Cyber Briefing, Sep 23: F5 BIG-IP zero-day exploited, Chrome and Windows chains targeted

A digital illustration representing cybersecurity news, featuring a shield with a padlock, a laptop, and various icons related to security and technology.

12 stories · 3 sources · 3 critical · 4 high · ~13 min read

Coverage: Last 24 hours

Today’s Highlights

Critical zero-days are being actively exploited in Google Chrome, F5 BIG-IP Access Policy Manager (APM), and SD-WAN management infrastructure, threatening widespread compromise. Meanwhile, attackers are leveraging advanced techniques such as chaining Chrome and Windows exploits and deploying AI-powered platforms for phishing at scale. Defensive urgency is paramount as risks expand not only from traditional exploits but also from fast-evolving AI models and automation.

Table of Contents

  1. Chrome 154 Patches 108 Vulnerabilities
  2. F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
  3. Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
  4. Check Point Patches Exploited Management Server Zero-Day
  5. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
  6. Arista Urges Immediate Patching of Exploited VCO Zero-Day
  7. Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

Critical   High   Medium   Low

Top Stories


Chrome 154 Patches 108 Vulnerabilities

Source: SecurityWeek | Published: Sep 23 | Risk: HIGH | Impacted: Enterprise endpoint fleets, VDI and DaaS users, App developers embedding Chromium | Topics: Vulnerability / Threat Intel

What happened: Google released Chrome 154, addressing 108 vulnerabilities, including 11 critical-severity issues like buffer overflows and use-after-free bugs. Nine critical flaws were reported by external researchers, earning $18,000 in bug bounty rewards. Users are advised to update their browsers promptly.

Why it matters: Browsers are a primary target for malicious code delivery, and critical browser bugs rapidly become part of exploit kits used to breach enterprise and personal systems.

How it works: Web browsers like Google Chrome process untrusted content from the internet. Critical memory handling flaws allow attackers to run arbitrary code by luring users to malicious sites or documents, often resulting in malware deployment.

Affected / Fix: Chrome 154 addresses 108 vulnerabilities including 11 critical; deploy latest browser version immediately.

Practitioner Perspective

This release includes 11 critical bug fixes for exploitable memory problems like buffer overflows and use-after-free conditions. Attackers routinely chain browser vulnerabilities with privilege escalation bugs to deploy malware or steal data, so patch lag creates high-value exposure. Enterprises with unmanaged endpoints or weak browser update controls are especially vulnerable. You should treat this Chrome release as security-critical: validate that auto-update is enforced on all endpoints and that any exceptions are tracked and mitigated. High-value users and VDI pools should be prioritized for verification.

Recommended Actions

  • Deploy Chrome 154 update across all Windows, Mac, and Linux endpoints within 24 hours
  • Audit Chrome extension inventory for exposure to known attack surfaces patched in this release

Exploits & CVEs


F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Source: The Hacker News | Published: Sep 23 | Risk: CRITICAL | Impacted: Enterprises using BIG-IP APM as OAuth servers, Cloud IAM teams, SaaS and legacy app owners tied to F5 APM | Topics: Vulnerability / Exploit

What happened: Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

Why it matters: Unauthenticated remote code execution on OAuth-capable APM instances gives attackers direct access to authentication infrastructure, risking downstream compromise of any applications using these tokens.

How it works: F5 BIG-IP APM provides authentication policy management and, when configured, serves as an OAuth authorization server. CVE-2026-94127 allows remote attackers to execute code without authentication on these systems, risking full compromise of identity flows.

Affected / Fix: Affects APM OAuth authorization servers; F5 has released engineering hotfixes.

Practitioner Perspective

Attackers are leveraging CVE-2026-94127 to gain RCE on F5 BIG-IP systems running APM as OAuth authorization servers. This creates an ideal pivot point for stealing, issuing, or replaying tokens, potentially compromising identity across the enterprise. The exploitation of authentication infrastructure is a recurring high-value attacker tactic, and hotfixes must be treated as mandatory. You should immediately verify which APM deployments are OAuth servers and prioritize both patching and proactive indicator hunting. Assume token forgery or theft may already have occurred in unpatched environments.

Recommended Actions

  • Apply engineering hotfixes for CVE-2026-94127 to all BIG-IP APM OAuth authorization servers
  • Review and rotate OAuth secrets, tokens, and associated credentials issued by impacted APMs

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Source: SecurityWeek | Published: Sep 23 | Risk: CRITICAL | Impacted: Enterprises using F5 BIG-IP appliances, Remote access and VPN service admins, Data center network teams | Topics: Vulnerability / Exploit

What happened: Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

Why it matters: Remote code execution by unauthenticated attackers on critical networking appliances undermines the security of any user sessions or data traversing these platforms.

How it works: F5 BIG-IP products provide load balancing, traffic management, and remote access functions. Remote code execution flaws allow attackers to run arbitrary code or commands on these appliances, bypassing authentication entirely.

Practitioner Perspective

This zero-day in F5 BIG-IP platforms highlights the danger to enterprises relying on physical and virtual networking appliances for secure access, and the persistent attacker focus on these gateways. Once compromised, attackers may access, modify, or forward sensitive traffic and pivot further inside the network. Immediate patching is important, but defenders must also audit for evidence of exploitation, especially during the disclosure-to-patch window. Any signs of compromise, such as unexplained process launches, should trigger a response runbook including device reimaging.

Recommended Actions

  • Deploy F5’s urgent zero-day patch across all exposed BIG-IP systems
  • Audit appliance logs for signs of unauthenticated traffic and RCE attempts since vulnerability disclosure

Check Point Patches Exploited Management Server Zero-Day

Source: SecurityWeek | Published: Sep 23 | Risk: CRITICAL | Impacted: Check Point firewall and gateway customers, Network security operations teams, Security policy enforcement administrators | Topics: Vulnerability / Exploit

What happened: The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek.

Why it matters: Remote script execution on security management servers gives attackers a high-leverage pivot point to reconfigure defenses, disable alerting, or propagate further attacks inside the network.

How it works: Check Point Management Servers orchestrate security policy, NAT, and rule deployment for firewalls and gateways. Remote code execution here could allow attackers to alter configurations or deploy further malicious scripts enterprise-wide.

Affected / Fix: Patch is available for affected Check Point Management Servers.

Practitioner Perspective

Check Point Management Servers are central to policy and firewall administration, an RCE zero-day here means attackers control not only a highly privileged box, but potentially the security posture of the entire protected estate. Patch urgency cannot be overstated, and defenders must assume any unpatched management server may already be compromised. Mandate immediate review of management server logs and restrict further changes until forensic investigation is complete. Rotate all credentials managed or accessed by the compromised instance.

Recommended Actions

  • Deploy the Check Point patch for the exploited management server zero-day on all instances
  • Audit management server logs for evidence of unauthorized script uploads or changes

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Source: The Hacker News | Published: Sep 23 | Risk: HIGH | Impacted: Organizations with unpatched Chrome and Windows fleets, Government and critical infrastructure sites, Geopolitical targets | Topics: Vulnerability / Ai

What happened: A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

Why it matters: Coordinated zero-day exploitation across browser and OS layers enables high-skill attackers to execute malware on fully patched endpoints, defeating most layered endpoint defenses.

How it works: This attack chains browser vulnerabilities in Chrome with a local privilege escalation in Windows’ Advanced Local Procedure Call (ALPC) to achieve remote code execution and persistence. The attack reaches across browser and OS process boundaries.

Affected / Fix: Chrome and Windows vulnerabilities (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) have updates available.

Practitioner Perspective

Chaining of Chrome CVEs (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC bug (CVE-2026-85880) demonstrates advanced TTPs by state-linked groups. The implication for defenders is that attackers are bypassing both browser sandboxes and OS privilege barriers to gain execution and persistence. Standard patching must be coupled with proactive hunting for exploitation artifacts, especially in verticals or geographies of strategic interest. Defenders should regressively analyze endpoint telemetry around the known attack windows and ensure endpoints are receiving updates quickly. Focus on closing exposure via swift patch compliance and reviewing browser telemetry for unusual process activity.

Recommended Actions

  • Patch Chrome for CVE-2026-85046 and CVE-2026-87491 across all endpoints
  • Apply OS updates for Windows ALPC CVE-2026-85880 on all affected systems

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Source: SecurityWeek | Published: Sep 23 | Risk: HIGH | Impacted: Enterprises with on-prem VeloCloud Orchestrator, Midsize and large SD-WAN users, Network operations teams | Topics: Vulnerability / Exploit

What happened: Arista has released urgent patches for a critical vulnerability in VeloCloud Orchestrator (VCO) deployments, tracked as CVE-2026-93952, which has been exploited as a zero-day. The flaw allows remote attackers to access privileged internal functionality, potentially compromising the confidentiality, integrity, and availability of the orchestrator and its data. The vulnerability affects only VeloCloud Orchestrator On-Prem and was resolved in VCO versions 5.2.3.16 and 6.4.2.8. Arista recommends updating to these versions and reviewing logs for suspicious activity.

