Seite wählen

24.09.2026

F5 fixes actively exploited zero-day flaw in BIG-IP APM

CSO Online 23.09.2026 20:44
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available.
BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users.

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

The Hacker News 23.09.2026 12:16
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.

A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.

cPanel has released fixed versions for both,

UniFi Gateways und Firewalls: Ubiquiti schließt DoS-Lücken

Heise Security 23.09.2026 11:53
In UniFi-Firewalls und -Gateways klaffen hochriskante Denial-of-Service-Lücken. Aktualisierte Firmware stopft die Lecks.

Absturzgefahr: Exploit lässt Angreifer DJI-Drohnen mitten im Flug kapern

Golem 23.09.2026 10:48
Mehrere Drohnenmodelle des Herstellers DJI sind anfällig für eine gefährliche Sicherheitslücke, die eine vollständige Kontrollübernahme ermöglicht. (Sicherheitslücke, WLAN)

NetBSD 10.2 stopft einige Sicherheitslücken

Heise Security 23.09.2026 10:02
NetBSD ist jüngst als Point-Release 10.2 erschienen. Die Entwickler schließen damit einige Sicherheitslücken.

Patchday: Adobe Connect ist unter Android, macOS und Windows verwundbar

Heise Security 23.09.2026 08:45
Es sind wichtige Sicherheitsupdates für verschiedene Adobe-Anwendungen erschienen.

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

The Hacker News 23.09.2026 08:29
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.

The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

The Hacker News 23.09.2026 07:04
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.

The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version