Five security items a day: vulnerabilities actually being exploited first, from the CISA KEV catalogue, then high-severity CVEs in widely deployed software.
CyberWatch Newsletter -- 2026-09-24
5 items out of 608 considered, known-exploited first, then severity and reach (cap 5).
Selection: 5 known-exploited (in the CISA KEV catalogue, attacks are happening now). Each item says which under "Why this is here".
KNOWN EXPLOITEDCRITICALCVSS 9.8published 2025-09-05
KNOWN EXPLOITED. CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity.
What happened: A critical vulnerability in the Linux kernel TLS implementation mishandles zero-length records on the receive list, potentially leading to data corruption or denial of service. The issue arises when the initial record is zero-length and processed from the receive list, bypassing expected type-checking logic.
Who is affected: Users running the Linux kernel with TLS enabled are affected, including systems using Debian Linux and Siemens SIMATIC CN 4100 firmware.
How serious: This is a critical vulnerability with a CVSS score of 9.8, allowing remote attackers to achieve full confidentiality, integrity, and availability impact without authentication.
What to do: Apply the stable kernel patches linked in the references to resolve the TLS record handling issue. Ensure your distribution provides the updated kernel packages to mitigate this risk.
Why this is here: Known exploited -- CISA lists this as known-exploited in Linux Kernel on 2026-09-18, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach 100/100 via "linux kernel".
KNOWN EXPLOITEDCRITICALCVSS 9.3published 2026-09-22
KNOWN EXPLOITED. CISA lists this as known-exploited in F5 BIG-IP APM on 2026-09-22, so it is being used against people now -- that outranks severity.
What happened: A vulnerability in F5 BIG-IP APM allows unauthenticated remote code execution when the system is configured as an OAuth Authorization Server. The flaw exists in the data plane and does not expose the control plane.
Who is affected: Organizations running F5 BIG-IP with APM configured specifically as an OAuth Authorization Server are affected. Deployments using APM strictly as an OAuth Client or Resource Server without authorization server profiles are not impacted.
How serious: The issue is rated Critical with a CVSS score of 9.3, allowing an unauthenticated attacker to execute arbitrary code on the target system.
What to do: Review your BIG-IP configuration to determine if the OAuth Authorization Server profile is active. Apply the relevant patch or mitigation provided by F5 for the affected software versions.
Why this is here: Known exploited -- CISA lists this as known-exploited in F5 BIG-IP APM on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.3); reach 56/100 via "big-ip".
KNOWN EXPLOITEDCRITICALCVSS 9.8published 2026-09-22
KNOWN EXPLOITED. CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity.
What happened: An unauthenticated attacker can exploit a directory traversal and file upload vulnerability to upload and execute arbitrary scripts on the Check Point Management Server.
Who is affected: Users of Check Point Quantum Security Management, Check Point multi-domain security management, and Check Point quantum security management are at risk.
How serious: The vulnerability is rated Critical with a CVSS score of 9.8, indicating high potential for complete system compromise.
What to do: Administrators should consult the Check Point support article and security advisory to apply necessary patches and secure their management servers immediately.
Why this is here: Known exploited -- CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach unrated (no entry in the reach table).
KNOWN EXPLOITEDCRITICALCVSS 9.8published 2026-09-09
KNOWN EXPLOITED. CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity.
What happened: A critical vulnerability in Check Point Quantum Security Gateway allows unauthenticated remote attackers to execute arbitrary code due to improper certificate trust validation during VPN negotiation.
Who is affected: Organizations using Check Point Quantum Security Gateway, Check Point Gaia Embedded, or Check Point Gaia OS are at risk.
How serious: The issue is rated Critical with a CVSS score of 9.8, indicating high potential for complete system compromise.
What to do: Administrators should consult the official Check Point support advisory and apply available patches immediately to mitigate active exploitation.
Why this is here: Known exploited -- CISA lists this as known-exploited in Check Point Multiple Products on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.8); reach unrated (no entry in the reach table).
KNOWN EXPLOITEDCRITICALCVSS 9.5published 2026-09-22
KNOWN EXPLOITED. CISA lists this as known-exploited in Arista VeloCloud Orchestrator on 2026-09-22, so it is being used against people now -- that outranks severity.
What happened: A vulnerability in VeloCloud Orchestrator on-prem allows remote attackers to access privileged internal functionality and impact the host. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and its managed data.
Who is affected: Users running Arista Networks VeloCloud Orchestrator on-prem are affected, including hosted and dedicated versions.
How serious: The issue is rated Critical with a CVSS score of 9.5, indicating severe potential impact on system security and data.
What to do: Check if your environment uses Arista VeloCloud Orchestrator on-prem and apply the available patch immediately.
Why this is here: Known exploited -- CISA lists this as known-exploited in Arista VeloCloud Orchestrator on 2026-09-22, so it is being used against people now -- that outranks severity. CRITICAL (CVSS 9.5); reach unrated (no entry in the reach table).
Summaries: 5/5 written by a local LLM.Source: NVD CVE 2.0 API.