Why it matters: A privileged access vulnerability in SD-WAN management can allow attackers to manipulate WAN topologies or compromise inter-site connectivity, risking data interception or service disruption.

How it works: VeloCloud Orchestrator manages central SD-WAN policy and traffic for distributed sites. CVE-2026-93952 lets attackers abuse internal functionality, potentially giving them broad control or data access via management APIs or interfaces.

Affected / Fix: Affects VeloCloud Orchestrator On-Prem; fixed in versions 5.2.3.16 and 6.4.2.8.

Practitioner Perspective

Attackers are actively exploiting CVE-2026-93952 targeting VeloCloud Orchestrator On-Prem deployments, meaning this is not a theoretical risk for distributed organizations. VCO is a central control point for SD-WAN, so compromise could cascade into full network control, interception, or disrupt remote site communications. Even after patching, forensic review is essential as attackers may have already gained persistent access or deployed additional tooling. Prioritize review of all VCO access logs and configuration histories for suspicious activity. Assume exploitation until thorough log review and redeployment verification is complete.

Recommended Actions

  • Patch all VeloCloud Orchestrator On-Prem appliances to at least 5.2.3.16 or 6.4.2.8
  • Search VCO event logs for unrecognized privileged operations or configuration changes

Emerging Signals


Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

Source: The Hacker News | Published: Sep 23 | Risk: HIGH | Impacted: Web teams using Next.js for Open Graph/social preview, Developers exposing user-driven image features, SaaS providers with custom image rendering | Topics: Vulnerability / Exploit

What happened: A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22.

Why it matters: Server-side code execution via crafted image uploads can directly compromise web app infrastructure, enabling lateral movement or data access well beyond the web tier.

How it works: Next.js ImageResponse generates images server-side, often for social sharing and preview features. Flaws in SVG processing can allow attackers to inject scripts or code, resulting in server-side code execution if user input is not properly validated.

Affected / Fix: Patched by Vercel on September 22; update Next.js and sanitize inputs.

Practitioner Perspective

The Next.js ImageResponse SVG flaw is exploitable when unsanitized user input passes into Open Graph or other image generation features, common in custom or marketing-heavy applications. Attackers can craft SVG payloads to achieve RCE if these code paths are exposed, even in internal or staged environments. Defenders should review every usage of ImageResponse, not just public endpoints, as internal compromise can be just as damaging. Review code and conduct instrumentation-based validation, because patching alone does not suffice if unsafe input logic persists.

Recommended Actions

  • Update Next.js to the version released on September 22 with the SVG code execution fix
  • Audit all Open Graph and ImageResponse usages for unsanitized user input

Also Today

Defensive Actions

  • Apply security patches and engineering hotfixes for F5 BIG-IP, Chrome, Windows ALPC, VeloCloud Orchestrator, Check Point, and Next.js vulnerabilities on all relevant infrastructure.
  • Monitor device code authentication flows for unusual activity; enable conditional access for SaaS such as M365 and Google Workspace.
  • Hunt for exploitation indicators and unusual process activity associated with recent zero-day CVEs: CVE-2026-94127 (F5 BIG-IP), CVE-2026-93952 (VeloCloud Orchestrator), CVE-2026-85046 and CVE-2026-87491 (Chrome), CVE-2026-85880 (Windows ALPC).
  • Rotate OAuth, privileged, and admin credentials stored on affected F5, Arista, and Check Point systems after patching.
  • Instrument server-side image processing logic and audit for SVG/script injection if using Next.js ImageResponse or related features.
  • Review and restrict SaaS and network management administrative interface exposures.
  • Conduct forensic and log reviews for all SD-WAN, management server, and gateway systems for signs of compromise during exploit windows.

What We’re Watching

  • Potential for wider exploitation of F5 BIG-IP vulnerabilities (CVE-2026-94127, 0-day class) by additional threat actors.
  • Ongoing attacks leveraging chained Chrome and Windows ALPC exploits (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880), especially in government and sensitive sectors.
  • Signs of post-compromise persistence or novel malware (e.g., CLEANGULP) related to endpoint exploitation during September.
  • Adoption of Next.js SVG code execution techniques in public exploit frameworks and underground forums in the coming days.
  • Further retaliatory threats or leak-driven campaigns from ShinyHunters or similarly motivated groups in response to recent press and law enforcement activity.

Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.



Categories: Cybersecurity Blog, Cybersecurity News

Tags: , , , , , ,

Leave a Reply

Discover more from TECHMANIACS.com

Subscribe now to keep reading and get access to the full archive.

Continue reading