 security fixes. CIS MS-ISAC warned that the most severe Chrome vulnerabilities could allow arbitrary code execution in the logged-on user's context.

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft disrupted the EvilTokens device-code phishing service, seizing 50 websites and disabling over 150 domains.

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

ShinyHunters-linked attackers exploited CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems.

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

Malwarebytes Labs reported that ShinyHunters said the breach was revenge for a “false” report and wants the bureau to retract its warning.

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Ars Technica noted that a simple ClickFix attack is one way to completely hijack the Meta Muse agent.

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Check Point fixed a zero-day in its Security Management Server that could run scripts without login and was actively exploited in July attacks.

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes. CISA added CVE-2026-93952 to its KEV catalog on September 22, 2026 after open-source reports of active exploitation.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.