Thursday, September 24, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Wednesday's disclosures include three CVSS 10.0 vulnerabilities: CVE-2026-69399 in Microsoft Azure Arc, CVE-2026-86708 in Zohocorp ManageEngine Applications Manager, and CVE-2026-59167 in the JiHong88 SunEditor rich text editor. The brief tracks 27 critical CVEs (down 36% from 42 the prior day) and 85 high-priority CVEs (down 11% from 96). Other notable critical issues include CVE-2026-86248 (CVSS 9.8) in Apache Tomcat, CVE-2026-93352 (CVSS 9.8) in the Plank laravel-mediable package, and five separate CVSS 9.8 vulnerabilities in the Orval OpenAPI client generator (CVE-2026-96754 through CVE-2026-96759). The day's exposure spans hybrid cloud management, IT monitoring platforms, web servers, and open-source developer tooling, and 8 CVEs affecting the Linux kernel, F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, and Zyxel switches have confirmed active exploitation. Defenders should restrict network access to management interfaces such as Azure Arc, ManageEngine, BIG-IP, and Check Point management servers, and review the vendor advisory for each affected product to confirm fixed versions.

  • Three CVSS 10.0 vulnerabilities affect Microsoft Azure Arc (CVE-2026-69399), Zohocorp ManageEngine Applications Manager (CVE-2026-86708), and JiHong88 SunEditor (CVE-2026-59167)
  • 27 critical CVEs (CVSS 9.0+), down 36% from 42 the prior day
  • 85 high-priority CVEs (CVSS 7.0-8.9), down 11% from 96 the prior day
  • Open-source developer tooling is heavily represented: five CVSS 9.8 flaws in Orval and one in Plank laravel-mediable call for dependency and build pipeline review
  • Check first: Apache Tomcat deployments (CVE-2026-86248, CVSS 9.8), Azure Arc-connected infrastructure, and ManageEngine Applications Manager instances
  • 8 actively exploited CVEs affect the Linux kernel, F5 BIG-IP, Check Point Quantum Security Management and Gateway, Arista VeloCloud Orchestrator On-Prem, and Zyxel GS1900-48HPv2 switches

Immediate action: Prioritize Microsoft Azure Arc, Zohocorp ManageEngine Applications Manager, and Apache Tomcat, along with the actively exploited F5 BIG-IP, Check Point Quantum, and Linux kernel issues, and restrict exposure of their management interfaces until they are remediated. Confirm fix status and affected versions in each vendor's advisory, and audit projects that depend on Orval, SunEditor, or laravel-mediable for updated package releases.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation