Unpatched Citrix NetScaler RCE Zero-Days, SharePoint and MikroTik RouterOS Flaws Hit CISA KEV, ShinyHunters Bypasses WAFs in Oracle PeopleSoft Attacks

This brief covers September 25–27, 2026. Each item was checked against its primary source (CISA’s KEV alert, the vendor advisory, or the original research), with reputable outlets linked for context. Two things lead this window: a warning of unpatched Citrix NetScaler zero-days under active exploitation, and a CISA KEV update covering Microsoft SharePoint and MikroTik RouterOS.

Two unpatched Citrix NetScaler RCE zero-days reported exploited in the wild

watchTowr · September 26, 2026

On September 26, watchTowr said two unpatched remote code execution vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway were exploited before any fix existed, and that the exploitation was found during forensic investigations. As of Sunday morning Citrix had published no bulletin, CVE IDs, CVSS scores, workarounds, or IOCs, and no CVE is in KEV. watchTowr expects Citrix communications and patches early in the week of September 28. These are separate from the August authentication bypass CVE-2026-19490. Some administrators have taken appliances offline. Because the exploitation came before any patch, installing the fix will not show whether a device was already compromised. Citrix’s existing guidance for suspected compromise (preserve evidence, isolate the appliance, rotate secrets and certificates) is the relevant playbook until then.

“While details are scarce, the information is credible.” (watchTowr, via X)

Source: The Hacker News · Citrix compromise guidance (CTX694799)

CISA adds exploited SharePoint code injection and MikroTik RouterOS flaws to KEV

CISA / Microsoft MSRC · September 25, 2026

CISA added two entries to the KEV catalog. CVE-2026-65660 (CVSS 8.8) is a code injection flaw in SharePoint Server 2016, 2019, and Subscription Edition. It lets an authenticated low-privilege attacker execute code over the network. Microsoft patched it in August and first classified it as spoofing, then reclassified it as RCE. Previdian saw exploitation attempts starting September 24, after Viettel Security published technical details. CVE-2026-67279 (CVSS 6.9) is a RouterOS flaw that lets an unauthenticated client open a session channel and send an exec request. Chained with CVE-2026-86060 (already in KEV) in the “MikroTrick” exploit, it gives unauthenticated administrative control of exposed routers, according to CERT Polska. Both have fixes available, and the SharePoint deadline for federal agencies is September 28.

“As of 9/25/2026, Microsoft had reliable evidence of observed attacks against exploitation of this vulnerability.” (Microsoft MSRC advisory)

Source: CISA alert · MSRC CVE-2026-65660 · SecurityWeek · The Hacker News

ShinyHunters resumes mass exploitation of Oracle PeopleSoft with a one-character WAF bypass

Mandiant / Google Threat Intelligence Group · September 25, 2026

Mandiant and GTIG report a new wave of attacks by UNC6240 (ShinyHunters) exploiting CVE-2026-35273 (CVSS 9.8), an unauthenticated Java deserialization RCE in PeopleSoft’s Environment Management Hub (PSEMHUB). Oracle patched it in June. The attackers request /%50SEMHUB/ instead of /PSEMHUB/, which slips past WAF rules that match the literal path before URL decoding. They are targeting organizations that deployed WAF rules but never patched. Web shells (x.jsp, u.jsp) were found on dozens of systems in higher education, technology, healthcare, government, and other sectors, along with the SIDEEYE backdoor, Neo-reGeorg tunnels, and MeshAgent. Mandiant’s advice: apply Oracle’s patch, disable or remove EMHub, and enforce blocking on the normalized path.

“WAF rules and path-based blocking are not a substitute for patching.” (Mandiant)

Source: Google Cloud Threat Intelligence · Oracle Security Alert · BleepingComputer

Kiteworks tells customers to shut down servers after a law-enforcement warning of an imminent attack

Kiteworks · September 25, 2026

Kiteworks, the secure file-sharing vendor formerly known as Accellion, told customers worldwide to take their systems offline for a six-hour window on Saturday, September 26. The company said federal authorities had warned that a threat actor might target Kiteworks systems. Kiteworks says it knows of no compromise and that all known vulnerabilities are fixed in version 9.5.1. It has not confirmed a zero-day, and no CVE has been assigned. Managed file transfer platforms have a long history as targets for data-theft extortion.

“We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach.” (Kiteworks statement to BleepingComputer)

Source: BleepingComputer · The Hacker News

Compromised Mini Shai-Hulud GitHub Actions came back online still serving malware

Socket · September 25, 2026

Socket found that two GitHub Actions compromised in the May 2026 Mini Shai-Hulud supply-chain campaign, actions-cool/issues-helper and actions-cool/maintain-one-comment, became accessible again on September 16. Their release tags still pointed to the malicious commits, so any workflow that referenced them by tag ran the payload again. GitHub has disabled both repositories a second time. Teams that use either action should audit recent workflow runs, rotate any CI secrets those runs could reach, and pin actions to full commit SHAs.

