Active-Exploitation
CVE-2026-61500: Rejetto HFS Predictable Session Key Gives Unauthenticated Admin and RCE, Probed Within a Day
Rejetto HFS 3.x signs sessions with a key derived from Math.random() and leaks its outputs at login, letting unauthenticated attackers forge admin sessions and run server-side JavaScript; scanning from China began October 1.
CVE-2026-88779: NetScaler SAML Memory Overflow Zero-Day Crashes Auth, Hits Freshly Patched Appliances
Citrix confirms exploitation of a NetScaler ADC/Gateway SAML memory overflow (CVSS 8.7) that crashes authentication services; honeypot data suggests appliances patched for the previous batch are also being hit.
Zammad CVE-2026-102489 and CVE-2026-102490: Session Hijack to Root Chain Exploited in DIVD Breach
Two Zammad zero-days chain a session hijack into RCE and local root; DIVD says an autonomous AI agent used them to breach its network, CISA added both to KEV, and the root flaw reportedly has no patch.
Warlock Ransomware Crew Keeps Breaking In Through SharePoint, Hits Water and Telecom Operators
Symantec ties the China-linked Storm-2603 (Longlegs) crew to new Warlock ransomware intrusions at a water utility and a telecom, using SharePoint access, a vulnerable K7 driver, VS Code tunnels and SYSVOL deployment.
FortiMail CVE-2026-104286: Unauthenticated Path Traversal Exploited as Zero-Day
Fortinet confirms in-the-wild exploitation of CVE-2026-104286, a CVSS 9.8 path traversal in FortiMail that lets unauthenticated attackers write arbitrary files. Patches are not yet released; CISA set a October 4 deadline.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Exploited
Cisco confirms in-the-wild exploitation of CVE-2026-76504, a CVSS 9.8 URL-encoding auth bypass that hands unauthenticated attackers admin API access on Catalyst SD-WAN Manager. No workaround; CISA added it to KEV.
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
CISA Adds Three Linux Kernel Flaws to KEV: TLS Receive Path, ebtables SNAT, and AF_ALG Race Condition Under Active Exploitation
CISA added three Linux kernel CVEs to its Known Exploited Vulnerabilities catalog on evidence of in-the-wild exploitation — a CVSS 9.8 TLS receive-path flaw, an 8.8 ebtables SNAT out-of-bounds write, and a 7.8 AF_ALG race condition — with FCEB remediation due September 21.
CVE-2026-87886: Acronis Backup Plugin for cPanel and Plesk Exploited for Root on Shared Hosting
CVE-2026-87886 (CVSS 7.8) lets a low-privileged local user escalate to root on cPanel, WHM, Plesk, and DirectAdmin hosts via world-writable files left behind by Acronis's backup plugin — already exploited in targeted attacks and added to CISA KEV with a September 19 federal deadline.
CVE-2026-76460: Maximum-Severity Cisco ISE Auth Bypass Exploited Before Disclosure
CVE-2026-76460 (CVSS 10.0) lets unauthenticated attackers bypass Cisco ISE's web management entirely via a privileged API endpoint and get root — Cisco found it while cleaning up a customer who was already compromised, and CISA added it to KEV within a day.
CVE-2026-5430: Active Exploitation of WSO2 API Manager JWT Bypass Delivers Forged Admin Tokens
Attackers are actively exploiting CVE-2026-5430 (CVSS 9.8), a JWT signature-verification flaw in WSO2 API Manager and its Universal Gateway, to forge tokens carrying administrator privileges — watchTowr's honeypots caught the first forged-admin-token traffic on September 13.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing
A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.
N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production
CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.
Microsoft's September Patch Tuesday Sets a New Record: ~970 Flaws, Two Zero-Days Actively Exploited
Microsoft's largest Patch Tuesday ever ships fixes for roughly 970 CVEs, including two zero-days already under active attack in the Windows Update Stack and ALPC, plus a trio of CVSS 10.0 cloud-identity bugs in Azure AD B2C, Azure AI Language, and Copilot Studio.