Vulnerabilities

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

CISA added two Check Point CVSS 9.8s to KEV yesterday. Federal due September 25 — patch gateways and management Jumbo…

F5 BIG-IP APM CVE-2026-94127: Unauth Heap Overflow RCE on APM+OAuth VIPs — KEV Due September 25

F5 BIG-IP APM CVE-2026-94127: Unauth Heap Overflow RCE on APM+OAuth VIPs — KEV Due September 25

Unauth data-plane RCE when a VIP has both APM and an OAuth profile. Hotfixes and interim iRule out; federal due…

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

In-the-wild V8 write; Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is today — verify Edge and other Chromium browsers too....

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

CISA added the GS1900 CGI stack overflow to KEV yesterday. Federal due September 24 — patch, lock management VLANs, triage....

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Two CVSS 9.8 unauth deserialization bugs on the ITSM brain. On-prem needs September updates or 2026.2+....

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Four more local-root bugs disclosed September 18 — different from Monday’s KEV trio. Confirm your kernel covers all four....

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Link-following Update Stack EoP to SYSTEM — federal due today. Verify September cumulatives actually landed....

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

CISA's three exploited Linux kernel bugs are due today. Patch, reboot, then triage....

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Pre-auth INLINE scripts escape GraalVM. Fortinet is blocking thousands of attempts — upgrade to 3.30.2+....

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

Hard-coded static key yields unauthenticated RCE on ARM ≤2026.2. Ship 2026.2.1....

Best Vulnerability Management Tools in 2026: What Security Teams Should Compare

Best Vulnerability Management Tools in 2026: What Security Teams Should Compare

A practical buyer guide to the best vulnerability management tools in 2026, including what to compare, which workflows matter most,…

Why is Cybersecurity Important in 2026?

Why is Cybersecurity Important in 2026?

Why is cybersecurity important? We analyze the primary dynamics that are driving the importance of cybersecurity for businesses and individuals.