“On September 16, 2026, both repositories became accessible again.” (Karlo Zanki, Socket)

Source: The Hacker News · BleepingComputer


This brief covers the trailing ~48 hours (September 25–27, 2026).

Primary sources:

WordPress Core RCE Under Active Exploitation, WSO2 and Adobe Commerce Added to KEV, TeamCity Flaw Tied to Ransomware

This brief covers security developments from September 23–25, 2026. Every item was checked against the vendor advisory, the CISA KEV catalog, or the original research, with reputable outlets linked for context.

Attackers move from probing to payloads on WordPress core flaw CVE-2026-87902

WordPress / Patchstack · September 23, 2026

CVE-2026-87902 is an unauthenticated path traversal flaw in WordPress core page-template resolution. It affects versions 4.7.0 through 7.1.1, and the WordPress security team rates it critical (CVSS v4.0 9.2). WordPress 7.1.2 fixed it on September 22, and the fix was backported to every branch down to 4.7. Patchstack saw reconnaissance start within hours of the patch. By September 23, traffic had grown tenfold and included pearcmd.php-based payloads that write PHP files to /tmp and /var/tmp. Remote code execution requires specific theme and server conditions, such as a theme directory whose name starts with page- and PHP’s register_argc_argv setting being enabled. None of the sources reviewed reported a CISA KEV listing.

“Because this is a security release, it is recommended that you update your sites immediately.” — WordPress.org, 7.1.2 release notes

Source: WordPress 7.1.2 Release · GHSA-7hp8-65ch-5whp · BleepingComputer

CISA adds WSO2 API Manager auth bypass CVE-2026-5430 to KEV

CISA / WSO2 · September 24, 2026

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. Federal agencies must patch by September 27. WSO2’s advisory scores the flaw CVSS 3.1 10.0, or 9.8 in single-tenant deployments. It describes a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, which can lead to takeover of administrative accounts. CISA’s KEV entry calls it a path traversal. Affected products are WSO2 API Control Plane 4.5.0–4.6.0, API Manager 4.1.0–4.6.0, Traffic Manager 4.5.0–4.6.0, and Universal Gateway 4.5.0–4.6.0. watchTowr reported in-the-wild attempts against its honeypots since at least September 13.

“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.” — WSO2 Security Advisory WSO2-2026-5328

Source: WSO2-2026-5328 · CISA alert · The Hacker News

Adobe Commerce / Magento session-switching flaw CVE-2026-71362 added to KEV

CISA / Adobe · September 24, 2026

CISA added CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento Open Source (CVSS 9.1), to the KEV catalog in the same September 24 update. The federal remediation deadline is September 27. The bug lets an unauthenticated attacker switch a customer session to another customer’s account. Sansec reported blocking exploitation attempts in August, shortly after Adobe’s APSB26-92 fix. Adobe has not yet updated its advisory to confirm exploitation. The fix is to install the -2026-aug security release or the APSB26-92 isolated patch.

“The vulnerability lets attackers switch a customer session to another customer account.” — Sansec

Source: CISA alert · Sansec research · The Hacker News

CISA marks JetBrains TeamCity CVE-2026-63077 as used in ransomware campaigns

CISA / JetBrains · September 23, 2026

CISA updated the KEV entry for CVE-2026-63077 to show that it is “Known” to be used in ransomware campaigns. The flaw is a critical authentication bypass in TeamCity On-Premises that JetBrains patched on July 25 in versions 2025.11.7 and 2026.1.3. It allows unauthenticated OS command execution through the agent polling protocol. The CVE was first added to KEV on August 5. Shadowserver still tracks about 160 unpatched internet-exposed servers.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands.” — JetBrains

Source: CISA KEV entry · JetBrains update · BleepingComputer

Still developing

Check Point confirms exploitation of Security Gateway VPN RCE and a Management Server zero-day

Check Point · September 22, 2026

Check Point Research confirmed exploitation of two flaws, both rated CVSS 9.8. The first, CVE-2026-85102, is a pre-authentication RCE in Security Gateway and Spark VPN certificate handling. It was patched September 9, and exploitation attempts against Spark customers started September 12. The second, CVE-2026-93616, is a pre-authentication path traversal zero-day in the Management web service that allows arbitrary script execution and Java class loading. It was used in a handful of targeted attacks on July 23 and is fixed via sk1000171. CISA added both to KEV on September 22 with a September 25 due date.

“Customers running affected versions should install the applicable fixes immediately.” — Lotem Finkelstein, Check Point Research

Source: Check Point advisory · sk1000117 · sk1000171 · BleepingComputer

F5 BIG-IP APM OAuth Authorization Server zero-day CVE-2026-94127

F5 · September 22, 2026

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM (CVSS 3.1 9.8 / CVSS 4.0 9.3). Unauthenticated attackers can get RCE when APM is configured as an OAuth Authorization Server. F5 confirmed in-the-wild exploitation and published indicators of compromise plus an iRule mitigation. CISA added the flaw to KEV on September 22. Shadowserver sees roughly 14,700 IPs with BIG-IP APM fingerprints.

