Threat Brief — 2026-09-23: Zero-days exploited across network appliances
Multiple critical zero-days are being actively exploited across network infrastructure products, with CISA adding several to its Known Exploited Vulnerabilities catalog today. A Chinese threat actor tracked as UTA0565 has been observed deploying CLEANGULP malware through a Chrome–Windows zero-day chain via fake websites. F5 BIG-IP APM, Check Point, and Arista VeloCloud all have newly KEV-listed flaws under active attack, while ShinyHunters has released further claims about its alleged FBI breach via an Oracle PeopleSoft zero-day.
Top items
- F5 BIG-IP APM heap buffer overflow (CVE-2026-94127KEV) — actively exploited, now in CISA KEV. A critical heap-based buffer overflow in BIG-IP Access Policy Manager permits unauthenticated remote code execution when APM is configured with an OAuth profile on a virtual server. F5 has released patches. This flaw is confirmed exploited in the wild and was added to CISA's KEV catalog. The underlying story was first reported earlier today. (src: The Hacker News) (src: BleepingComputer) (src: CISA KEV)
- Chinese threat actor UTA0565 exploits Chrome–Windows zero-day chain deploying CLEANGULP. A Chinese threat actor codenamed UTA0565 exploited a chain of Google Chrome and Microsoft Windows zero-days through fake websites to deploy CLEANGULP malware. Attacks were detected on September 3–4, 2026. Three CVEs are listed in CISA KEV — CVE-2026-85046KEV, CVE-2026-87491KEV, and CVE-2026-85880KEV — confirming active exploitation in the wild. (src: The Hacker News)
- Two Check Point vulnerabilities added to CISA KEV — both exploited in the wild. CVE-2026-85102KEV is an improper certificate validation flaw affecting Check Point Security Gateway and Spark Firewall when using Site-to-Site VPN or Remote Access VPN. CVE-2026-93616KEV is a path traversal vulnerability in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. These relate to the Check Point Management Server story first reported 2026-09-18 by The Hacker News. (src: CISA KEV)
- Arista VeloCloud Orchestrator (CVE-2026-93952KEV) added to CISA KEV. An improper input validation flaw in Arista VeloCloud Orchestrator on-premises allows remote attackers to access privileged internal functions. Now confirmed exploited in the wild. This is a development in the VeloCloud Orchestrator story first reported 2026-09-22 by The Hacker News. (src: CISA KEV)
- Seven Chromium V8 engine vulnerabilities disclosed by MSRC. Microsoft has published information on seven Chromium V8 bugs: CVE-2026-87625 (use-after-free), CVE-2026-87601 (race condition), CVE-2026-87536 (use-after-free), CVE-2026-87612 (type confusion), CVE-2026-87489 (memory corruption), CVE-2026-87587 (use-after-free), and CVE-2026-87564 (type confusion). No exploit activity has been confirmed for any of these. (src: MSRC) (src: MSRC) (src: MSRC)
- Next.js ImageResponse SVG flaw enables server code execution. A critical vulnerability in Next.js's ImageResponse feature — used to generate Open Graph and social preview images — could allow attackers to execute server-side code via crafted SVG input when an application passes untrusted values to the component. Vercel has disclosed the flaw. No exploit activity has been confirmed. (src: The Hacker News)
- ShinyHunters releases further details on alleged FBI breach. The ShinyHunters group has expanded its claims about breaching FBI systems via a zero-day in Oracle PeopleSoft, stating it stole approximately 2–3 TB of data including personal and medical records of current and former employees and job applicants. The FBI has not publicly confirmed the breach. This story was first reported 2026-09-22 by BleepingComputer. (src: The Hacker News) (src: Xakep)
- Third cyberattack on a tanker reported — hackers gained control of vessel systems. Hackers reportedly seized control of a tanker's systems in what is described as the third such incident, affecting equipment directly tied to liquefied gas safety. This is a development in the vessel cyber breach story first reported 2026-09-17 by SecurityLab. (src: SecurityLab)
Themes
Network appliance zero-day cluster. F5 BIG-IP APM, two distinct Check Point product lines, and Arista VeloCloud Orchestrator all received KEV additions today, indicating coordinated or concurrent exploitation of perimeter and management infrastructure. Attackers are targeting OAuth-configured access proxies, VPN certificate validation, and management-plane path traversal — all pre-authentication vectors on devices that often sit at the network boundary.
Chrome–Windows exploit chain adoption. The UTA0565 activity confirms that Chrome–Windows zero-day chains are not merely theoretical; at least one Chinese APT has operationalized them with dedicated malware (CLEANGULP) and watering-hole infrastructure. This follows last week's reporting on the BlueMoon exploit kit being adopted by multiple groups.
