Critical vulnerabilities discovered in infrastructure software

Between 2026-09-22 and 2026-09-24, multiple remote code execution vulnerabilities were disclosed in Android Telecom (CVE-2026-49881), Check Point Management (CVE-2026-93616), Check Point VPN (CVE-2026-85102), ManageEngine OpManager (CVE-2026-19599), GitLab (CVE-2026-89078), and Luxion KeyShot (CVE-2026-92202). Several are actively exploited in the wild.

14 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

A critical Android Telecom vulnerability (CVE-2026-49881) allows remote code execution. Read the analysis and learn how to secure your device today. # Android # CVE202649881 # Cybersecurity # Infosec

mastodon:infosec-exchangeother7d ago kagi ↗

A critical Android Telecom vulnerability (CVE-2026-49881) allows remote code execution. Read the analysis and learn how to secure your device today. # Android # CVE202649881 # Cybersecurity # Infosec # ZeroDay https:// securityonline.info/android-te lecom-vulnerability-cve-2026-49881/?utm_source=mastodon&utm_medium=jetpack_social

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now. # CheckPoint # CVE202693616 # Cybersecurity # InfoSec

mastodon:infosec-exchangeother7d ago kagi ↗

A critical exploited Check Point Management vulnerability (CVE-2026-93616) allows attackers to execute arbitrary scripts. Secure your servers now. # CheckPoint # CVE202693616 # Cybersecurity # InfoSec # Vulnerability # RCE https:// securityonline.info/exploited- cve-2026-93616-checkpoint-scripts/?utm_source=mastodon&utm_medium=jetpack_social

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks. # CheckPoint # CVE202685102 # VPN # Cybersecu

mastodon:infosec-exchangeother7d ago kagi ↗

An exploited Check Point VPN vulnerability allows remote code execution. Patch this Check Point VPN vulnerability now to block active in-the-wild attacks. # CheckPoint # CVE202685102 # VPN # Cybersecurity # Infosec # ZeroDay https:// securityonline.info/checkpoint -vpn-vulnerability-cve-2026-85102/?utm_source=mastodon&utm_medium=jetpack_social

A critical ManageEngine ADSelfService Plus vulnerability (CVE-2026-74849) allows system compromise. Update to build 7001 to secure your endpoints. # ManageEngine # ADSelfServicePlus # CVE202674849 # C

mastodon:infosec-exchangeother7d ago kagi ↗

A critical ManageEngine ADSelfService Plus vulnerability (CVE-2026-74849) allows system compromise. Update to build 7001 to secure your endpoints. # ManageEngine # ADSelfServicePlus # CVE202674849 # Cybersecurity # Infosec # RCE https:// securityonline.info/manageengi ne-adselfservice-plus-vulnerability-cve-2026-74849/?utm_source=mastodon&utm_medium=jetpack_social

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes. # F5 # BIGIP # CVE202694127 # Cybersecurity #

mastodon:infosec-exchangeother7d ago kagi ↗

An exploited BIG-IP APM vulnerability tracked as CVE-2026-94127 allows RCE attacks. Secure your BIG-IP APM vulnerability deployments with new F5 hotfixes. # F5 # BIGIP # CVE202694127 # Cybersecurity # InfoSec # RCE # Vulnerability https:// securityonline.info/big-ip-apm -vulnerability-cve-2026-94127/?utm_source=mastodon&utm_medium=jetpack_social

Technical details and a PoC for the D-Link DAP-1360 vulnerability (CVE-2026-95675) are public. Learn how this unauthenticated flaw impacts legacy routers. # DLink # DAP1360 # CVE202695675 # RCE # Rout

mastodon:infosec-exchangeother6d ago kagi ↗

Technical details and a PoC for the D-Link DAP-1360 vulnerability (CVE-2026-95675) are public. Learn how this unauthenticated flaw impacts legacy routers. # DLink # DAP1360 # CVE202695675 # RCE # RouterSecurity # Cybersecurity https:// securityonline.info/d-link-dap -1360-vulnerability-poc/?utm_source=mastodon&utm_medium=jetpack_social

SolarWinds Observability vulnerabilities allow RCE via CVE-2026-28324. Update to version 2026.2.3 to secure your monitoring infrastructure today. # SolarWinds # Cybersecurity # CVE202628324 # CVE20262

mastodon:infosec-exchangeother6d ago kagi ↗

SolarWinds Observability vulnerabilities allow RCE via CVE-2026-28324. Update to version 2026.2.3 to secure your monitoring infrastructure today. # SolarWinds # Cybersecurity # CVE202628324 # CVE202628325 # RCE # Infosec https:// securityonline.info/solarwinds -observability-vulnerabilities-fixed/?utm_source=mastodon&utm_medium=jetpack_social

Critical HPE ALE vulnerabilities threaten enterprise networks. Update HPE ALE vulnerabilities now to prevent unauthorized access and remote code execution. # HPENetworking # ALE # Cybersecurity # Info

mastodon:infosec-exchangeother6d ago kagi ↗

Critical HPE ALE vulnerabilities threaten enterprise networks. Update HPE ALE vulnerabilities now to prevent unauthorized access and remote code execution. # HPENetworking # ALE # Cybersecurity # InfoSec # Vulnerability # CVE202676708 https:// securityonline.info/hpe-ale-vu lnerabilities-patch/?utm_source=mastodon&utm_medium=jetpack_social

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps. # Nextjs # CVE202694545 # RCE # Cybersecurity # WebSecurity

mastodon:infosec-exchangeother6d ago kagi ↗

Vercel fixed a critical Next.js RCE vulnerability in image generation. Update to patch this Next.js RCE vulnerability and secure your apps. # Nextjs # CVE202694545 # RCE # Cybersecurity # WebSecurity # Vulnerability https:// securityonline.info/nextjs-rce -vulnerability-cve-2026-94545/?utm_source=mastodon&utm_medium=jetpack_social

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today. # WordPress # CVE202693485 # StoredXSS # RCE # Cybersecurit

mastodon:infosec-exchangeother6d ago kagi ↗

Details and PoC exploit code for a critical WordPress stored XSS are public. Learn how CVE-2026-93485 enables RCE and patch WordPress today. # WordPress # CVE202693485 # StoredXSS # RCE # Cybersecurity # Infosec https:// securityonline.info/wordpress- stored-xss-poc/?utm_source=mastodon&utm_medium=jetpack_social

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally. # DLink # RouterSecurity # CVE # CyberSecuri

mastodon:infosec-exchangeother6d ago kagi ↗

Discover the critical CVE-2026-86296 vulnerability in D-Link DIR-822A routers. Learn how this DHCP flaw allows attackers to execute arbitrary code locally. # DLink # RouterSecurity # CVE # CyberSecurity # TechNews https:// meterpreter.org/dlink-dir-822a -router-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network. # ManageEngine # Cybersecurity # CVE2026

mastodon:infosec-exchangeother6d ago kagi ↗

ManageEngine security vulnerabilities expose servers to remote code execution. Patch these OpManager vulnerabilities and CVE-2026-19599 to secure your network. # ManageEngine # Cybersecurity # CVE202619599 # OpManager # Infosec # Vulnerability https:// securityonline.info/manageengi ne-security-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social

A GitLab critical patch release addresses two CVEs enabling a GitLab RCE vulnerability. Update your CI/CD pipelines to prevent arbitrary code execution. # GitLab # Cybersecurity # CVE202689078 # CVE20

mastodon:infosec-exchangeother6d ago kagi ↗

A GitLab critical patch release addresses two CVEs enabling a GitLab RCE vulnerability. Update your CI/CD pipelines to prevent arbitrary code execution. # GitLab # Cybersecurity # CVE202689078 # CVE202693577 # InfoSec # RCE https:// securityonline.info/gitlab-cri tical-patch-release-rce/?utm_source=mastodon&utm_medium=jetpack_social

Luxion KeyShot users: patch now. RCE vulnerability (CVE-2026-92202, CVSS 7.8) in BIP files allows remote code execution. Update available. # Cybersecurity https:// deafnews.it/en/article/luxion- keysh

mastodon:infosec-exchangeother5d ago kagi ↗

Luxion KeyShot users: patch now. RCE vulnerability (CVE-2026-92202, CVSS 7.8) in BIP files allows remote code execution. Update available. # Cybersecurity https:// deafnews.it/en/article/luxion- keyshot-rce-vulnerability-in-bip-files-patch-available