“We have learned that this vulnerability has been exploited.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

ShinyHunters claims FBI breach via unpatched Oracle PeopleSoft zero-day

BleepingComputer · September 22, 2026

The ShinyHunters extortion group claims it used a new Oracle PeopleSoft RCE zero-day to reach FBI systems and FBI-managed AWS GovCloud infrastructure. It says it stole 2–3 TB of employee and applicant data. The FBI says it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov” but has not confirmed a breach. Oracle has not published an advisory or CVE, and the zero-day has not been independently verified.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 23–25, 2026).

Primary sources:

Anthropic Launches Claude Opus 5.5, OpenAI Ships GPT-6 Sol and Luna at Half Price, and Claude Agents Find a CRISPR-Like Enzyme System

This brief covers the trailing ~72 hours (September 22–25, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Two frontier releases landed on the same day: Anthropic introduced Claude Opus 5.5, the first model in its Claude 5.5 family, and OpenAI extended its GPT-6 generation downmarket with GPT-6 Sol and GPT-6 Luna at 50% lower API prices. Anthropic also unveiled a life sciences lab and early results in which Claude agents found a previously unrecognized enzyme system. At the UN, Sam Altman addressed the Security Council and OpenAI extended its Daybreak cyber-defense program to Ukraine, and Google added real-time video avatars to Gemini 3.8 Live.

Anthropic introduces Claude Opus 5.5: Fable 5.1-level performance at 40% lower cost than Opus 5

Anthropic · September 22, 2026

Opus 5.5 is the first model in the Claude 5.5 family and Anthropic’s first release since it called for “pacing the frontier.” Anthropic reports 66.4% on Terminal-Bench 4.0, 54.4% on FrontierCode v1.1, 57.8% on CursorBench 4.0, and a GDPval-AA v2.1 Elo of 1846, ahead of Fable 5.1, Opus 5, and GPT-6 Astra on most of those measures. Pricing drops to $4/$20 per million input/output tokens with cache reads at $0.20 (60% below Opus 5), output is over 30% faster, and the model scored best to date on Anthropic’s automated behavioral audit. Because its biology and cyber capabilities are comparable to Claude Mythos 5.1, it ships with Fable 5.1-class safeguards that transparently fall back to other models; Sonnet 5.5 and Haiku 5.5 are due in the coming weeks.

“It performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.” — Anthropic

Source: Introducing Claude Opus 5.5

OpenAI releases GPT-6 Sol and GPT-6 Luna, cutting API prices 50% versus GPT-5.6

OpenAI · September 22, 2026

OpenAI expanded the GPT-6 family with two cheaper tiers trained with methods similar to GPT-6 Astra. GPT-6 Sol is priced at $2/$10 per million input/output tokens and GPT-6 Luna at $0.10/$0.50, both half the GPT-5.6 promotional prices. OpenAI reports Sol scoring 33.2% on Zapier’s AutomationBench at $0.27 per task and 68.8% on DeepSWE v1.1, and says Sol makes about half as many factual mistakes as its predecessor on its internal evaluation. The launch also brings improved prompt caching with 90% discounts on cached reads and cache-preserving changes to reasoning effort and tools; the models are live in ChatGPT Work, Codex, and the API as gpt-6-sol and gpt-6-luna.

“GPT-6 Astra introduced a new generation of intelligence—these models help distribute the benefits of that intelligence by advancing the frontier on cost efficiency.” — OpenAI

Source: Introducing GPT-6 Sol and Luna

Claude agents discover a novel enzyme system with CRISPR-like repeats as Anthropic unveils a life sciences lab

Anthropic · September 23, 2026

Anthropic introduced a new life sciences research group and Bay Area wet lab focused on AI-driven genome mining. In its first reported result, roughly 950 Claude agents spent 21 hours and 210 million tokens surveying over 200,000 reverse transcriptases, narrowing 3,500 candidate systems to 20 detailed reports. One agent spotted a tandem repeat array next to an unusual RT in jumbo phages, a system Anthropic calls array-associated reverse transcriptases (ART). Initial lab experiments show the array is expressed as distinct short RNAs, suggesting a possibly programmable mechanism; its function is still under investigation, and a pre-print has been released.

“This is an exciting example of how AI agents can contribute to biological discovery.” — Feng Zhang, MIT and the Broad Institute

Source: Claude discovers a novel enzyme system with CRISPR-like repeats

Sam Altman addresses the UN Security Council, calling for international frontier AI standards

OpenAI · September 23, 2026

In remarks to the Security Council, Altman named two failure modes to avoid: losing control of the future to AI, especially as systems approach recursive self-improvement, and excessive concentration of power. He said OpenAI has unilaterally slowed down before and will again, and called for complementary national and international frontier AI standards covering capability measurement, risk assessment, safeguard sufficiency, incident reporting, and secure channels for sharing emerging threats, without locking in incumbents.

