Tuesday, September 15, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

AI orchestration frameworks and enterprise edge infrastructure carried the weight of Tuesday's disclosures, with five separate CVSS 9.8 remote code execution issues in MervinPraison PraisonAI and companion library praisonaiagents alongside platform-level flaws in Apple operating systems and Google Android. The day brought 56 critical CVEs (up 300% from 14 the prior day) and 80 high-priority CVEs (down 22% from 102), for 136 total. Notable entries include CVE-2026-57124 and CVE-2026-57123 (CVSS 9.8) in the PraisonAI stack, CVE-2026-65414 (CVSS 9.8) affecting iOS, iPadOS, macOS, tvOS, visionOS and watchOS, and CVE-2026-90937 (CVSS 9.9) in the froxlor hosting control panel. Unauthenticated remote code execution and authentication bypass dominate the critical set, hitting developer tooling (IBM Langflow OSS, MISP) and internet-facing management interfaces used across hosting, DevOps and security operations. Thirteen CVEs have confirmed active exploitation, including Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center and Secure Email Gateway, Fortinet FortiOS, Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab and JFrog Artifactory; treat management planes on those products as the first isolation and patching priority, restrict administrative access to trusted networks, and confirm fix availability in each vendor's advisory.

  • AI agent frameworks are the standout target: five CVSS 9.8 remote code execution CVEs across MervinPraison PraisonAI and praisonaiagents (CVE-2026-57123, 57124, 57125, 57127, 57131)
  • 56 critical CVEs (CVSS 9.0+), up 300% from 14 the prior day
  • 80 high-priority CVEs (CVSS 7.0-8.9), down 22% from 102 the prior day
  • Remote code execution and authentication bypass dominate, affecting Apple platforms (CVE-2026-65414), Google Android (CVE-2026-28606), IBM Langflow OSS (CVE-2026-12944, CVSS 9.6) and froxlor (CVE-2026-90937, CVSS 9.9)
  • Check first: internet-facing management interfaces on Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Fortinet FortiOS and FortiSwitchManager, Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab and JFrog Artifactory
  • 13 CVEs have confirmed active exploitation in the wild, concentrated in network edge and remote access products

Immediate action: Prioritise the actively exploited edge and management products: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center and Secure Email Gateway, Fortinet FortiOS and FortiSwitchManager, Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab, JFrog Artifactory, plus Microsoft Windows and Google Chrome. Teams running AI agent frameworks should inventory PraisonAI, praisonaiagents and IBM Langflow deployments and remove any exposure to untrusted networks while they assess. Confirm the fix status and required version for each affected product in that vendor's own advisory before scheduling maintenance.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation