Why Should I Care? โ 2026-09-23 | ๐ด 5 HIGH ยท ๐ก 3 MEDIUM ยท ๐ต 27 RADAR ยท โช 69 FILTERED
๐ Briefing โ 2026-09-23
35 vendor intel items scanned | ๐ด 5 HIGH | ๐ก 3 MEDIUM | ๐ต 27 RADAR | โช 69 FILTERED
๐ด Critical โ action required:
- CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities are actively exploited and pose significant risks.
- Siemens SIPLUS and SIMATIC Products (CVE-2026-31431) โ Yes, if you run any version of SIMATIC AX Runtime Core Linux Common Debian, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC AX Runtime Core Linux VMWare Development, or SIMATIC CN 4100 below version 6.0: you are vulnerable to the 'Copy Fail' vulnerability.
- lwIP TCP/IP Stack MQTT Client Application (CVE-2026-87121) โ Yes, if you run MQTT Client Application versions >=2.0.1 and <=2.2.1: an attacker could gain full code execution on your device.
- Siemens Siveillance Control (CVE-2026-50093) โ Yes, if you run Siveillance Control or Siveillance Control Pro versions below 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, or 4.0.11.2177: An attacker can upload files to gain root access, fully compromising your system.
- Siemens Industrial Edge Management (CVE-2026-18963) โ Yes, if you run Siemens Industrial Edge Management Cloud, Pro V1 >= 1.14.9 < 1.15.20, Pro V2 >= 2.2.0 < 2.2.2, or Virtual >= 2.6.0 < 2.9.1: An attacker can reset user credentials and take over accounts without email verification.
Everything else can wait.
๐ก Medium โ review when time permits:
- Siemens Desigo CC family โ Yes, if you run Siemens Desigo CC family V6 or V7: this vulnerability allows attackers to execute arbitrary code on your client devices through specially crafted graphics documents.
- lwIP (Lightweight IP) โ Yes, if you run lwIP API versions >=2.0.1 and <=2.2.1: this vulnerability could crash your system, cause a DoS, or allow an attacker to execute arbitrary code.
- OpenPLC Runtime v3 โ Yes, if you run OpenPLC Runtime v3: this vulnerability allows attackers to hijack session cookies and control the PLC, impacting critical infrastructure.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127
โ Why Should I Care?
Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities are actively exploited and pose significant risks.
๐ฏ Affected versions: Check Point Multiple Products: all versions; Arista VeloCloud Orchestrator: all versions; F5 BIG-IP APM: all versions
๐ญ In plain English:
These vulnerabilities allow attackers to either bypass security checks, access sensitive files, or crash systems. For example, an attacker could exploit the Check Point vulnerability to bypass security checks and gain unauthorized access to your network.
๐ง Prerequisites:
- Running an affected version of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM
โฑ Urgency: High urgency due to active exploitation and significant risk to the federal enterprise.
๐ก Context: The root cause involves improper validation and handling of input or certificates, allowing attackers to exploit these vulnerabilities.
Siemens SIPLUS and SIMATIC Products
CISA Advisories [CISA KEV] | CVE-2026-31431
โ Why Should I Care?
Yes, if you run any version of SIMATIC AX Runtime Core Linux Common Debian, SIMATIC AX Runtime Core Linux Common Debian arm64, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development, SIMATIC AX Runtime Core Linux VMWare Development, or SIMATIC CN 4100 below version 6.0: you are vulnerable to the 'Copy Fail' vulnerability.
๐ฏ Affected versions: SIMATIC AX Runtime Core Linux Common Debian vers:all/*, SIMATIC AX Runtime Core Linux Common Debian arm64 vers:all/*, SIMATIC AX Runtime Core Linux Platform Container Common Debian Development vers:all/*, SIMATIC AX Runtime Core Linux VMWare Development vers:all/*, SIMATIC CN 4100 vers:intdot/<6.0
๐ญ In plain English:
The 'Copy Fail' vulnerability means that an attacker could potentially copy sensitive data from your system without your knowledge. For example, an attacker could copy configuration files or other sensitive data from your SIMATIC devices, which could then be used to further compromise your system or steal sensitive information.
๐ง Prerequisites:
- The attacker must have network access to the affected SIMATIC devices.
โฑ Urgency: High urgency due to the potential for sensitive data exfiltration.
โ Fixed in: 6.0 and above for SIMATIC CN 4100
๐ก Context: The root cause is a flaw in the data handling mechanisms that allows for unauthorized data copying.
lwIP TCP/IP Stack MQTT Client Application
CISA Advisories | CVSS 9.8 | CVE-2026-87121
โ Why Should I Care?
Yes, if you run MQTT Client Application versions >=2.0.1 and <=2.2.1: an attacker could gain full code execution on your device.