“Beating companies in a competitive pace is not a reason to make rash decisions.” — Sam Altman, OpenAI

Source: Sam Altman’s remarks at the United Nations Security Council

OpenAI extends its Daybreak cyber-defense program to the Government of Ukraine

OpenAI · September 23, 2026

Announced on the sidelines of the UN General Assembly, the arrangement with Ukraine’s Ministry of Digital Transformation gives Ukrainian teams access to OpenAI’s Daybreak tools for finding software vulnerabilities and developing and testing fixes to protect civilian infrastructure. OpenAI noted its cyber models are already used by defenders in France, Germany, and Poland, and by the EU cyber agency ENISA, and that CERT Polska used them to help find six vulnerabilities in third-party router software.

“Ukraine is already on the front line, and its defenders need support now.” — Sasha Baker, Head of National Security Policy, OpenAI

Source: OpenAI extends cyber access to Ukraine for civilian defense

Google adds Live Avatar to Gemini 3.8 Live for real-time, lip-synced video agents

Google · September 24, 2026

Google paired its Gemini 3.8 Live native dialogue model with low-latency streaming video, producing enterprise agents that listen, see, and speak through an animated persona with lip-sync and facial expressions. The feature supports asynchronous tool calling so the avatar keeps talking while fetching data in the background, switches among 97 languages mid-conversation, and can generate custom avatars from a reference image for allowlisted enterprises. All audio and video output is watermarked with SynthID, and the feature is available now in Gemini Enterprise.

“Starting today, Gemini 3.8 Live with Live Avatar is available in Gemini Enterprise.” — Google

Source: Introducing Gemini 3.8 Live with Live Avatar


This brief covers the trailing ~72 hours (September 22–25, 2026).

Primary sources:

F5 BIG-IP APM RCE, Arista VeloCloud and Check Point Management Zero-Days Hit CISA KEV

This brief covers September 22–23, 2026. Every item below was checked against CISA’s KEV alert and the vendor advisory as reported. On September 22, CISA added four actively exploited flaws to the Known Exploited Vulnerabilities catalog. Three are zero-days in edge and management infrastructure: F5 BIG-IP APM, Arista VeloCloud Orchestrator, and Check Point Management Server. Federal agencies were given three days to patch under BOD 26-04.

F5 BIG-IP APM: unauthenticated RCE exploited as a zero-day (CVE-2026-94127)

F5 / CISA · September 22, 2026

CVE-2026-94127 (CVSS 9.8) is a heap-based buffer overflow in BIG-IP Access Policy Manager. An unauthenticated attacker can use it for remote code execution when an APM access policy and an OAuth profile are configured on a virtual server. Only deployments using APM as an OAuth Authorization Server are affected; Appliance mode is also vulnerable. Affected versions are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3. F5 has shipped hotfixes and published three indicators of compromise (IoCs). The flaw is actively exploited and was added to KEV on September 22.

“We have learned that this vulnerability has been exploited.” — F5 advisory K000162605

Source: F5 K000162605 · SecurityWeek

Arista VeloCloud Orchestrator On-Prem: CVSS 10 zero-day under active attack (CVE-2026-93952)

Arista / CISA · September 22, 2026

CVE-2026-93952 (CVSS 10) is an improper input validation flaw in on-premises VeloCloud Orchestrator (VCO). It lets remote attackers reach privileged internal functionality without tenant or operator credentials. Only instances using certificate-based Edge-to-VCO authentication are exposed. The flaw is fixed in VCO 5.2.3.16 and 6.4.2.8, and patches for other trains are coming. Arista has published no definitive IoCs and recommends reviewing web, application and system logs. The flaw is actively exploited and was added to KEV on September 22.

“This issue was discovered externally and is known to be actively exploited.” — Arista Security Advisory 0183

Source: Arista Security Advisory 0183 · SecurityWeek

Check Point Management Server: pre-auth path traversal and file upload zero-day (CVE-2026-93616)

Check Point / CISA · September 22, 2026

CVE-2026-93616 (CVSS 9.8) is a directory traversal and file upload flaw. It lets unauthenticated attackers upload and run arbitrary scripts on Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. Fixes are in the R82.20 Security Hotfix and in Jumbo Hotfix Takes for R82.10, R82, R81.20 and R81.10. Standard LivePatch updates do not fix it. As interim mitigation, restrict TCP/19009 to trusted IPs. The flaw is actively exploited against a small number of customers and was added to KEV on September 22.

“This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked.” — Check Point sk1000171

Source: Check Point sk1000171 · SecurityWeek

Check Point Security Gateway / Spark VPN auth bypass now exploited (CVE-2026-85102)

Check Point / CISA · September 22, 2026

CVE-2026-85102 (CVSS 9.8) is improper certificate validation during VPN negotiation. It allows unauthenticated authentication bypass and code execution on Security Gateway and Spark firewalls. Check Point patched it on September 9 and at that time had no evidence of exploitation. It now reports exploitation attempts against Spark customers worldwide. The flaw was added to KEV on September 22.

