Weekly briefing: September 21 to September 27, 2026
Unauthenticated attackers are exploiting CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, to run code on systems acting as OAuth authorization servers. Citrix confirmed that two critical unauthenticated RCE vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in NetScaler ADC and Gateway.
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Unauthenticated attackers are exploiting CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, to run code on systems acting as OAuth authorization servers.
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers The Hacker News
- Critical Vulnerability in F5 BIG-IP APM CERT-EU
- Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) – CVE-2026-94127 Canadian Centre for Cyber Security
- Vulnerability in F5 BIG-IP CERT-FR
- A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code Execution CIS MS-ISAC
- Heap-based buffer overflow vulnerability in F5 BIG-IP Access Policy Manager (CVE-2026-94127) JPCERT/CC
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Citrix confirmed that two critical unauthenticated RCE vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in NetScaler ADC and Gateway.
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation The Hacker News
- Citrix confirms two NetScaler RCE zero-days exploited in attacks BleepingComputer
- Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products Australian Cyber Security Centre
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway CISA
- Critical Vulnerabilities in Citrix NetScaler ADC and Gateway CERT-EU
- Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772 Canadian Centre for Cyber Security
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
CISA added the vulnerability to its KEV catalog on September 25, 2026 after open-source reports of active exploitation.
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers The Hacker News
- Elementor WordPress flaw lets attackers create admin accounts BleepingComputer
- Vulnerability in WordPress CERT-FR
- WordPress security advisory (AV26-952) – Update 1 Canadian Centre for Cyber Security
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Microsoft SharePoint CVE-2026-65660, a code injection flaw, allows authenticated attackers to execute arbitrary code on vulnerable servers. CISA added CVE-2026-65660 to its KEV catalog on September 25, 2026, and federal agencies must patch by September 28.
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE The Hacker News
- Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks SecurityWeek
- Vulnerability Impacting Microsoft SharePoint Server – CVE-2026-65660 Canadian Centre for Cyber Security
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
GitLab’s non-expiring incoming email token can allow holders to commit code with user permissions and trigger CI/CD jobs. CERT-FR reported multiple GitLab vulnerabilities, some enabling arbitrary code execution, data confidentiality breach, and remote XSS.
- A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You The Hacker News
- GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks Dark Reading
- Multiple vulnerabilities in GitLab CERT-FR
- GitLab security advisory (AV26-962) Canadian Centre for Cyber Security
Update Chrome: 108 security fixes for desktop, new release for Android
Google released Chrome 154 for desktop and began rolling out Chrome 155 for Android, addressing 108 security fixes. CIS MS-ISAC warned that the most severe Chrome vulnerabilities could allow arbitrary code execution in the logged-on user's context.
- Update Chrome: 108 security fixes for desktop, new release for Android Malwarebytes Labs
- Multiple vulnerabilities in Google Chrome CERT-FR
- Google Chrome security advisory (AV26-955) Canadian Centre for Cyber Security
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution CIS MS-ISAC
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Microsoft disrupted the EvilTokens device-code phishing service, seizing 50 websites and disabling over 150 domains.
- Microsoft disrupts AI-assisted platform that compromised 12,000 accounts Ars Technica
- Microsoft Disrupts EvilTokens Device Code Phishing Service Dark Reading
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises The Hacker News
- Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Threat Intelligence
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters-linked attackers exploited CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules to deploy web shells on dozens of systems.
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells The Hacker News
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks BleepingComputer
- ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft Google Threat Intelligence
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
Malwarebytes Labs reported that ShinyHunters said the breach was revenge for a “false” report and wants the bureau to retract its warning.
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Ars Technica noted that a simple ClickFix attack is one way to completely hijack the Meta Muse agent.
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Check Point fixed a zero-day in its Security Management Server that could run scripts without login and was actively exploited in July attacks.
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting CVE-2026-93952 in certificate-authenticated VeloCloud Orchestrators, with some release trains still awaiting fixes. CISA added CVE-2026-93952 to its KEV catalog on September 22, 2026 after open-source reports of active exploitation.
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups The Hacker News
- Arista Networks security advisory (AV26-947) – Update 1 Canadian Centre for Cyber Security
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.