What you need to know today.
F5 BIG-IP APM, Check Point Servers, and VeloCloud Orchestrator face actively exploited critical vulnerabilities, alongside critical SAP and Adobe flaws.

A critical unauthenticated remote code execution vulnerability in F5 BIG-IP APM, tracked as CVE-2026-94127, is being actively exploited. This flaw allows attackers to execute arbitrary code by sending specially crafted traffic to virtual servers configured with specific APM access policies and OAuth profiles. The vulnerability, which has a CVSS score of 9.8, is particularly concerning as it targets the authentication and authorization mechanisms within BIG-IP APM when acting as an OAuth Authorization Server. Exploitation could lead to a complete system compromise. Patches are available from F5, and CISA has added this to its Known Exploited Vulnerabilities (KEV) catalog. The Hacker News, Cyber Security News, SecurityWeek, Rapid7 Blog, watchTowr Labs, The Register Security.
Check Point Management Servers are targeted by an actively exploited directory traversal and file upload vulnerability, CVE-2026-93616. This critical flaw, with a CVSS score of 9.8, allows unauthenticated attackers to upload and execute arbitrary scripts on the server, potentially leading to full system compromise. The vulnerability has been added to CISA's KEV catalog, indicating active exploitation. The Hacker News, Cyber Security News, SecurityWeek, Vypr Intelligence, Help Net Security.
VeloCloud Orchestrator (VCO) on-premises deployments are vulnerable to CVE-2026-93952, a critical flaw rated CVSS 10.0, which allows remote attackers to access privileged internal functionality and impact the VCO host. This vulnerability has been observed to be actively exploited, particularly in certificate-based setups. Successful exploitation could lead to a compromise of confidentiality and integrity. CISA has added this vulnerability to its KEV catalog. The Hacker News, SecurityWeek, Help Net Security, CISA Alerts.
SAP has released patches for a critical memory safety vulnerability in its Extended Passport Protocol (EPP) processing library, CVE-2026-44756. This flaw, with a CVSS score of 10.0, can be exploited by an unauthenticated attacker through a crafted network request with a malformed EPP header, potentially leading to arbitrary code execution. The vulnerability affects various SAP products, including SAP NetWeaver and SAP Cloud. Infosecurity Magazine, The Hacker News, SecurityWeek, Cyber Security News, GovInfoSecurity.
Several critical vulnerabilities have been disclosed across various Adobe products. CVE-2026-75745 in Adobe Experience Manager Forms JEE and CVE-2026-75682 in Adobe Connect are among the most severe, both carrying a CVSS score of 10.0 and allowing for arbitrary code execution. Adobe has released patches for these and other vulnerabilities affecting its products. SecurityWeek.
A critical unauthenticated remote code execution vulnerability, CVE-2026-28324, has been identified in SolarWinds Observability Self-Hosted. This flaw arises from insufficient integrity checks and can be exploited by attackers to execute arbitrary code on vulnerable systems, particularly those configured in non-default or insecure ways. Cyber Security News.
Oracle has addressed critical vulnerabilities in its Oracle Forms and Oracle Internet Directory products. CVE-2026-83099 in Oracle Forms and CVE-2026-83059 in Oracle Internet Directory are both rated CVSS 10.0 and allow unauthenticated attackers to exploit the flaws, potentially leading to system compromise.
Lantronix devices, including SLC8000, EMG8500, and EMG7500, are affected by critical vulnerabilities. CVE-2026-80155 allows for authentication bypass in the web management portal's upload endpoint, while CVE-2026-80147 is a stack-based buffer overflow vulnerability exploitable by authenticated attackers. Patches are available for some versions.
Other critical vulnerabilities include a stack-based buffer overflow in RTI Connext Professional (CVE-2026-7866), an OS command injection flaw in Virtualizor (CVE-2026-43641), a hard-coded credentials vulnerability in LTSecurity LTK3500SF (CVE-2026-47116), and a buffer overflow in Arubanetworks' Utility daemon leading to unauthenticated RCE (CVE-2024-26305). Additionally, IBM DOORS Next has a vulnerability (CVE-2024-27253) allowing authenticated users to bypass security logic. A CGI Script Center vulnerability (CVE-2000-0944) allows password modification without knowing the original. A stack-based buffer overflow in FAST FAC1203R Gigabit Edition (CVE-2026-96257) and an Improper Control of Code Generation vulnerability in Adobe Campaign Classic (CVE-2026-73369) also present significant risks. Finally, a missing authentication vulnerability in Gigatech PDV5701 (CVE-2026-94493) has been reported.