Network-Appliance
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key Enables Unauthenticated RCE
A hard-coded cryptographic key in SolarWinds Access Rights Manager (CVE-2026-28326, CVSS 8.8) lets an adjacent-network attacker run arbitrary code with no credentials. Patch to ARM 2026.2.1.
CVE-2026-87886: Acronis Backup Plugin for cPanel and Plesk Exploited for Root on Shared Hosting
CVE-2026-87886 (CVSS 7.8) lets a low-privileged local user escalate to root on cPanel, WHM, Plesk, and DirectAdmin hosts via world-writable files left behind by Acronis's backup plugin — already exploited in targeted attacks and added to CISA KEV with a September 19 federal deadline.
FamousSparrow's New SparroWocky Backdoor Hits Latin American Governments Through Exposed Exchange Servers
ESET details SparroWocky, a new C++ backdoor deployed by the China-aligned FamousSparrow group via public-facing Microsoft Exchange servers against Latin American governments since mid-2025.
CVE-2026-76460: Maximum-Severity Cisco ISE Auth Bypass Exploited Before Disclosure
CVE-2026-76460 (CVSS 10.0) lets unauthenticated attackers bypass Cisco ISE's web management entirely via a privileged API endpoint and get root — Cisco found it while cleaning up a customer who was already compromised, and CISA added it to KEV within a day.
CVE-2026-59971: MySQL MCP Server's SSE Mode Ships With No Auth, No Host Checks — CVSS 10
CVE-2026-59971 (CVSS 10) in the designcomputer mysql_mcp_server package leaves SSE/HTTP deployments wide open to unauthenticated SQL execution, reachable directly or via DNS rebinding, with no fix required beyond upgrading to 0.4.2.
CVE-2026-5430: Active Exploitation of WSO2 API Manager JWT Bypass Delivers Forged Admin Tokens
Attackers are actively exploiting CVE-2026-5430 (CVSS 9.8), a JWT signature-verification flaw in WSO2 API Manager and its Universal Gateway, to forge tokens carrying administrator privileges — watchTowr's honeypots caught the first forged-admin-token traffic on September 13.
CVE-2026-75754: Chained Flaw in ASUS Control Center Enterprise Gives Unauthenticated Root
CVE-2026-75754 (CVSS 10.0) chains a missing-auth SSRF flaw with hardcoded SSH credentials to hand unauthenticated attackers root on ASUS Control Center Enterprise servers — and everything those servers manage.
Three Strikes: How Cisco's Firewall Brain Became Everyone's Favorite Target
In 2026, Cisco Secure FMC took three separate maximum-severity zero-days — and the third one put a Russian APT and a ransomware affiliate on the same box, in the same weeks, running the same playbook. That convergence is the story, not the CVE.
CVE-2026-85102 & CVE-2026-85103: Dutch NCSC Warns Exploitation of Check Point VPN Certificate RCE Flaws Is Imminent
Two unauthenticated CVSS 9.8 RCE bugs in Check Point's VPN certificate handling have hotfixes since September 9 — the Dutch NCSC says active exploitation is likely imminent even though no public PoC exists yet.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production
CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root
Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.
Two Critical Command Injection Flaws in Advantech WISE-6610 Industrial Gateways (CVE-2026-79697, CVE-2026-79698)
Two CVSS 9.9 command injection bugs in Advantech's WISE-6610 cellular IoT gateway let an attacker with access to the admin web UI run arbitrary OS commands as root, with public exploit code already circulating.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches
A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.