Skip to content

Sam's News โ€” security โ€” 2026-09-23

Security

8.5 F5 patches critical BIG-IP zero-day vulnerability in OAuth servers

F5 released patches on September 22, 2026 for CVE-2026-94127, a critical zero-day vulnerability (CVSS 9.8/10) in BIG-IP Access Policy Manager allowing unauthenticated remote code execution via heap-based buffer overflow. CISA added the flaw to its Known Exploited Vulnerabilities catalog.

  • CVE-2026-94127 rated 9.8/10 CVSS v3.1, 9.3/10 CVSS v4.0
  • Affects BIG-IP 21.1.0, 17.5.0โ€“17.5.1, 17.1.0โ€“17.1.3 when APM functions as OAuth server
  • CISA issued directive: federal agencies must patch by September 25
  • Limiting management interface access does not prevent exploitation

Sources: The Hacker News AI Web Searched, BleepingComputer RSS, SecurityWeek RSS

8.5 ShinyHunters Claims FBI Data Breach

The cyber extortion group ShinyHunters claimed responsibility for breaching the FBI and stealing sensitive data on agents and job applicants.

  • Claimed September 22, 2026
  • Stole data on nearly all FBI agents and job applicants
  • Breached Oracle PeopleSoft HR server, then Amazon government cloud
  • Obtained terabytes of data including agent home addresses and spouse phone numbers
  • Poses counterintelligence threat; second known FBI system breach in 2026

Sources: The Hacker News RSS Update to: Hacking Group ShinyHunters Claims FBI Data Breach, Steals Employee and Applicant Information

8 Critical Next.js ImageResponse Vulnerability Enables Server Code Execution via SVG Injection

A critical vulnerability in Next.js ImageResponse (CVE-2026-94545, CVSS 9.5) allows remote code execution when untrusted data is embedded in SVG input on Node.js runtime. Vercel patched the flaw on September 22, 2026 in version 16.3.6.

  • CVE-2026-94545 rated 9.5 CVSS severity
  • Affects Next.js versions 16.2.0โ€“16.3.5 on Node.js runtime
  • Edge version and Next.js 15 not affected
  • Fixed September 22 in version 16.3.6
  • Flaw stems from improper escaping in Satori's SVG output

Sources: The Hacker News AI Web Searched

7.5 Arista Networks urges immediate patching of exploited VCO zero-day

Arista Networks released urgent patches for CVE-2026-93952, a critical-severity zero-day (CVSS 10.0) in VeloCloud Orchestrator (VCO) on-premises that is actively being exploited. The vulnerability allows unauthenticated remote access to privileged internal functions.

  • CVE-2026-93952 rated 10.0 CVSS severity
  • Affects VeloCloud Orchestrator On-Prem (formerly Broadcom product)
  • Patches released for versions 5.2.3.16 and 6.4.2.8
  • Added to CISA Known Exploited Vulnerabilities September 24; federal agencies have 3 days to patch
  • Requires network access to VCO web interface and access to VeloCloud Edge certificate

Sources: SecurityWeek AI Web Searched

7.5 Chinese hackers exploit Chrome-Windows zero-day chain to deploy CLEANGULP malware

A Chinese threat actor known as UTA0565 has exploited a Chrome-Windows zero-day vulnerability chain to deliver CLEANGULP malware through fraudulent websites.

Sources: The Hacker News RSS

7.5 Check Point Patches Critical Unauthenticated Code Execution Flaw

Check Point released a patch for a critical-severity zero-day in its management server that allowed unauthenticated attackers to upload and execute arbitrary scripts.

  • CVE-2026-93616, CVSS 9.8
  • Path traversal in web service enables unauthenticated script execution
  • Actively exploited July 23, 2026; patch released September 22, 2026
  • Affects R82.20 through R80 versions (R80โ€“R81.10 end of support)
  • Also disclosed separate VPN flaw CVE-2026-85102 under active exploitation

Sources: SecurityWeek RSS Update to: Check Point Security Management Server Zero-Day Actively Exploited

7.5 FBI investigating ShinyHunters claims of employee data theft

The FBI is investigating claims by ShinyHunters that they have stolen employee data from the agency.

Sources: securityboulevard.com Web Search

6.5 ENISA 2026 threat landscape report highlights ransomware, AI-enabled attacks across EU

The European cybersecurity agency ENISA identified ransomware, vulnerability exploitation, and AI-powered attacks as primary threats to European organizations.

Sources: Industrial Cyber RSS

6.5 Outerlimit launches AI agent safety platform with $16 million pre-seed funding

Outerlimit emerged from stealth with $16 million in funding for a decentralized authorization layer to monitor and prevent harmful autonomous AI actions.

Sources: SecurityWeek RSS

6 Ryuk ransomware operator sentenced to 24 months in prison

An Armenian national was sentenced to 24 months in prison and three years supervised release for participating in Ryuk ransomware attacks against U.S. companies.

Sources: BleepingComputer RSS