๐ฏ Affected versions: >=2.0.1 and <=2.2.1
๐ญ In plain English:
This vulnerability allows an attacker to write data outside the intended memory area, potentially giving them full control over your device. For example, an attacker could remotely execute malicious code, take over your device, and perform actions like stealing data or disrupting operations.
๐ง Prerequisites:
- Running MQTT Client Application versions >=2.0.1 and <=2.2.1
โฑ Urgency: High urgency due to the critical nature of the vulnerability and the potential for full code execution.
โ Fixed in: f89407ea711879c04d91c92b35d67be78bbaf0f1
๐ก Context: The root cause is an out-of-bounds write vulnerability in the lwIP TCP/IP Stack MQTT Client Application.
Siemens Siveillance Control
CISA Advisories | CVSS 9 | CVE-2026-50093
โ Why Should I Care?
Yes, if you run Siveillance Control or Siveillance Control Pro versions below 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, or 4.0.11.2177: An attacker can upload files to gain root access, fully compromising your system.
๐ฏ Affected versions: Siveillance Control Pro V3.0 < V3.0.12.2173, Siveillance Control Pro V4.0 < V4.0.9.2178, Siveillance Control V3.0 < V3.0.22.2177, Siveillance Control V4.0 < V4.0.11.2177
๐ญ In plain English:
This vulnerability lets attackers upload any file they want to your server, which can give them full control over your system. For example, an attacker could upload a malicious script that allows them to take over your entire server and steal sensitive data.
๐ง Prerequisites:
- Access to the OIS web module
- Versions below the patched versions
โฑ Urgency: High urgency due to the potential for full system compromise and unauthorized access.
โ Fixed in: 3.0.12.2173, 4.0.9.2178, 3.0.22.2177, 4.0.11.2177
๐ก Context: The root cause is an unrestricted file upload feature that does not properly validate the type or content of uploaded files.
Siemens Industrial Edge Management
CISA Advisories | CVSS 9.1 | CVE-2026-18963
โ Why Should I Care?
Yes, if you run Siemens Industrial Edge Management Cloud, Pro V1 >= 1.14.9 < 1.15.20, Pro V2 >= 2.2.0 < 2.2.2, or Virtual >= 2.6.0 < 2.9.1: An attacker can reset user credentials and take over accounts without email verification.
๐ฏ Affected versions: Industrial Edge Management Cloud: all, Pro V1: >= 1.14.9 < 1.15.20, Pro V2: >= 2.2.0 < 2.2.2, Virtual: >= 2.6.0 < 2.9.1
๐ญ In plain English:
This vulnerability means an attacker can reset user passwords and take over accounts without needing to verify via email. For example, an attacker could log in as an admin and change critical settings or steal sensitive data.
๐ง Prerequisites:
- Unauthenticated access to the system
- Access to the password reset functionality
โฑ Urgency: High urgency due to the risk of full account takeover by unauthenticated attackers.
โ Fixed in: 1.15.20, 2.2.2, 2.9.1
๐ก Context: The root cause is a flaw in the reset-credentials flow of the keycloak-services component, allowing bypass of email verification.
Why Should I Care? ๐ก MEDIUM (3)
Siemens Desigo CC family
CISA Advisories | CVSS 8.2 | CVE-2026-34223
โ Why Should I Care?
Yes, if you run Siemens Desigo CC family V6 or V7: this vulnerability allows attackers to execute arbitrary code on your client devices through specially crafted graphics documents.
๐ฏ Affected versions: Desigo CC family V6 vers:all/*, Desigo CC family V7 vers:all/*
๐ญ In plain English:
This vulnerability means that if you open a specially crafted graphics document, an attacker can run any code they want on your computer, potentially taking control of it. For example, an attacker could use this to install malware or gain access to other parts of your network.
๐ง Prerequisites:
- User must open a maliciously crafted graphics document
- User must have sufficient privileges to display the document
โฑ Urgency: High urgency due to the potential for full client system compromise and lateral movement within the network.
๐ก Context: The root cause is insufficient input validation when handling scripts embedded within user-defined graphics documents.
lwIP (Lightweight IP)
CISA Advisories | CVSS 8.8 | CVE-2026-91018
โ Why Should I Care?
Yes, if you run lwIP API versions >=2.0.1 and <=2.2.1: this vulnerability could crash your system, cause a DoS, or allow an attacker to execute arbitrary code.
๐ฏ Affected versions: API >=2.0.1 and <=2.2.1
๐ญ In plain English:
This vulnerability allows an attacker to crash your system, make it unresponsive, or take control of it. For example, an attacker could send a specially crafted packet to your system, causing it to crash or allowing them to run any code they want.
๐ง Prerequisites:
- Running affected lwIP versions
- Network access to the system
โฑ Urgency: High urgency due to the potential for remote code execution and system crashes.
