Wednesday, September 23, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Adobe accounted for most of yesterday's top-scoring disclosures, with several CVSS 9.9 to 10.0 vulnerabilities in Adobe Campaign Classic, Adobe Connect, and AEM 6.5 Forms JEE, alongside maximum-severity flaws in Lantronix console servers and RTI Connext Professional. Yesterday's disclosures included 42 critical CVEs (up 31% from 32 the prior day) and 96 high-priority CVEs (down 12% from 109). Notable critical entries include CVE-2026-75745 (CVSS 10) in Adobe AEM 6.5 Forms JEE, CVE-2026-80155 (CVSS 10) affecting Lantronix SLC8000 and EMG-series devices, and CVE-2026-7866 (CVSS 10) in RTI Connext Professional. The set spans enterprise marketing and collaboration platforms, out-of-band management hardware, and industrial and embedded middleware, and 8 vulnerabilities have confirmed active exploitation, including issues in F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, and the Linux kernel. Defenders should first restrict network access to Adobe Campaign Classic and AEM Forms servers, isolate Lantronix management interfaces from untrusted networks, and verify fix status with each vendor before scheduling remediation.

  • Adobe Campaign Classic is affected by at least six critical vulnerabilities rated CVSS 9.9 to 10.0, with further critical issues in AEM 6.5 Forms JEE and Adobe Connect
  • 42 critical CVEs (CVSS 9.0+) were disclosed, up 31% from 32 the prior day
  • 96 high-priority CVEs (CVSS 7.0-8.9) were disclosed, down 12% from 109 the prior day
  • Maximum-severity flaws reach out-of-band management and middleware: Lantronix SLC8000/EMG console servers (CVE-2026-80155) and RTI Connext Professional (CVE-2026-7866)
  • Check network edge and management systems first: F5 BIG-IP, Check Point Quantum Security Gateway and Management, Arista VeloCloud Orchestrator On-Prem, and Zyxel GS1900 switches
  • 8 vulnerabilities have confirmed active exploitation, including three Linux kernel issues and flaws in F5 BIG-IP (CVE-2026-94127) and Check Point Quantum (CVE-2026-85102, CVE-2026-93616)

Immediate action: Put Adobe Campaign Classic, AEM 6.5 Forms JEE, and Adobe Connect deployments first in line, then network edge and management systems with confirmed exploitation: F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, Zyxel GS1900 switches, and Linux kernel hosts. Check each vendor's advisory to confirm fix status and affected versions. Until updates are applied, keep Lantronix console servers and other management interfaces off untrusted networks.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation