CTIPilot

Live threat brief

LIVE updated 23 Sep 07:14 UTC
ACT NOW · CRITICALCVE-2026-94127 · exploited · 4 sources · 23 Sep 04:42Z

F5 confirms exploitation of an unauthenticated RCE in BIG-IP's OAuth authentication gateway

An unauthenticated, network-only attacker can trigger a heap-based buffer overflow in F5 BIG-IP Access Policy Manager's OAuth-profile handling, reaching remote code execution on the TMM data plane. F5 confirms active exploitation; the exposure is limited to virtual servers configured with both an APM access policy and an OAuth profile.

F5 confirms active exploitation of this unauthenticated RCE. Inventory every virtual server that combines an APM access policy with an OAuth profile. Apply the engineering hotfix now (21.1.0.2.0.30.22 / 17.5.1.9.0.160.12 / 17.1.3.5.0.41.14); where the hotfix cannot land immediately, request the emergency iRule mitigation from F5 Support. Prioritise internet-facing instances.

Open the full advisory to act →

Do now8

  • Inventory every BIG-IP APM virtual server pairing an access policy with an OAuth profile, and patch or apply the emergency iRule to each one now.
    FindingCVE-2026-94127
  • Upgrade every on-prem VeloCloud Orchestrator on the 5.2.x or 6.4.x train to 5.2.3.16+ / 6.4.2.8+ now.
    FindingCVE-2026-93952
  • On the unpatched 6.1.x/7.0.x trains, restrict VCO web-interface access to trusted administrative networks now; no fix exists yet.
    FindingCVE-2026-93952
  • Apply the R82.20 Security Hotfix or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Management / Multi-Domain Security Management / Log / Multi-Domain Log / SmartEvent server now; no LivePatch exists for this issue.
    FindingCVE-2026-93616
  • Until patched, restrict TCP/19009 to trusted administrative IP ranges via Trusted Clients / implied rules on every affected server.
    FindingCVE-2026-93616
  • Apply LivePatch Take 24 or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Gateway, Management Server and Spark Firewall now; if the offline LivePatch package was used on R82.10 JHF Take 24 or lower / R82 JHF Take 107 or lower / R81.20 JHF Take 146 or lower, also install the hardened Take 26; no workaround exists for Remote Access VPN or the locally-managed Spark Firewall short of patching.
    FindingCVE-2026-85103 +1
  • Review Mobile Access logs for anomalous certificate-based logins and any follow-on internal port/service scanning from suspicious Mobile Access sessions on every Spark Firewall, whether or not it has already been patched.
    FindingCVE-2026-85103 +1
  • Patch every self-managed Virtualizor installation to 3.2.9 patch 9 or 3.3.0 now, and keep admin-panel ports 4084/4085 off the public internet or behind an allowlist regardless of patch level.
    FindingCVE-2026-43641 +2
9findings
4critical
2high
4exploited
1updated
Categories5 vulnerability2 policy2 threat

22.09.2026 07:1423.09.2026 07:14 UTC · last 24h

Latest findings

Criticality
Kind
Topic
Region
23 Sep 07:14Z· run · 9 findings
23 Sep04:52ZNEW

Virtualizor VPS/hypervisor control panel: a login-page guard's own exemption for act=login lets an unauthenticated attacker reach root

Softaculous Virtualizor's admin panel guards every pre-authentication request except one: a request with act=login walks straight into an unauthenticated billing-module handler. From there, an attacker reaches unauthenticated root command execution, PHP object injection, or arbitrary tenant-balance manipulation. Fixed in 3.2.9 patch 9 / 3.3.0; VulnCheck's disclosure does not state whether it observed in-the-wild exploitation, and built a fully automated internal exploit module (using its own open-source go-exploit framework, not published for this CVE) that requires no credentials or account information from the operator.

vulnerability23 Sep 04:52Zsingle-sourceopen ↗
Sources: VulnCheck
23 Sep04:50ZNEW
HIGHNATOB2

Open-source AI pentesting harnesses (Strix, Cairn, Hermes) run an autonomous intrusion-and-skimmer campaign against online retailers for about $25 a target

Gambit Security reconstructs a financially motivated campaign, running since July 2026, in which three open-source AI agent harnesses, Strix (vulnerability discovery), Cairn (autonomous exploitation) and Hermes (orchestration), ran nearly the entire intrusion lifecycle unattended against online retailers, compromising at least 27 named victims and confirming live checkout-page skimmers on 19 of them, plus 100+ further sites found via a shared skimmer signature. Hermes is the same AI-agent framework observed in three prior, unrelated intrusions, two of them against government targets with contested attribution.

threat23 Sep 04:50Zsingle-sourceopen ↗
23 Sep04:45ZNEW
ROUTINENATOA2

NCSC Switzerland: Google recovery-address abuse plus a Sites-hosted phishing page plants an OAuth app-password backdoor that survives a password reset