โ Fixed in: f873b6295933e4149a2132adf3e9a2d2a676a5ec
๐ก Context: The root cause is a double free vulnerability in lwIP, where memory is freed twice, leading to undefined behavior.
OpenPLC Runtime v3
CISA Advisories | CVSS 6.1 | CVE-2026-88020
โ Why Should I Care?
Yes, if you run OpenPLC Runtime v3: this vulnerability allows attackers to hijack session cookies and control the PLC, impacting critical infrastructure.
๐ฏ Affected versions: OpenPLC 3
๐ญ In plain English:
This vulnerability means an attacker could steal your session cookies and pretend to be you, allowing them to control the PLC and the processes it manages. For example, they could change the settings of a manufacturing plant's machinery, potentially causing malfunctions or safety issues.
๐ง Prerequisites:
- Access to the web interface
- No proper input validation
โฑ Urgency: High urgency due to the potential for attackers to control critical infrastructure processes.
โ Fixed in: OpenPLC v4
๐ก Context: The root cause is improper neutralization of input during web page generation, leading to cross-site scripting.
Why Should I Care? ๐ต On the Radar (27)
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks (The Hacker News) โ A critical flaw in Check Point's Security Management Server and Spark firewalls allowed attackers to run scripts without logging in. This could compromise your network security. Check Point has released a fix, but you need to apply it immediately.
- Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access (The Hacker News) โ There are active attacks exploiting vulnerabilities in Zyxel GS1900 series switches and Veeam Agent for Windows, allowing attackers to execute commands and gain SYSTEM-level access. This can lead to data exfiltration and control of your infrastructure.
- Chinese hackers exploit WordPress, Zyxel flaws to steal govt data (BleepingComputer) โ Chinese hackers have exploited vulnerabilities in WordPress and ZyXEL switches to steal sensitive data from government and business networks. This means that if your organization uses these technologies, your data could be at risk.
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates (The Hacker News) โ A new tool called BigDiskBuster can prevent Microsoft Defender from updating by filling up your disk space. This means your security software won't get the latest updates to protect against new threats.
- Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials (The Hacker News) โ A critical flaw in Bifrost AI gateway lets attackers run commands on your server without needing any credentials. This can lead to unauthorized access to your API keys and sensitive data.
- Check Point warns of Management Server zero-day exploited in attacks (BleepingComputer) โ A critical vulnerability in Check Point's Security Management Server allows attackers to execute arbitrary scripts, potentially giving them full control over your security infrastructure. This is a high-priority issue because it can be exploited to gain unauthorized access and control over your network security systems.
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach (BleepingComputer) โ A hacking group called ShinyHunters claims to have breached FBI systems using a new, unpatched vulnerability in Oracle PeopleSoft, stealing sensitive data. This could affect any organization using PeopleSoft.
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE (The Hacker News) โ A flaw in SharePoint Server versions 2016, 2019, and Subscription Edition allows attackers who can authenticate to execute arbitrary code on the server. This could lead to full control over the server, which is a serious security risk.
- New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory (The Hacker News) โ A new Linux kernel flaw allows guest virtual machines to access and modify host memory, potentially leading to a full escape from the guest environment. This affects ARM64 systems with nested virtualization enabled.
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups (The Hacker News) โ A critical flaw in VeloCloud Orchestrator allows attackers to access and control the orchestrator and its managed Edge devices if certificate-based authentication is used. This can lead to full compromise of your SD-WAN infrastructure.
- D-Link warns of max severity zero-day bug in DIR-822A routers (BleepingComputer) โ D-Link has identified a critical vulnerability in DIR-822A routers that could allow attackers to execute code remotely. This could lead to device compromise and potential inclusion in botnets for DDoS attacks.
- CISA orders feds to patch Zyxel flaw exploited for data theft (BleepingComputer) โ A critical flaw in Zyxel GS1900 switches is being actively exploited by attackers to steal data. Zyxel has released a patch, but it's urgent to apply it to avoid unauthorized access and data theft.
- New Windows Defender zero-day blocks Microsoft antivirus updates (BleepingComputer) โ A security researcher has released a new exploit called BigDiskBuster that can prevent Windows Defender from updating, leaving your systems stuck with outdated antivirus definitions. This means your systems could be at higher risk of malware attacks.
- WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session (The Hacker News) โ A recent flaw in WordPress allows attackers to inject malicious scripts through comments, which can then be activated when an admin views the page, leading to full server control. This affects all versions from 4.7 to 7.1.
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor (The Hacker News) โ A security flaw in Meta's Muse AI assistant for Mac allows malware to redirect voice commands to an attacker, potentially giving them access to your files, emails, and more. This is a significant risk for anyone using Muse on a Mac.
โช 69 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV