Daily briefing · September 22, 2026

Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flaws

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — critical

September 22, 2026 marks a critical day with 445 new vulnerabilities published — 79 of them critical — and three already confirmed by CISA as actively exploited: a zero-day directory traversal in Check Point's Quantum Security Management armed on the same day it was disclosed, a remote access bypass in VeloCloud Orchestrator, and an RCE in F5 BIG-IP APM's OAuth authorization server. Defenders should treat today's bulletin as a high-urgency alert, with widespread exposure across network infrastructure, marketing platforms, and AI tooling.

Today’s brief
  • 3 CVEs confirmed actively exploited (CISA KEV): Check Point Quantum, VeloCloud VCO, and F5 BIG-IP APM — patch or isolate immediately
  • Check Point CVE-2026-93616 was armed on the same day it was disclosed — unauthenticated file upload leading to RCE is already being weaponized in the wild
  • Four CVSS 10.0 RCE flaws hit Adobe Campaign Classic simultaneously, with no user interaction required — high-value target for threat actors
  • RTI Connext Professional and Adobe AEM Forms JEE each carry CVSS 10.0 stack overflow / authorization bypass flaws affecting broad version ranges
79
critical
3
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-93616KEVCVSS 9.8PoCsame dayaffects Quantum Security Management
An unauthenticated directory traversal and file upload vulnerability in Check Point Quantum Security Management Server that allows arbitrary script execution — armed with a proof of concept on the same day of disclosure and already confirmed exploited by CISA and VulnCheck, making this the single most urgent item in today's bulletin.
2
CVE-2026-93952KEVCVSS 9.5affects VeloCloud Orchestrator (VCO) On-Prem
A critical authentication bypass in VeloCloud Orchestrator (VCO) on-prem allows remote attackers to access privileged internal functionality, threatening the confidentiality, integrity, and availability of all data and configurations managed by the orchestrator — already observed in active exploitation.
3
CVE-2026-94127KEVCVSS 9.3affects BIG-IP
When BIG-IP APM is deployed as an OAuth Authorization Server, crafted malicious traffic can trigger remote code execution — confirmed actively exploited by CISA and VulnCheck, and only environments using the OAuth AS profile are affected, so configuration review is the first defensive step.
4
CVE-2026-75745CVSS 10affects AEM 6.5 Forms JEE
Adobe Experience Manager Forms on JEE carries a CVSS 10.0 Incorrect Authorization flaw enabling arbitrary code execution without any user interaction and with changed scope — organizations running AEM Forms in JEE mode should treat this as a priority patch.
5
CVE-2026-7866CVSS 10affects Connext Professional
A CVSS 10.0 stack-based buffer overflow in RTI Connext Professional Core Libraries affects a wide version range from 4.3x through 7.7.0.1, potentially exposing real-time distributed systems and industrial/defense environments to remote compromise.
6
CVE-2026-77244CVSS 10affects mcp-atlassian
The mcp-atlassian MCP server prior to 0.22.0 accepts unauthenticated HTTP requests and falls back to the operator's global Atlassian credentials, meaning any network-reachable attacker can invoke Jira or Confluence actions as the operator — a supply-chain risk for AI-integrated enterprise workflows.
7
CVE-2026-75703CVSS 10affects Adobe Campaign Classic
A CVSS 10.0 code injection vulnerability in Adobe Campaign Classic allows arbitrary code execution in the current user's context with no user interaction required and changed scope — one of four critical flaws hitting ACC today, signaling a significant patch cycle for marketing infrastructure teams.
8
CVE-2026-84412CVSS 10affects Adobe Campaign Classic
A second CVSS 10.0 code injection flaw in Adobe Campaign Classic mirrors CVE-2026-75703 in severity and impact; the simultaneous disclosure of multiple critical ACC vulnerabilities increases the risk that chaining becomes possible before patches are applied.
9
CVE-2026-75721CVSS 10affects Adobe Campaign Classic
A third code injection vulnerability in Adobe Campaign Classic rated CVSS 10.0 with no user interaction required — organizations should assume all three ACC code injection CVEs may be exploitable in sequence and prioritize isolation of ACC instances until patches are deployed.
10
CVE-2026-75723CVSS 10affects Adobe Campaign Classic
An Incorrect Authorization vulnerability in Adobe Campaign Classic (CVSS 10.0) rounds out today's ACC cluster, enabling arbitrary code execution without user interaction — the breadth of this patch wave for a single product is operationally significant for security teams managing marketing platforms.
Ransomware today

Recently discovered ransomware victims include four Brazilian organizations: Metallco (Manufacturing) was hit by Play, Javep Chevrolet (Retail & E-Commerce) by Akira, Cassias MG Government (Government & Defense) by Emperador, and AKAZZO by ArcusMedia. Looking at the 30-day activity window, thegentlemen leads with 8 attacks — all targeting Brazil — followed by Krybit, Akira, and Emperador, which together confirm Brazil as a primary operational focus for multiple active ransomware groups simultaneously.

Metallco BRplay · Manufacturing
Javep Chevrolet BRakira · Retail & E-Commerce
AKAZZO BRarcusmedia
Cassias MG Government BRemperador · Government & Defense
thegentlemen 8krybit 3akira 3emperador 2Vexy Ransomware 2settra 2
Active groups & APTs

Several threat actor groups are currently active or recently updated in threat intelligence feeds: Handala, Linkc, Mogilevich, Iran-linked Moses Staff, China-linked Elderwood, and Fulcrumsec. While no specific victims are attributed to these groups at this time, their active status in tracking systems suggests ongoing reconnaissance or campaign preparation that defenders should monitor alongside today's critical CVEs.

Brazil focus

Brazil is facing intense and sustained pressure from ransomware operators: in the past 30 days, confirmed victims include Metallco, Javep Chevrolet (targeted twice by Akira), Cassias MG Government, AKAZZO, Konnatus (legal services), Vetta (technology), and K3G Solutions Brazil. The concentration of attacks across manufacturing, government, retail, and professional services sectors — combined with groups like thegentlemen operating exclusively within Brazil — indicates a well-established targeting pattern that goes beyond opportunistic attacks.

Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
Konnatus (usucapião legal services)N0n · Professional Services
Vettaakira · Technology
Javep Chevroletakira · Retail & E-Commerce
K3G Solutions BrazilPanzer · Other
Today’s recommendation: Immediately prioritize patching or network isolation for Check Point Quantum Management Server (CVE-2026-93616), VeloCloud VCO on-prem (CVE-2026-93952), and F5 BIG-IP APM OAuth AS deployments (CVE-2026-94127), as all three are confirmed under active exploitation; Adobe Campaign Classic and AEM Forms JEE administrators should begin emergency patch assessment for the four CVSS 10.0 vulnerabilities disclosed today.
Given the breadth of today's critical disclosures across network infrastructure, marketing platforms, and AI-integrated tooling, now is the moment to validate which of these affected surfaces are reachable within your own environment before attackers do it for you.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share