Switzerland's national cybersecurity authority documents a fraud chain where attackers register a victim's address as their own Google account's recovery address, then use a genuine Google security notification as a vishing hook to steer the victim to a Google Sites-hosted phishing page. Once inside the real account, attackers provision an app password, a legacy credential that bypasses MFA and survives a subsequent password change.

threat23 Sep 04:45Zsingle-source · national CERTopen ↗
23 Sep04:44ZNEW
NOTABLENATOA1

Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026

Austria's NIS2-transposition law (NISG 2026) enters into force on 1 October 2026, creating the Bundesamt für Cybersicherheit (BCS) as the supervisory authority for essential/important entities, with a graduated 24h/72h incident-reporting clock, mandatory management security training, and new powers for the BCS to run active vulnerability scans against covered entities' internet-facing systems, obstruction becomes a criminal offence.

policy23 Sep 04:44Zmulti-sourceopen ↗
23 Sep04:43ZNEW
NOTABLENATOA1

EU Court of Auditors: cyber-incident cooperation framework only partially effective, cross-border notification failed for the 2025 airport ransomware disruption

The European Court of Auditors' Special Report 19/2026 finds the EU's cybersecurity-incident cooperation framework only partially effective: NIS2 transposition is two years behind schedule in most member states, national-security law lets states withhold incident information, and Germany, Belgium and Ireland never formally notified ENISA of the September 2025 Collins Aerospace ransomware attack that disrupted four major European airports.

policy23 Sep 04:43Zmulti-sourceopen ↗
23 Sep04:42ZNEW
CRITICALCVE-2026-94127exploitedNATOA1

CVE-2026-94127, F5 BIG-IP APM: unauthenticated heap overflow in OAuth-profile processing reaches RCE on the TMM data plane (CVSS 9.8)

An unauthenticated, network-only attacker can trigger a heap-based buffer overflow in F5 BIG-IP Access Policy Manager's OAuth-profile handling, reaching remote code execution on the TMM data plane. F5 confirms active exploitation; the exposure is limited to virtual servers configured with both an APM access policy and an OAuth profile.

vulnerability23 Sep 04:42Zmulti-sourceopen ↗
23 Sep04:41ZNEW
CRITICALCVE-2026-93952exploitedNATOA1

CVE-2026-93952, Arista VeloCloud Orchestrator: actively exploited, two release trains still have no fix

Arista's on-premises VeloCloud Orchestrator (CVSS 10.0/9.5) is under active exploitation via a flaw reachable from the VCO web interface on deployments using certificate-based Edge authentication, requiring no VCO credentials. Fixes exist only for the 5.2 and 6.4 trains; 6.1.x and 7.0.x remain unpatched as of 2026-09-22, the same trains Arista already reported exploited via a separate flaw in July 2026.

vulnerability23 Sep 04:41Zmulti-sourceopen ↗
23 Sep04:40ZNEW
CRITICALCVE-2026-93616exploitedNATOA1

CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day since July (CVSS 9.8)

An unauthenticated attacker can upload and execute an arbitrary script on Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent via a directory-traversal and file-upload flaw. Check Point identified pinpointed exploitation on 2026-07-23, roughly two months before the 2026-09-22 fix; no LivePatch exists, only a hotfix or Jumbo Hotfix Accumulator.

vulnerability23 Sep 04:40Zmulti-sourceopen ↗
23 Sep04:37ZUPD
CRITICALCVE-2026-85103 +1exploitedupdatedNATOA2

Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)

Update · CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on 2026-09-22, and Check Point's own advisory confirms a wave of exploitation attempts against Spark Firewall customers globally beginning 2026-09-12, three days after the fix shipped, using certificate-based Mobile Access logins from anonymization infrastructure. A September 14 advisory update also reveals a coverage gap in the original fix affecting offline LivePatch installs on specific older hotfix baselines, closed by a second, hardened LivePatch (Take 26) issued two days after exploitation began. Exploitation status moves from unexploited to confirmed exploited; priority moves from high to critical. CVE-2026-85103 is unaffected and remains not confirmed exploited. (first published 2026-09-10)

vulnerability10 Sep 04:45Zmulti-sourceopen ↗

Explore the knowledge base

Machine-readable: briefbook.json · search.json · RSS feeds · STIX 2.1 · llms.txt · every entry's raw source at entries/<date>/<slug>/index.md

Continuous cyber threat intelligence

Read the signal, not the noise.

CTIPilot is continuous cyber threat intelligence for Swiss government entities: national, cantonal and communal administrations, emergency services, police and armed forces. Published the hour it is verified; source-linked, IOC-free, autonomously generated by an LLM.

Everything verified or updated in the last 24 hours, held to a constant relevance bar. An update or correction to an earlier finding floats it back to the top under the run that made it. How this works →