Tuesday, September 22, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Apache Software Foundation products and Google Chrome account for the highest-impact disclosures, with remote code execution and authentication bypass flaws in widely deployed middleware and browser components. The day brought 32 critical CVEs (up 113% from 15 the prior day) and 109 high-priority CVEs (up 51% from 72), for 141 total. Named critical entries include CVE-2026-94301 (CVSS 9.8) in Apache MINA, CVE-2026-86473 (CVSS 9.1) in Apache Airflow, CVE-2026-89422 (CVSS 9.3) in Erlang OTP, and two Google Chrome flaws at CVSS 9.6 (CVE-2026-91710 and CVE-2026-93372). WordPress plugin vulnerabilities again make up a large share of the high-priority set, alongside container and observability tooling such as Fluent Bit (CVE-2026-61674, CVSS 9.2) and remote access gateways like warpgate (CVE-2026-58491, CVSS 9.3); seven CVEs carry confirmed active exploitation, including Cisco Identity Services Engine and Acronis Backup. Prioritise internet-facing network access control, backup infrastructure, and browser fleets, verify fix status in each vendor advisory, and restrict management interfaces on Apache middleware and remote access gateways until updates are confirmed applied.

  • Apache Software Foundation products lead the day: Apache MINA (CVE-2026-94301, CVSS 9.8) and Apache Airflow (CVE-2026-86473, CVSS 9.1)
  • 32 critical CVEs (CVSS 9.0+), up 113% from 15 the prior day
  • 109 high-priority CVEs (CVSS 7.0-8.9), up 51% from 72 the prior day
  • Remote code execution and authentication bypass dominate, affecting Apache MINA, Erlang OTP (CVE-2026-89422, CVSS 9.3), Fluent Bit (CVE-2026-61674, CVSS 9.2), and warpgate (CVE-2026-58491, CVSS 9.3)
  • Check first: Google Chrome deployments (CVE-2026-91710 and CVE-2026-93372, both CVSS 9.6), Mailu mail servers (CVE-2026-85751, CVSS 9.8), and WordPress sites running Give Tributes or Web to Print Online Designer
  • Seven CVEs have confirmed active exploitation, spanning Cisco Identity Services Engine, Acronis Backup, Google Pixel, Zyxel GS1900-48HPv2, and the Linux kernel

Immediate action: Patch Cisco Identity Services Engine, Acronis Backup, and Zyxel GS1900-48HPv2 devices first given confirmed exploitation, then move to Apache MINA and Apache Airflow deployments and Chrome browser fleets. Confirm the fixed version and fix status for each affected product in the vendor's own advisory before scheduling maintenance windows, and restrict network access to Airflow web interfaces and warpgate gateways until updates are in place.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation