Zero-Day
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-93952: Actively Exploited CVSS 10 Flaw Hands Attackers Privileged Access to Arista's VeloCloud Orchestrator
A maximum-severity input validation flaw in Arista's VeloCloud Orchestrator lets attackers who hold only the public half of an edge device's certificate reach privileged internal functionality on the SD-WAN control plane — and it's already being exploited in the wild.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
Plugin4Shell: SHA-Pinning Bypass Enables Zero-Click RCE Across Claude Code, Codex, Copilot, and Gemini CLI
A Git reference-resolution flaw dubbed Plugin4Shell lets a plugin repository owner silently swap the code behind a SHA-pinned install across all four major AI coding agents, achieving zero-click RCE on developer and CI machines that trust the pin.
CVE-2026-85102 & CVE-2026-85103: Dutch NCSC Warns Exploitation of Check Point VPN Certificate RCE Flaws Is Imminent
Two unauthenticated CVSS 9.8 RCE bugs in Check Point's VPN certificate handling have hotfixes since September 9 — the Dutch NCSC says active exploitation is likely imminent even though no public PoC exists yet.
Microsoft's September Patch Tuesday Sets a New Record: ~970 Flaws, Two Zero-Days Actively Exploited
Microsoft's largest Patch Tuesday ever ships fixes for roughly 970 CVEs, including two zero-days already under active attack in the Windows Update Stack and ALPC, plus a trio of CVSS 10.0 cloud-identity bugs in Azure AD B2C, Azure AI Language, and Copilot Studio.
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.
CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE
SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.
CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation
CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation — VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.
CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely
A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.
ShieldBreak (CVE-2026-69414): A Full Bypass of Microsoft's RoguePlanet Defender Patch, Still Unfixed
Nightmare Eclipse's ShieldBreak fully bypasses the fix for RoguePlanet, Microsoft Defender's earlier SYSTEM-privilege zero-day. Microsoft has assigned CVE-2026-69414 and confirmed a patch is in progress, but none has shipped.
SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE
A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.
Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)
CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.