Sam's News โ security โ 2026-09-23¶
Security¶
8.5 F5 patches critical BIG-IP zero-day vulnerability in OAuth servers¶
F5 released patches on September 22, 2026 for CVE-2026-94127, a critical zero-day vulnerability (CVSS 9.8/10) in BIG-IP Access Policy Manager allowing unauthenticated remote code execution via heap-based buffer overflow. CISA added the flaw to its Known Exploited Vulnerabilities catalog.
- CVE-2026-94127 rated 9.8/10 CVSS v3.1, 9.3/10 CVSS v4.0
- Affects BIG-IP 21.1.0, 17.5.0โ17.5.1, 17.1.0โ17.1.3 when APM functions as OAuth server
- CISA issued directive: federal agencies must patch by September 25
- Limiting management interface access does not prevent exploitation
Sources: The Hacker News AI Web Searched, BleepingComputer RSS, SecurityWeek RSS
8.5 ShinyHunters Claims FBI Data Breach¶
The cyber extortion group ShinyHunters claimed responsibility for breaching the FBI and stealing sensitive data on agents and job applicants.
- Claimed September 22, 2026
- Stole data on nearly all FBI agents and job applicants
- Breached Oracle PeopleSoft HR server, then Amazon government cloud
- Obtained terabytes of data including agent home addresses and spouse phone numbers
- Poses counterintelligence threat; second known FBI system breach in 2026
Sources: The Hacker News RSS Update to: Hacking Group ShinyHunters Claims FBI Data Breach, Steals Employee and Applicant Information
8 Critical Next.js ImageResponse Vulnerability Enables Server Code Execution via SVG Injection¶
A critical vulnerability in Next.js ImageResponse (CVE-2026-94545, CVSS 9.5) allows remote code execution when untrusted data is embedded in SVG input on Node.js runtime. Vercel patched the flaw on September 22, 2026 in version 16.3.6.
- CVE-2026-94545 rated 9.5 CVSS severity
- Affects Next.js versions 16.2.0โ16.3.5 on Node.js runtime
- Edge version and Next.js 15 not affected
- Fixed September 22 in version 16.3.6
- Flaw stems from improper escaping in Satori's SVG output
Sources: The Hacker News AI Web Searched
7.5 Arista Networks urges immediate patching of exploited VCO zero-day¶
Arista Networks released urgent patches for CVE-2026-93952, a critical-severity zero-day (CVSS 10.0) in VeloCloud Orchestrator (VCO) on-premises that is actively being exploited. The vulnerability allows unauthenticated remote access to privileged internal functions.
- CVE-2026-93952 rated 10.0 CVSS severity
- Affects VeloCloud Orchestrator On-Prem (formerly Broadcom product)
- Patches released for versions 5.2.3.16 and 6.4.2.8
- Added to CISA Known Exploited Vulnerabilities September 24; federal agencies have 3 days to patch
- Requires network access to VCO web interface and access to VeloCloud Edge certificate
Sources: SecurityWeek AI Web Searched
7.5 Chinese hackers exploit Chrome-Windows zero-day chain to deploy CLEANGULP malware¶
A Chinese threat actor known as UTA0565 has exploited a Chrome-Windows zero-day vulnerability chain to deliver CLEANGULP malware through fraudulent websites.
Sources: The Hacker News RSS
7.5 Check Point Patches Critical Unauthenticated Code Execution Flaw¶
Check Point released a patch for a critical-severity zero-day in its management server that allowed unauthenticated attackers to upload and execute arbitrary scripts.
- CVE-2026-93616, CVSS 9.8
- Path traversal in web service enables unauthenticated script execution
- Actively exploited July 23, 2026; patch released September 22, 2026
- Affects R82.20 through R80 versions (R80โR81.10 end of support)
- Also disclosed separate VPN flaw CVE-2026-85102 under active exploitation
Sources: SecurityWeek RSS Update to: Check Point Security Management Server Zero-Day Actively Exploited
7.5 FBI investigating ShinyHunters claims of employee data theft¶
The FBI is investigating claims by ShinyHunters that they have stolen employee data from the agency.
Sources: securityboulevard.com Web Search
6.5 ENISA 2026 threat landscape report highlights ransomware, AI-enabled attacks across EU¶
The European cybersecurity agency ENISA identified ransomware, vulnerability exploitation, and AI-powered attacks as primary threats to European organizations.
Sources: Industrial Cyber RSS
6.5 Outerlimit launches AI agent safety platform with $16 million pre-seed funding¶
Outerlimit emerged from stealth with $16 million in funding for a decentralized authorization layer to monitor and prevent harmful autonomous AI actions.
Sources: SecurityWeek RSS
6 Ryuk ransomware operator sentenced to 24 months in prison¶
An Armenian national was sentenced to 24 months in prison and three years supervised release for participating in Ryuk ransomware attacks against U.S. companies.
Sources: BleepingComputer RSS