“We are now observing exploitation attempts against Check Point Spark customers globally.” — Check Point

Source: Check Point advisory blog · CISA KEV alert

Still developing

Zyxel GS1900 switch stack overflow added to KEV (CVE-2026-7273)

CISA · September 21, 2026

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series switches, to the KEV catalog based on evidence of active exploitation. SecurityWeek has linked the exploitation to Chinese threat actors. GS1900 owners should apply Zyxel’s fixed firmware.

Source: CISA KEV alert

Brevo supply-chain attack served ClickFix malware through embedded scripts

Brevo / Sansec · September 18, 2026

Attackers used a compromised long-lived Cloudflare API key to deploy a worker. The worker injected malicious scripts into brevo.com, sibforms.com and three JavaScript files that customers embed on their sites. The scripts showed selected visitors fake “verify you are human” ClickFix pages. On WordPress sites where the visitor was a logged-in admin, they tried to install a plugin. Sansec estimates more than 100,000 sites were affected. Sites that embed Brevo widgets should check for unauthorized plugins.

Source: Brevo post-mortem · Sansec · SecurityWeek


This brief covers the trailing ~48 hours (September 22–23, 2026).

Primary sources:

Check Point Management Zero-Day, F5 BIG-IP APM Heap Overflow, and Arista VeloCloud CVSS 10.0 Land in CISA KEV; WordPress 7.1.2 Path Traversal Under Active Attack

This brief covers the trailing ~48 hours (September 22–23, 2026). Every item below was checked against its primary source — the vendor advisory, CISA’s Known Exploited Vulnerabilities (KEV) catalog, or the original research post — and the dates and scores shown are the ones published there.

CISA adds four zero-days to KEV in one day: Check Point (×2), F5 BIG-IP APM, Arista VeloCloud

CISA · September 22, 2026

CISA added four vulnerabilities to the KEV catalog on September 22, all of them edge or management-plane products and all with a federal remediation deadline of September 25, 2026: CVE-2026-85102 and CVE-2026-93616 (Check Point), CVE-2026-93952 (Arista VeloCloud Orchestrator), and CVE-2026-94127 (F5 BIG-IP APM). Each is covered in its own item below. A day earlier, on September 21, CISA also added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, with a September 24 deadline.

“These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.” — CISA

Source: CISA alert (Sept 22) · CISA alert (Sept 21, Zyxel)

Check Point discloses exploited Security Management zero-day (CVE-2026-93616) and confirms in-the-wild attacks on the VPN certificate flaw (CVE-2026-85102)

Check Point · September 22, 2026

Check Point published sk1000171 and a security blog for CVE-2026-93616 (CVSS 9.8), a pre-authentication directory traversal and file upload bug in the Security Management Server, Multi-Domain Server, Log Server, and SmartEvent that lets an attacker with access to the management web service (TCP/19009) run arbitrary scripts. The company says it was used in a handful of targeted attacks on July 23, 2026. Affected: R82.20, R82.10 JHF Take 44 and below, R82 Take 126 and below, R81.20 Take 166 and below, and end-of-support R81.10 and earlier; fixes are R82.10 Take 45+, R82 Take 127+, R81.20 Take 170+, R81.10 Take 192+, and a hotfix for R82.20. There is no LivePatch for this one. The same advisory reports that CVE-2026-85102 (CVSS 9.8, the improper certificate validation flaw patched September 9) is now seeing exploitation attempts against Spark firewall customers globally, starting around September 12. Both CVEs were added to CISA KEV on September 22.

“CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory.” — Lotem Finkelstein, Check Point

Source: Check Point sk1000171 · Check Point blog · BleepingComputer

F5 patches BIG-IP APM heap overflow exploited for unauthenticated RCE on OAuth authorization servers (CVE-2026-94127)

F5 · September 22, 2026

F5 advisory K000162605 describes CVE-2026-94127, a heap-based buffer overflow (CWE-122) in BIG-IP Access Policy Manager rated 9.8 on CVSS v3.1 and 9.3 on CVSS v4.0. It is reachable only when an APM access policy and OAuth profile are attached to a virtual server with APM acting as an OAuth Authorization Server; client- and resource-server-only deployments are not affected. F5 says the bug has been exploited and shipped engineering hotfixes for 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3, with an iRule mitigation available from F5 Support. Other BIG-IP modules, BIG-IP Next, F5OS, NGINX, and Distributed Cloud are not vulnerable. Added to CISA KEV September 22.

