VYPR
AI Brief2026-09-25· generated Sep 25, 2026

What you need to know today.

Multiple critical vulnerabilities in SonicWall, GitLab, Check Point, Adobe Campaign Classic, and Cisco IOS are being actively exploited and have been added to the CISA KEV catalog.

A critical deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw, tracked as CVE-2025-23006, could allow an unauthenticated remote attacker to execute arbitrary code under specific conditions. The vulnerability was reportedly exploited in the wild before a patch was available, as noted by Tenable. Organizations using affected SonicWall devices should prioritize applying the available security updates to mitigate the risk of compromise.

GitLab has released patches for a critical path traversal vulnerability, CVE-2026-85706, affecting multiple versions of its Community Edition (CE) and Enterprise Edition (EE). This flaw allows an unauthenticated user to read arbitrary files on the server, potentially leading to the exposure of sensitive information or credentials. The vulnerability was quickly added to the CISA KEV catalog due to active exploitation observed shortly after its disclosure, with reports from Rapid7 and CyberScoop highlighting widespread scanning and exploitation attempts. Affected versions include those prior to 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2.

Check Point has addressed a critical vulnerability in its Quantum Security Gateway, CVE-2026-85102, which allows unauthenticated remote attackers to execute arbitrary code by exploiting improper certificate trust validation during VPN negotiation. This flaw has been added to the CISA KEV catalog, indicating active exploitation. Multiple security outlets, including Cyber Security News and Help Net Security, reported on the exploitation of this vulnerability, with some noting its use in targeted attacks against management servers and Spark firewalls. Organizations using Check Point Quantum Security Gateways should apply the provided patches immediately.

A wave of seventeen critical vulnerabilities has been disclosed in Adobe Campaign Classic (ACC), with several already added to the CISA KEV catalog. These flaws, including multiple instances of code injection and improper authorization, could allow attackers to achieve arbitrary code execution in the context of the current user. Vypr Intelligence reported on the coordinated disclosure of these vulnerabilities, emphasizing the severe risk they pose. While specific exploitation details are still emerging, the critical nature and high CVSS scores of these vulnerabilities necessitate prompt patching by all affected organizations.

Cisco has acknowledged and patched a critical cross-site request forgery (CSRF) vulnerability in its IOS software, specifically affecting the HTTP Administration component on the 871 Integrated Services Router. Tracked as CVE-2008-4128, this vulnerability could allow remote attackers to execute arbitrary commands by tricking users into clicking malicious links. The US and its allies have warned of Russian cyberattacks targeting critical infrastructure routers, and this vulnerability, despite its age, has been added to the CISA KEV catalog due to active exploitation. Organizations using affected Cisco IOS versions should update to a patched release.

Synthesized by Vypr AI