The Exploit Bulletin — Wednesday, September 23, 2026: 4 issues require action
Wednesday, September 23, 2026 — 4 issues require action. If you run none of the software below, you are done.
Affects: Quantum Security Management, Multi-Domain Security Management Server, Multi-Domain Log Server, SmartEvent · F5 BIG-IP APM · VeloCloud Orchestrator On-Prem · BigCommerce
1. Pre-auth path traversal to script execution in Check Point Security Management web service (CVE-2026-93616)
CISA KEV (due 2026-09-25) · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.8
Check Point published fixes on 2026-09-22 after Check Point Research identified a handful of targeted exploitations of this zero-day, and CISA added it to KEV with a 2026-09-25 due date, so management servers left at older Jumbo Hotfix takes remain open to unauthenticated takeover.
A path traversal flaw in the Check Point Management web service lets an unauthenticated attacker who can reach the service execute a script from an arbitrary path and load an arbitrary Java class, giving code execution on the Security Management Server, Multi-Domain Server, Log Server, Multi-Domain Log Server or SmartEvent. Compromise of the management server exposes the policy and credentials for every gateway it manages.
Affected: Quantum Security Management R82.20 with no Jumbo Hotfix; Quantum Security Management R82.10 with Jumbo Hotfix Take 44 or below; Quantum Security Management R82 with Jumbo Hotfix Take 126 or below; Quantum Security Management R81.20 with Jumbo Hotfix Take 166 or below; Quantum Security Management R81.10 (EOS) with Jumbo Hotfix Take 190 or below; Quantum Security Management R81, R80.40, R80.30, R80.20, R80.10 (all EOS); Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent on the same versions
How to Test: Check the installed release and Jumbo Hotfix take on each Security Management, Multi-Domain, Log Server and SmartEvent host: R82.20 without any Jumbo Hotfix, R82.10 at Take 44 or below, R82 at Take 126 or below, R81.20 at Take 166 or below, R81.10 at Take 190 or below, and all R81/R80.x releases are vulnerable. Review the management web service's access logs for path traversal sequences and requests loading unexpected scripts or Java classes, look for unfamiliar script or class files on the server, and audit administrator accounts and policy changes; Check Point reports exploitation dating back to July 23, so widen the log window accordingly.
How to Mitigate: Install the Jumbo Hotfix that includes the fix per Check Point sk1000171: a take above 44 on R82.10, above 126 on R82, above 166 on R81.20, above 190 on R81.10, and the first available Jumbo Hotfix on R82.20. Hosts on R81, R80.40, R80.30, R80.20 or R80.10 are end-of-support and must be upgraded to a supported release; until fixed, restrict access to the management web service to trusted administrative networks.
Evidence: CISA KEV · VulnCheck KEV · Vendor confirmed · CISA SSVC: active · BleepingComputer: management server zero-day exploited · The Hacker News: zero-day exploited in targeted attacks
2. Unauthenticated heap overflow RCE in F5 BIG-IP APM OAuth profiles (CVE-2026-94127)
CISA KEV (due 2026-09-25) · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.3
F5 disclosed the flaw on 2026-09-22 as a zero-day already exploited for remote code execution and CISA set a KEV due date of 2026-09-25, so any internet-facing APM OAuth virtual server left unpatched is exposed to full device takeover.
A heap-based buffer overflow in BIG-IP APM is reachable when an access policy and an OAuth profile are configured on a virtual server, letting an unauthenticated network attacker execute code on the BIG-IP system. Only deployments where APM acts as an OAuth authorization server are affected.
Affected: F5 BIG-IP APM 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG; F5 BIG-IP APM 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG; F5 BIG-IP APM 17.1.0 prior to Hotfix-BIGIP-17.1.3.5.0.41.14-ENG
How to Test: Confirm the BIG-IP version is in the 17.1.x, 17.5.x or 21.1.x affected ranges and whether the APM module is provisioned; then inventory virtual servers that have both an access policy and an OAuth profile attached (APM acting as an OAuth authorization server) — those are the vulnerable exposure points. Review APM and system logs around those virtual servers for malformed OAuth requests, unexpected process crashes or restarts, and unknown processes, files or accounts on the BIG-IP, and follow CISA's forensics triage requirements given confirmed exploitation.