“This vulnerability allows an unauthenticated attacker to perform RCE.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

Arista VeloCloud Orchestrator CVSS 10.0 input-validation flaw actively exploited (CVE-2026-93952)

Arista · September 22, 2026

Arista Security Advisory 0183 covers CVE-2026-93952, an improper input validation bug in on-premises VeloCloud Orchestrator rated 10.0 on CVSS v3.1 (9.5 on v4.0). It affects deployments that use certificate-based Edge-to-Orchestrator authentication; an attacker with network access to the VCO web UI and the public portion of an Edge authentication certificate can reach privileged internal functions without tenant or operator credentials. Affected: 5.2.3.15 and below, 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below. Fixes are available for 5.2.3.16+ and 6.4.2.8+; Arista says patches for the 6.1.x and 7.0.x lines are still pending, and hosted VCO instances have already been patched. The advisory lists file, service, and IP indicators of compromise. Added to CISA KEV September 22.

“This issue was discovered externally and is known to be actively exploited.” — Arista Security Advisory 0183

Source: Arista SA 0183 · BleepingComputer

WordPress 7.1.2 fixes unauthenticated path traversal (CVE-2026-87902); exploitation began within hours

WordPress.org / Patchstack · September 22–23, 2026

WordPress 7.1.2 shipped on September 22 to fix CVE-2026-87902, an unauthenticated path traversal in page template resolution that yields local file inclusion and, on servers with a writable include path or PEAR’s pearcmd available, code execution. WordPress rates it 9.2 on CVSS v4.0 (8.1 on v3.1); it affects every core release from 4.7.0 through 7.1.1, with backports down to 4.7.37. A proof of concept from the reporter is public. Patchstack observed reconnaissance traffic less than five hours after the release and, by September 23, attackers writing PHP files to disk via the flaw. Not in CISA KEV at time of writing.

“That is arbitrary file write with attacker-controlled PHP content, which is code execution.” — Patchstack

Source: WordPress 7.1.2 release · Patchstack · BleepingComputer

Next.js 16.3.6 patches critical RCE in next/og ImageResponse (CVE-2026-94545)

Vercel · September 22, 2026

Vercel published GHSA-vcvr-r3jv-pc5j for CVE-2026-94545, rated Critical (CVSS v4.0 9.5), in the Node.js implementation of ImageResponse from next/og. Improper escaping in SVG output generated by the upstream Satori library can lead to remote code execution when attacker-controlled values land in SVG content, attributes, or styles. Affected: Next.js 16.2.0 through 16.3.5; fixed in 16.3.6 (15.5.26 adds hardening, and the Edge runtime implementation is not affected). No exploitation has been reported and the flaw is not in KEV.

Source: GHSA-vcvr-r3jv-pc5j · Next.js blog · The Hacker News

Public exploit for unpatched Ubuntu kernel AF_UNIX use-after-free enables container-to-host root (CVE-2026-80521)

DepthFirst · September 22, 2026

DepthFirst researcher Zhenpeng Lin published a working container escape exploit for CVE-2026-80521 (CVSS 7.8), a use-after-free in the Linux kernel’s AF_UNIX socket garbage collector introduced in 6.10 and backported to 6.1 and 6.6. Upstream fixed it on August 6 (mainline 7.2, stable 7.1.10), but Ubuntu’s tracker still lists the kernel packages for 26.04 and 24.04 as “Vulnerable, work in progress.” The exploit code is public on GitHub. No in-the-wild exploitation has been reported and the CVE is not in KEV.

“As of today, it is still unpatched in the latest ubuntu 26.04 release.” — DepthFirst

Source: DepthFirst research · The Hacker News

Financially motivated actor uses open-source AI agent frameworks to skim 600,000+ payment cards

Gambit Security · September 22, 2026

Gambit Security’s threat intelligence team documented an ongoing campaign, active since at least July, in which a threat actor runs open-source agent frameworks (Strix, Cairn, Hermes) to attack online retailers autonomously at roughly $25 per target. The report counts more than 600,000 unexpired card records taken from two victims, skimmers on at least 119 sites, and 105 attack projects against 27+ companies in the September 10–15 window alone. No CVE is involved; the agents chain ordinary web application weaknesses.

“Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees.” — Gambit Security

Source: Gambit Security · BleepingComputer

ShinyHunters claims FBI breach via alleged Oracle PeopleSoft zero-day; FBI says it is investigating

Reuters / 404 Media · September 22, 2026

ShinyHunters claims to have breached the FBI through an unpatched Oracle PeopleSoft vulnerability, pivoted into AWS GovCloud infrastructure, and stolen 2–3 TB of data on agents and job applicants; apply.fbijobs.gov was defaced and currently shows a maintenance page. 404 Media verified some phone numbers in a roughly 5,000-record sample. The FBI told Reuters and BleepingComputer it is aware of the claims and investigating. No CVE has been published, Oracle has not commented, and the zero-day claim remains unverified.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” — FBI statement to Reuters

Source: Reuters · 404 Media · The Hacker News

Still developing

Three Linux kernel flaws added to KEV; Red Hat flags known exploits

CISA / Red Hat · September 18–19, 2026

CISA added CVE-2025-39682 (kTLS receive path, CVSS 9.8), CVE-2026-53266 (ebtables SNAT ARP out-of-bounds write, CVSS 8.8), and CVE-2025-39964 (AF_ALG race condition, CVSS 7.8) to KEV on September 18 with a September 21 federal deadline. Red Hat updated its advisories on September 19 to mark all three as having known exploits. Fixed upstream kernels have been available since 2025 for the two older bugs and since June 2026 for CVE-2026-53266.

