CVE Digest — September 22, 2026
12 CVE
4 KEV
Critical
Digest for September 22, 2026: 4 new entries in the CISA KEV catalog and 8 advisories from ACN, the Italian cybersecurity agency. KEV entries are known to be exploited in the wild: patch the affected products as soon as possible.
ACN advisories (Italy)
- F5 BIG-IP: rilevato sfruttamento in rete della CVE-2026-94127
- CheckPoint: rilevato sfruttamento in rete della CVE-2026-93616
- Risolte vulnerabilità in MISP
- Risolte vulnerabilità in Apache Airflow
- Nextcloud: PoC pubblica per lo sfruttamento della CVE-2026-77165
- Risolta vulnerabilità in Conda
- Telegram Desktop: PoC pubblica per lo sfruttamento della CVE-2026-94488
- Risolte tre vulnerabilità in ntop
| CVE | Product | CVSS | Severity | Summary | References |
|---|---|---|---|---|---|
| CVE-2026-93952 KEV | Arista VeloCloud Orchestrator | 10 | Critical | Critical CVSS 10.0 vulnerability in Arista VeloCloud Orchestrator (VCO) on-prem. Improper input validation (CWE-20) lets a remote unauthenticated attacker reach privileged internal functionality, compromising confidentiality, integrity, and availability of the orchestrator and i… CWE-20 | |
| CVE-2026-94127 KEV | F5 BIG-IP APM | 9.8 | Critical | Critical CVSS 9.8 heap-based buffer overflow (CWE-122) in F5 BIG-IP APM. When an access policy and OAuth profile are configured on a virtual server, malicious traffic allows unauthenticated remote code execution. Only affects deployments where APM is an OAuth Authorization Serve… CWE-122 | |
| CVE-2026-93616 KEV | Check Point Multiple Products | 9.8 | Critical | Critical CVSS 9.8 path traversal and file upload vulnerability (CWE-22) in Check Point Security Management Server, Multi-Domain Security Management Server, Log Servers, and SmartEvent. An unauthenticated attacker can upload and execute arbitrary scripts on the management server.… CWE-22 | |
| CVE-2026-85102 KEV | Check Point Multiple Products | 9.8 | Critical | Critical CVSS 9.8 improper certificate validation vulnerability (CWE-295) in Check Point Security Gateway and Spark Firewall using Site-to-Site or Remote Access VPN. An unauthenticated remote attacker can execute arbitrary code on the gateway. Added to CISA KEV on 2026-09-22; ap… CWE-295 | |
| CVE-2026-94127 | – | 9.8 | Critical | ACN advisory (2026-09-22): in-the-wild exploitation detected of CVE-2026-94127 in F5 BIG-IP APM. Exploitation could allow remote attackers to execute arbitrary code on affected systems. Critical, CVSS 9.8, heap-based buffer overflow (CWE-122) when APM is configured as an OAuth A… | |
| CVE-2026-93616 | – | 9.8 | Critical | ACN advisory (2026-09-22): in-the-wild exploitation detected of CVE-2026-93616 in Check Point Management Server. The vulnerability could allow remote attackers to execute arbitrary code on affected systems. Critical, CVSS 9.8: path traversal and file upload (CWE-22) enabling una… | |
| risolte-vulnerabilita-in-misp-1 | – | – | High | ACN advisory (2026-09-22): MISP security updates fix multiple vulnerabilities, including six rated high severity, in the open-source collaborative threat-intelligence platform. Exploitation could allow remote attackers to elevate privileges, execute arbitrary code, access sensit… | |
| risolte-vulnerabilita-in-apache-airflow-2 | – | – | Critical | ACN advisory (2026-09-22): security updates fix three vulnerabilities, one rated critical, in Apache Airflow. Exploitation could allow an attacker to bypass security features on affected systems. | |
| CVE-2026-77165 | – | – | Unknown | ACN advisory (2026-09-22): a public Proof of Concept (PoC) is available for CVE-2026-77165 in Nextcloud Server, the open-source cloud storage platform. The flaw (CWE-284) prevents file owners from unlocking TYPE_TOKEN locks placed by other users, leaving files permanently locked… | |
| risolta-vulnerabilita-in-conda | – | – | High | ACN advisory (2026-09-22): security updates fix a high-severity vulnerability in Conda, the open-source platform for managing Python environments and packages. Exploitation via specially crafted packages could allow an attacker to write files to unintended locations or overwrite… | |
| CVE-2026-94488 | – | 8.2 | High | ACN advisory (2026-09-22): a public Proof of Concept (PoC) is available for CVE-2026-94488, already patched by the vendor, in Telegram Desktop. The flaw is an XSS (CWE-79) in the HTML exporter, fixed in 6.9.4; exploitation could let a remote attacker bypass security mechanisms o… | |
| risolte-tre-vulnerabilita-in-ntop | – | – | High | ACN advisory (2026-09-22): three high-severity vulnerabilities fixed in ntop, the network traffic analysis and monitoring product. Exploitation could allow an attacker to access sensitive information, bypass security features, execute arbitrary code, or modify data/code on affec… |
Disclaimer
This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.