How to Patch: Install the F5 engineering hotfix for your branch: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG or Hotfix-BIGIP-17.1.3.5.0.41.14-ENG (F5 article K000162605). If the hotfix cannot be applied immediately, remove the OAuth profile from affected virtual servers or restrict access to them to trusted sources until patched.
Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · Canadian Centre for Cyber Security AL26-022: F5 indicates exploitation in the wild · BleepingComputer: APM zero-day exploited in RCE attacks · The Hacker News: APM zero-day exploited for unauthenticated RCE
3. Unauthenticated access to privileged internal functions in on-prem VeloCloud Orchestrator (CVE-2026-93952)
CISA KEV (due 2026-09-25) · AUTHENTICATION BYPASS · CRITICAL · CVSS 9.5
Arista's advisory of 2026-09-22 confirms the flaw is being actively exploited and CISA added it to KEV the same day with a 2026-09-25 due date, so an unpatched on-prem orchestrator is a live path to compromise of the entire SD-WAN estate.
An improper input validation flaw in on-premises VeloCloud Orchestrator lets a remote attacker with no credentials reach privileged internal functionality and compromise the VCO host and the data it manages for every Edge in the SD-WAN. Arista rates it CVSS 3.1 10.0 with changed scope; hosted and dedicated VCO instances were already patched by Arista.
Affected: VeloCloud Orchestrator (VCO) On-Prem 5.2.0 through 5.2.3.15; VeloCloud Orchestrator (VCO) On-Prem 6.1.0 through 6.1.3.7; VeloCloud Orchestrator (VCO) On-Prem 6.4.0 through 6.4.2.7; VeloCloud Orchestrator (VCO) On-Prem 7.0.0 through 7.0.0.2
How to Test: Check the running VCO on-prem software version against the affected trains (5.2.x ≤ 5.2.3.15, 6.1.x ≤ 6.1.3.7, 6.4.x ≤ 6.4.2.7, 7.0.x ≤ 7.0.0.2); Arista states that a release not on this list is not vulnerable regardless of platform. Hosted/dedicated VCO customers are already patched by Arista. Review orchestrator access logs for unexpected unauthenticated requests to internal/privileged endpoints and audit for new or altered administrator accounts, Edge configurations and API tokens, following CISA's forensics triage guidance since exploitation is confirmed.
How to Patch: Upgrade on-prem VCO to a release newer than the affected ceiling in your train (above 5.2.3.15, 6.1.3.7, 6.4.2.7 or 7.0.0.2) per Arista Security Advisory 0183 (BUG1907167 / BUG1937417). Until upgraded, restrict network access to the orchestrator's management interface to trusted sources only.
Evidence: CISA KEV · VulnCheck KEV · Vendor confirmed · CISA SSVC: active · The Hacker News: VCO flaw actively exploited · Canadian Centre for Cyber Security AV26-947
4. BigCommerce merchants breached through compromised Ribon third-party app credentials
CONFIRMED BREACH · HIGH
BigCommerce has begun notifying merchants this week, and any store that had a Ribon app connected during September 13-17 may still be serving injected skimmer script to checkout pages and still holds live app API credentials that were in the attacker's hands.
Attackers obtained credentials for third-party Ribon applications installed on BigCommerce stores and used them to reach merchant environments and inject malicious scripts into storefronts. BigCommerce confirmed the credential compromise on September 17, removed the apps, and notified affected merchants; access to shopper data occurred between September 13 and September 17, with at least one merchant (Master of Malt) confirming shopper details were accessed.
Affected: BigCommerce stores with Ribon third-party applications connected (access window 2026-09-13 to 2026-09-17)
How to Test: In the BigCommerce control panel, list installed/authorized apps and API accounts and check whether any Ribon app was connected; review store audit logs and API account activity for requests between September 13 and September 17, 2026, and diff theme files, script manager entries and checkout pages for unrecognized JavaScript or external script tags added in that window. Also check for any BigCommerce breach notification e-mail to the store owner address.
How to Mitigate: Uninstall the Ribon apps, revoke and reissue every BigCommerce API account token and OAuth grant the store holds, remove any injected script manager entries or theme code, reset staff/control-panel passwords and enforce MFA, then assess whether shopper records accessed in the window require customer notification.
Evidence: BleepingComputer: BigCommerce confirms Ribon app credential compromise, notifies merchants · SC Media: BigCommerce merchants impacted by third-party app data breach
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].