Source: CISA alert (two) · CISA alert (one) · The Hacker News

Joint advisory: North Korea’s WaterPlum infected 30,000 devices, moved $10.7M in crypto

FBI / Japan NPA / ACSC / BfV · September 18, 2026

A joint advisory from U.S., Japanese, Australian, and German authorities attributes the “Contagious Interview” fake-recruiter campaign to WaterPlum, a unit under North Korea’s 313 General Bureau, and ties it to the DPRK IT-worker scheme. It names the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware families and notes the actors’ use of AI face-swapping in video interviews.

“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.” — Joint cybersecurity advisory

Source: IC3 joint advisory (PDF) · BleepingComputer

ShinyHunters defaces Clop’s leak site, claims theft of onion keys

BleepingComputer · September 19, 2026

ShinyHunters breached and defaced the Clop ransomware gang’s Tor data leak site via what it says is an unauthenticated file upload flaw in Grav CMS, and claims to have taken source code, logs, and the onion service private keys. BleepingComputer confirmed the defacement but not the theft claims. The group frames it as retaliation in a feud dating to Clop’s 2025 Oracle E-Business Suite campaign.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 22–23, 2026).

Primary sources:

xAI Ships Grok 4.7, OpenAI Forms an Independent Math Advisory Group After Its Navier–Stokes Result, Xiaomi Open-Sources MiMo-V2.6 and Alibaba Releases Qwen-Image-2.1

This brief covers the trailing ~72 hours (September 19–22, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. The window was a model-release weekend: xAI shipped Grok 4.7 as its new flagship for coding and knowledge work, Xiaomi open-sourced the trillion-parameter, omnimodal MiMo-V2.6 series, and Alibaba’s Qwen team released Qwen-Image-2.1, a compact unified image generator and editor with native transparency. On the governance side, OpenAI responded to an open letter from mathematicians by standing up an independent Advisory Group on Mathematics and AI to review and communicate results from the internal model that resolved Navier–Stokes earlier this month. Google opened pre-orders for Googlebook, a laptop built around on-device Gemini, and OpenAI expanded OpenAI Academy with role-based learning paths.

xAI releases Grok 4.7, a larger base model with a new safeguard stack, at the same $2/$6 price as Grok 4.6

SpaceXAI · September 21, 2026

Grok 4.7 uses a new, larger base model than Grok 4.6 and was trained with a longer reinforcement-learning run weighted toward tasks that take many hours to complete, with explicit training to understand the Grok Bot harness. xAI reports 46.3% on CursorBench 4.0 (vs. 40.4% for 4.6), 71.0% on DeepSWE v1.1 at high effort, 38.0% on Terminal-Bench 4.0 (up from 20.3%), and a GDPval Elo of 1,695, placing it between Grok 4.6 and Fable 5.1. The company says the model was built with an entirely new safeguard stack, topping LatchBio’s biosafety benchmark at 62.4% and allowing only 3.3% of risky dual-use prompts through on its HackerBench v0.3, while select cybersecurity partners get invite-only access to its red-team capabilities. It is available today in Cursor, Grok Build, and the Grok API at $2 per million input tokens and $6 per million output tokens, with a fast variant at twice the output speed for twice the price.

“It works longer on difficult tasks, checks its own work more carefully, and comes with our best-calibrated safeguards to date.” — SpaceXAI

Source: Introducing Grok 4.7

OpenAI stands up an independent Advisory Group on Mathematics and AI after its internal model resolves 100+ open problems

OpenAI · September 21, 2026

OpenAI disclosed that the internal model it began training on August 28, the same system behind its Navier–Stokes result, has now resolved more than 100 long-standing open problems across most areas of mathematics, at a pace that surprised the company’s own mathematicians. Citing the open letter “A Severe Misalignment of AI in Mathematics,” in which mathematicians objected to solving open problems as a benchmark for new AI systems, OpenAI said it is working with an independent advisory group hosted at the Institute for Advanced Study to assess the significance of emerging results, coordinate their dissemination, and advise on academic standards. Members are unpaid, may publish unsolicited advice, and can change the group’s membership; initial members include Timothy Gowers, Martin Hairer, Edward Witten, Ravi Vakil, Camillo De Lellis, Melanie Matchett Wood, Ulrike Tillmann, Nikhil Srivastava, and François Charles. OpenAI notes the group will not advise on how to pace its internal progress on mathematics.

“The group will operate independently from OpenAI. The group will have the freedom to offer advice we have not requested, comment on OpenAI’s impact on mathematics, and make its advice public.” — OpenAI

Source: Advisory Group on Mathematics and Artificial Intelligence

Xiaomi open-sources MiMo-V2.6: a 1.02T-parameter omnimodal MoE with 1M context, trained in one mixed RL run

Xiaomi MiMo · September 21, 2026

Xiaomi released the MiMo-V2.6 series under an MIT license, led by MiMo-V2.6-Pro-RL, a sparse mixture-of-experts model with 1.02 trillion total and 42 billion active parameters, a 1M-token context window, and native text, image, video, and audio input. The technical approach centers on “You Only RL Once,” a single mixed reinforcement-learning run spanning coding, general agents, vision, and cybersecurity, plus a groupwise agentic grader that ranks passing rollouts against each other to push toward shorter, cheaper solutions. Xiaomi’s own evaluation table puts Pro at 71.9% on DeepSWE v1.1, 76.9% on Toolathlon-Verified, 82.0% on OSWorld-Verified, and 94.0% on CyberGym, generally within a few points of Claude Opus 5 and GPT-5.6 Sol on agentic benchmarks. A smaller Flash model (309B parameters) and an UltraSpeed variant of Pro are served through Xiaomi’s API at $0.435/$0.87 and $0.14/$0.28 per million input/output tokens respectively.

“One mixed RL run across coding, general agents, visual, and cybersecurity — not separate per-domain runs.” — Xiaomi MiMo Team

Source: MiMo-V2.6 (see also the MiMo-V2.6-Pro-RL model card)

Alibaba’s Qwen team releases Qwen-Image-2.1, a 7B unified generator and editor with native transparency

Qwen (Alibaba) · September 20, 2026

Qwen-Image-2.1 unifies text-to-image generation and image editing in a single model with just 7 billion parameters in its visual generation component (a 32-layer single-stream DiT), paired with a Qwen3-VL 8B text encoder and a 64-channel RGBA VAE. It natively generates and edits transparent images, accepts up to 10 reference images for multi-subject composition, supports circle, paint, and mask annotations to target local edits, and renders natively at 2K resolution. A mixed-granularity attention design lets the model encode text and condition images once and reuse the prefix KV cache across all denoising steps. Weights are on Hugging Face and ModelScope under the Qwen Research License, with day-zero support in Diffusers, ComfyUI, vLLM-Omni, SGLang, and LightX2V, and two fine-tuned Qwen3.5-VL 9B prompt-rewriting models released alongside.

“We are excited to open-source Qwen-Image-2.1, a unified text-to-image generation and image editing model in the Qwen family.” — Qwen team

Source: Qwen-Image-2.1 on GitHub (blog: qwen.ai)

Google opens Googlebook pre-orders: a $899 laptop built around on-device Gemini, Magic Pointer, and Antigravity

Google · September 21, 2026

Google detailed the intelligence layer of Googlebook, its new Android-and-ChromeOS-based laptop, which brings Gemini directly onto the device. Magic Pointer summons Gemini with a cursor wiggle to act on whatever is on screen (scheduling a training plan into Calendar, checking whether a hovered email is spam, combining selected images); Rambler turns spoken stream-of-consciousness into structured, multilingual notes; and Create My Widget builds custom widgets from a description. Every Googlebook ships with Google Antigravity and a full Linux terminal for agentic coding tools, and Gemini Spark can keep processing tasks after the lid is closed. Pre-orders start at $899 and include 12 months of Google AI Pro, with devices arriving October 4 in the U.S. and October 5 in Canada, the U.K., Ireland, France, Germany, and Australia.

“Developers also have access to a full Linux terminal environment to run tools like Claude Code or Antigravity CLI and do serious agentic coding right on your Googlebook.” — Alexander Kuscher, Google

Source: Googlebook’s built-in intelligence reinvents the way you use your laptop

OpenAI expands OpenAI Academy with role-based learning paths and course badges

OpenAI · September 21, 2026

OpenAI added new course pathways to OpenAI Academy for developers (Build with AI, eight courses covering Codex and the API, evaluations, agents, and production operation), leaders (an AI Leadership course on strategy, ownership, and roadmaps), and educators and college students (AI for Educators and AI for College Students), joining the existing Apply AI at Work pathway for knowledge workers. Each course ends with an assessment, and learners who pass earn an OpenAI Academy course badge. The company positions the expansion as part of deployment, encouraging organizations to combine pathways for onboarding, technical teams, and executive programs.

“At OpenAI, we treat learning as part of deployment.” — OpenAI

Source: Expanding OpenAI Academy with new learning paths

Still developing

OpenAI publishes an Australian Youth Safety Blueprint (September 18, 2026). Just before this window opened, OpenAI released a six-pillar roadmap for protecting young Australians using AI, spanning AI literacy, age-appropriate safeguards, privacy-protective age assurance, connections to crisis support, and parental controls, and noted that ChatGPT for Teens began rolling out in Australia in August as the default experience for users identified as 13 to 17. Source: Introducing the Australian Youth Safety Blueprint


This brief covers the trailing ~72 hours (September 19–22, 2026).

Primary sources: