Live threat brief
F5 confirms exploitation of an unauthenticated RCE in BIG-IP's OAuth authentication gateway
An unauthenticated, network-only attacker can trigger a heap-based buffer overflow in F5 BIG-IP Access Policy Manager's OAuth-profile handling, reaching remote code execution on the TMM data plane. F5 confirms active exploitation; the exposure is limited to virtual servers configured with both an APM access policy and an OAuth profile.
F5 confirms active exploitation of this unauthenticated RCE. Inventory every virtual server that combines an APM access policy with an OAuth profile. Apply the engineering hotfix now (21.1.0.2.0.30.22 / 17.5.1.9.0.160.12 / 17.1.3.5.0.41.14); where the hotfix cannot land immediately, request the emergency iRule mitigation from F5 Support. Prioritise internet-facing instances.
Open the full advisory to act →Do now8
- Inventory every BIG-IP APM virtual server pairing an access policy with an OAuth profile, and patch or apply the emergency iRule to each one now.FindingCVE-2026-94127
- Upgrade every on-prem VeloCloud Orchestrator on the 5.2.x or 6.4.x train to 5.2.3.16+ / 6.4.2.8+ now.FindingCVE-2026-93952
- On the unpatched 6.1.x/7.0.x trains, restrict VCO web-interface access to trusted administrative networks now; no fix exists yet.FindingCVE-2026-93952
- Apply the R82.20 Security Hotfix or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Management / Multi-Domain Security Management / Log / Multi-Domain Log / SmartEvent server now; no LivePatch exists for this issue.FindingCVE-2026-93616
- Until patched, restrict TCP/19009 to trusted administrative IP ranges via Trusted Clients / implied rules on every affected server.FindingCVE-2026-93616
- Apply LivePatch Take 24 or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Gateway, Management Server and Spark Firewall now; if the offline LivePatch package was used on R82.10 JHF Take 24 or lower / R82 JHF Take 107 or lower / R81.20 JHF Take 146 or lower, also install the hardened Take 26; no workaround exists for Remote Access VPN or the locally-managed Spark Firewall short of patching.FindingCVE-2026-85103 +1
- Review Mobile Access logs for anomalous certificate-based logins and any follow-on internal port/service scanning from suspicious Mobile Access sessions on every Spark Firewall, whether or not it has already been patched.FindingCVE-2026-85103 +1
- Patch every self-managed Virtualizor installation to 3.2.9 patch 9 or 3.3.0 now, and keep admin-panel ports 4084/4085 off the public internet or behind an allowlist regardless of patch level.FindingCVE-2026-43641 +2
22.09.2026 07:14 → 23.09.2026 07:14 UTC · last 24h
Latest findings
Virtualizor VPS/hypervisor control panel: a login-page guard's own exemption for act=login lets an unauthenticated attacker reach root
Softaculous Virtualizor's admin panel guards every pre-authentication request except one: a request with act=login walks straight into an unauthenticated billing-module handler. From there, an attacker reaches unauthenticated root command execution, PHP object injection, or arbitrary tenant-balance manipulation. Fixed in 3.2.9 patch 9 / 3.3.0; VulnCheck's disclosure does not state whether it observed in-the-wild exploitation, and built a fully automated internal exploit module (using its own open-source go-exploit framework, not published for this CVE) that requires no credentials or account information from the operator.
Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target
Gambit Security reconstructs a financially motivated campaign, running since July 2026, in which three open-source AI agent harnesses, Strix (vulnerability discovery), Cairn (autonomous exploitation) and Hermes (orchestration), ran nearly the entire intrusion lifecycle unattended against online retailers, compromising at least 27 named victims and confirming live checkout-page skimmers on 19 of them, plus 100+ further sites found via a shared skimmer signature. Hermes is the same AI-agent framework observed in three prior, unrelated intrusions, two of them against government targets with contested attribution.
NCSC Switzerland: Google recovery-address abuse plus a Sites-hosted phishing page plants an OAuth app-password backdoor that survives a password reset
Switzerland's national cybersecurity authority documents a fraud chain where attackers register a victim's address as their own Google account's recovery address, then use a genuine Google security notification as a vishing hook to steer the victim to a Google Sites-hosted phishing page. Once inside the real account, attackers provision an app password, a legacy credential that bypasses MFA and survives a subsequent password change.
Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026
Austria's NIS2-transposition law (NISG 2026) enters into force on 1 October 2026, creating the Bundesamt für Cybersicherheit (BCS) as the supervisory authority for essential/important entities, with a graduated 24h/72h incident-reporting clock, mandatory management security training, and new powers for the BCS to run active vulnerability scans against covered entities' internet-facing systems, obstruction becomes a criminal offence.
EU Court of Auditors: cyber-incident cooperation framework only partially effective, cross-border notification failed for the 2025 airport ransomware disruption
The European Court of Auditors' Special Report 19/2026 finds the EU's cybersecurity-incident cooperation framework only partially effective: NIS2 transposition is two years behind schedule in most member states, national-security law lets states withhold incident information, and Germany, Belgium and Ireland never formally notified ENISA of the September 2025 Collins Aerospace ransomware attack that disrupted four major European airports.
CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)
An unauthenticated, network-only attacker can trigger a heap-based buffer overflow in F5 BIG-IP Access Policy Manager's OAuth-profile handling, reaching remote code execution on the TMM data plane. F5 confirms active exploitation; the exposure is limited to virtual servers configured with both an APM access policy and an OAuth profile.
CVE-2026-93952, Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix
Arista's on-premises VeloCloud Orchestrator (CVSS 10.0/9.5) is under active exploitation via a flaw reachable from the VCO web interface on deployments using certificate-based Edge authentication, requiring no VCO credentials. Fixes exist only for the 5.2 and 6.4 trains; 6.1.x and 7.0.x remain unpatched as of 2026-09-22, the same trains Arista already reported exploited via a separate flaw in July 2026.
CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day since July (CVSS 9.8)
An unauthenticated attacker can upload and execute an arbitrary script on Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent via a directory-traversal and file-upload flaw. Check Point identified pinpointed exploitation on 2026-07-23, roughly two months before the 2026-09-22 fix; no LivePatch exists, only a hotfix or Jumbo Hotfix Accumulator.
Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)
Update · CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on 2026-09-22, and Check Point's own advisory confirms a wave of exploitation attempts against Spark Firewall customers globally beginning 2026-09-12, three days after the fix shipped, using certificate-based Mobile Access logins from anonymization infrastructure. A September 14 advisory update also reveals a coverage gap in the original fix affecting offline LivePatch installs on specific older hotfix baselines, closed by a second, hardened LivePatch (Take 26) issued two days after exploitation began. Exploitation status moves from unexploited to confirmed exploited; priority moves from high to critical. CVE-2026-85103 is unaffected and remains not confirmed exploited. (first published 2026-09-10)
Explore the knowledge base
Machine-readable: briefbook.json · search.json · RSS feeds · STIX 2.1 · llms.txt · every entry's raw source at entries/<date>/<slug>/index.md
Read the signal, not the noise.
CTIPilot is continuous cyber threat intelligence for Swiss government entities: national, cantonal and communal administrations, emergency services, police and armed forces. Published the hour it is verified; source-linked, IOC-free, autonomously generated by an LLM.
Everything verified or updated in the last 24 hours, held to a constant relevance bar. An update or correction to an earlier finding floats it back to the top under the run that made it. How this works →