VYPR
AI Brief2026-09-27· generated Sep 27, 2026

What you need to know today.

CISA adds FreePBX, Windows IKE, and WordPress flaws to KEV; active exploitation of WordPress vulnerability noted.

A critical vulnerability in FreePBX (CVE-2025-57819) has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw allows unauthenticated attackers to gain administrative access to FreePBX systems by exploiting insufficiently sanitized user input. The vulnerability affects FreePBX versions 15, 16, and 17. Immediate patching or mitigation is strongly recommended to prevent unauthorized access and potential system compromise.

Microsoft's Windows IKE Extension is facing a critical double-free vulnerability (CVE-2026-33824), also added to the CISA KEV catalog. This flaw permits remote, unauthenticated attackers to execute arbitrary code over a network. While Microsoft has released patches, the active exploitation highlighted by its inclusion in the KEV catalog underscores the urgency for all users to apply these security updates.

A supply chain attack compromised the ASUS Live Update client, leading to the distribution of unauthorized modifications (CVE-2025-59374). This critical vulnerability could allow attackers to target specific devices with malicious code. ASUS has acknowledged the issue, and users are advised to check for and apply any available updates or security advisories from the vendor.

WordPress core is affected by a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to perform path traversal, potentially leading to local file inclusion and code execution. This flaw was added to the CISA KEV catalog shortly after its disclosure, indicating active exploitation. WordPress has released version 7.1.2 to address this critical issue, and users should update immediately. As The Hacker News reported, exploitation began within hours of the patch release.

Multiple critical vulnerabilities have been disclosed in Microsoft products, including Azure Logic Apps (CVE-2026-83944, CVE-2026-70200), Microsoft Fabric (CVE-2026-69843), Azure Arc (CVE-2026-69399), and Microsoft Container Registry (CVE-2026-69865). These flaws primarily involve privilege escalation through authentication bypass, improper access control, and path traversal, allowing unauthorized attackers to gain elevated privileges over a network. Microsoft has released patches for these vulnerabilities, and users are urged to apply them promptly. Vypr Intelligence reported on the broad impact of these disclosures.

Adobe has released patches for critical vulnerabilities in Adobe Experience Manager Forms JEE (CVE-2026-75745) and Adobe Campaign Classic (CVE-2026-75721). The AEM Forms vulnerability allows arbitrary code execution, while the Campaign Classic flaw involves code injection. Both are critical and could lead to significant compromise if exploited. SecurityWeek reported on these and other Adobe patches.

Synthesized by Vypr AI
KEV Updates: FreePBX, Windows IKE, WordPress Exploited · VYPR