Daily Brief

WordPress under active attack — patch Core before Friday

WordPress under active attack — patch Core before Friday

Attackers went from probing to writing PHP in under a day. Verify you’re on a fixed release....

Tomcat WebSocket lock can be walked around — check yours this week

Tomcat WebSocket lock can be walked around — check yours this week

If auth sits in a Tomcat security constraint, an alternate endpoint name can skip it....

Palo Alto says HIGHEST urgency — root risk on PA-Series firewalls

Palo Alto says HIGHEST urgency — root risk on PA-Series firewalls

No known exploit yet — that’s the window, not a reason to wait....

SAP’s CVSS 10 kernel bug now has public PoCs — patch Internet-facing first

SAP’s CVSS 10 kernel bug now has public PoCs — patch Internet-facing first

Shared kernel, pre-auth, PoCs out. Role checks won’t save you....

Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

WordPress under active exploitation, Tomcat WebSocket bypass, Palo Alto HIGHEST urgency, SAP OVERPASS with public PoCs....

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

CISA added two Check Point CVSS 9.8s to KEV yesterday. Federal due September 25 — patch gateways and management Jumbo…

F5 BIG-IP APM CVE-2026-94127: Unauth Heap Overflow RCE on APM+OAuth VIPs — KEV Due September 25

F5 BIG-IP APM CVE-2026-94127: Unauth Heap Overflow RCE on APM+OAuth VIPs — KEV Due September 25

Unauth data-plane RCE when a VIP has both APM and an OAuth profile. Hotfixes and interim iRule out; federal due…

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

In-the-wild V8 write; Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is today — verify Edge and other Chromium browsers too....

The 5-Minute Cyber Brief: September 23, 2026

The 5-Minute Cyber Brief: September 23, 2026

Check Point VPN+mgmt KEV due Friday, F5 APM OAuth RCE, Arista VeloCloud CVSS 10, Chromium V8 due today....

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

CISA added the GS1900 CGI stack overflow to KEV yesterday. Federal due September 24 — patch, lock management VLANs, triage....

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Two CVSS 9.8 unauth deserialization bugs on the ITSM brain. On-prem needs September updates or 2026.2+....

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Four more local-root bugs disclosed September 18 — different from Monday’s KEV trio. Confirm your kernel covers all four....