CyberWatch Newsletter

Five security items a day: vulnerabilities actually being exploited first, from the CISA KEV catalogue, then high-severity CVEs in widely deployed software.

CyberWatch Newsletter -- 2026-09-22

5 items out of 611 considered, known-exploited first, then severity and reach (cap 5).

Selection: 5 known-exploited (in the CISA KEV catalogue, attacks are happening now). Each item says which under "Why this is here".

1. KNOWN EXPLOITED -- CVE-2025-39682

KNOWN EXPLOITED CRITICAL CVSS 9.8 published 2025-09-05

KNOWN EXPLOITED. CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity.

What happened: A critical flaw in the Linux kernel TLS implementation mishandles zero-length records on the receive list, potentially causing processing errors during recvmsg calls. The issue arises when an initial record from the receive list is zero length, bypassing expected type checks and loop breaks.

Who is affected: Users running the Linux kernel with TLS enabled are affected, including systems using Debian Linux and Siemens SIMATIC CN 4100 firmware.

How serious: This vulnerability is rated Critical with a CVSS score of 9.8, indicating it can lead to complete compromise of confidentiality, integrity, and availability.

What to do: Apply the kernel updates provided in the linked stable git commits to resolve the TLS record handling defect. Ensure your distribution or firmware vendor has released the patched version for your specific environment.

Why this is here: Known exploited -- CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach 100/100 via "linux kernel".

2. KNOWN EXPLOITED -- CVE-2026-76460

KNOWN EXPLOITED CRITICAL CVSS 10.0 published 2026-09-16

KNOWN EXPLOITED. CISA lists this as known-exploited in Cisco Identity Services Engine on 2026-09-16, so it is being used against people now -- that outranks severity.

What happened: A critical vulnerability in the Cisco Identity Services Engine API allows unauthenticated remote attackers to bypass authentication controls. This flaw enables unauthorized access to the device by sending crafted requests to the affected API endpoint.

Who is affected: Organizations running Cisco Identity Services Engine Software or the Cisco ISE Passive Identity Connector are at risk.

How serious: The issue is rated Critical with a perfect CVSS score of 10.0, indicating full compromise of confidentiality, integrity, and availability.

What to do: Administrators should review the official Cisco Security Advisory and apply the necessary patches or mitigations immediately.

Why this is here: Known exploited -- CISA lists this as known-exploited in Cisco Identity Services Engine on 2026-09-16, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 10.0); reach 60/100 via "cisco".

3. KNOWN EXPLOITED -- CVE-2026-94127

KNOWN EXPLOITED CRITICAL CVSS 9.3 published 2026-09-22

KNOWN EXPLOITED. CISA lists this as known-exploited in F5 BIG-IP APM on 2026-09-22, so it is being used against people now -- that outranks severity.

What happened: A vulnerability in F5 BIG-IP allows unauthenticated remote code execution when specific malicious traffic targets a virtual server configured with both an APM access policy and an OAuth profile.

Who is affected: Administrators running F5 BIG-IP systems, particularly those in Appliance mode, with the specified access policy and OAuth profile configuration.

How serious: The issue is rated Critical with a CVSS score of 9.3, enabling full remote code execution by unauthenticated attackers without control plane exposure.

What to do: Review the official F5 support article K000162605 for mitigation steps and ensure your systems are updated or configured securely.

Why this is here: Known exploited -- CISA lists this as known-exploited in F5 BIG-IP APM on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.3); reach 56/100 via "big ip".

4. KNOWN EXPLOITED -- CVE-2026-93616

KNOWN EXPLOITED CRITICAL CVSS 9.8 published 2026-09-22

KNOWN EXPLOITED. CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity.

What happened: An unauthenticated attacker can exploit a directory traversal and file upload vulnerability to upload and execute arbitrary scripts on the Check Point Management Server.

Who is affected: Administrators running Check Point Quantum Security Management are at risk of remote code execution.

How serious: The vulnerability is rated Critical with a CVSS score of 9.8, allowing full system compromise without authentication.

What to do: Review the official Check Point security advisory and support article for immediate mitigation steps and patch information.

Why this is here: Known exploited -- CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach unrated (no entry in the reach table).

5. KNOWN EXPLOITED -- CVE-2026-85102

KNOWN EXPLOITED CRITICAL CVSS 9.8 published 2026-09-09

KNOWN EXPLOITED. CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity.

What happened: An improper certificate trust validation flaw in Check Point Quantum Security Gateway allows unauthenticated remote attackers to execute arbitrary code during VPN negotiation.

Who is affected: Administrators and organizations using Check Point Quantum Security Gateway devices.

How serious: The vulnerability is rated Critical with a CVSS score of 9.8, indicating a high risk of complete system compromise.

What to do: Review the official Check Point security advisory and support article for details on applying the necessary patches or mitigations.

Why this is here: Known exploited -- CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach unrated (no entry in the reach table).

Summaries: 5/5 written by a local LLM. Source: NVD CVE 2.0 API.