0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Check Point Multiple Products Path Traversal Vulnerability
CVE-2026-93616: CVSS 9.8 path traversal and file upload in Check Point Management Server enabling unauth RCE. Confirmed exploited; patches available.
Arista VeloCloud Orchestrator Unauthenticated RCE
“CVE-2026-93952 is a CVSS 10.0 improper input validation flaw in Arista VeloCloud Orchestrator that allows unauthenticated remote code execution. Added to CISA KEV on September 22, 2026.”
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux kernel TLS receive path: zero-length record bypasses recvmsg() handling, corrupting downstream TLS processing. CVSS 9.8. In CISA KEV Sept. 18, 2026.
From the desk

D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix
CVE-2026-86296: CVSS 10.0 D-Link DIR-822A zero-day with public PoC exploit code and no patch. D-Link says the device is end-of-life and replacement is needed.

Check Point Patches Management Server Zero-Day
CVE-2026-93616: CVSS 9.8 Check Point Management Server flaw allows unauth script execution via path traversal. Added to CISA KEV with a Sept. 25 deadline.

F5 Patches BIG-IP APM RCE Zero-Day Under Attack
CVSS 9.8 F5 BIG-IP APM heap overflow: unauth RCE when an access policy and OAuth profile share a virtual server. Confirmed exploited; patches available.

ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day
ShinyHunters claims it breached FBI systems via an unpatched Oracle PeopleSoft zero-day, exfiltrating employee data. FBI and Oracle have not confirmed.

Arista VeloCloud CVSS 10.0 Flaw Added to CISA KEV
CISA added CVE-2026-93952, a CVSS 10.0 unauthenticated RCE flaw in Arista VeloCloud Orchestrator, to its KEV catalog September 22. Federal agencies have until September 25 to patch.

New Windows Defender Zero-Day Blocks AV Updates
Naceri released BigDiskBuster, a zero-day PoC that blocks Windows Defender from updating on all supported Windows. No patch and no CVE assigned.
This week's SITREP
Sep 22: Cl0p Extorted, CrowdSec Source Code, BigCommerce
ShinyHunters escalates against Cl0p with an eight-figure demand and threatens to expose ransom-payer records. CrowdSec confirms source code theft. BigCommerce merchants hit via Ribon apps.




