VORANT. Threat Intelligence Research Sign in Create a free account

CERT-FR flags actively exploited flaws in Check Point, F5, Citrix, WSO2

severe vulnerability technologyinfrastructuretelecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR's weekly bulletin lists actively exploited critical RCE flaws in Check Point, F5 BIG-IP, WordPress, Citrix NetScaler, WSO2, Arista VeloCloud and more, urging urgent patching.

This is CERT-FR's regular weekly vulnerability bulletin (week 39, 21-27 September 2026) summarizing the most significant vulnerabilities disclosed and patched that week, with emphasis on those already under active exploitation. Multiple critical (CVSS 9.3-9.9) remote code execution and security-bypass flaws affect widely deployed enterprise products: Check Point Multi-Domain Security Management/Security Management (CVE-2026-93616, CVE-2026-91843), F5 BIG-IP APM (CVE-2026-94127), WordPress core (CVE-2026-87902, the 'Click2Shell' RCE requiring an admin to submit a malicious form), GitLab CE/EE (CVE-2026-89078, CVE-2026-93577), SolarWinds Observability Self-Hosted (CVE-2026-28324) and Serv-U (CVE-2026-28308), HPE Aruba Networking Analytics and Location Engine (CVE-2026-76708/76709), Synology DSM (CVE-2026-13639, CVE-2026-13684), and Apache Tomcat (CVE-2026-86248, CVE-2026-76183, CVE-2026-86350). Check Point, F5 and WordPress vulnerabilities are confirmed exploited in the wild; most others show no public exploitation information yet.

A secondary table lists additional actively exploited vulnerabilities tracked outside the main critical table: WSO2 Traffic Manager/API Manager/Universal Gateway (CVE-2026-5430, CVSS 10, security bypass), Arista VeloCloud Orchestrator (CVE-2026-93952), Citrix NetScaler ADC/Gateway (CVE-2026-88771 and related CVEs, RCE and security bypass), Zyxel GS1900 series switch firmware (CVE-2026-7273, buffer overflow RCE), Microsoft SharePoint Server (CVE-2026-65660), Roundcube Webmail (CVE-2026-48842, SQLi), Veeam Backup & Replication (CVE-2026-32996, privilege escalation), MikroTik RouterOS (CVE-2026-67279), and Foxit PDF Editor/Reader (CVE-2026-91799, public exploit code available). The bulletin also enumerates ~27 separate CERT-FR advisories issued that week covering Mattermost, Microsoft Edge, Moodle, Chrome, Wireshark, LibreNMS, PaperCut, Microsoft Office, Zabbix Agent, PHP, Elastic products, and Linux kernel updates across Ubuntu, Red Hat, SUSE and Debian LTS, plus updates to older advisories on Siemens products and Microsoft SharePoint.

Defenders should prioritize patching Check Point Security Management/Multi-Domain, F5 BIG-IP APM, WordPress (upgrade directly to 7.1.2 to cover both CVE-2026-87902 and the Click2Shell issue), Citrix NetScaler, and WSO2 products given confirmed in-the-wild exploitation, then work through the remaining critical RCE and security-bypass items (GitLab, Aruba, Synology, Tomcat, SolarWinds) per vendor advisories referenced in each CERT-FR AVI bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-13639CVE-2026-13684CVE-2026-28308CVE-2026-28324CVE-2026-32996CVE-2026-48842CVE-2026-5430KEVCVE-2026-65660KEVCVE-2026-67279KEVCVE-2026-7273KEVCVE-2026-76183CVE-2026-76708CVE-2026-76709CVE-2026-86248CVE-2026-86350CVE-2026-87902KEVCVE-2026-88771KEVCVE-2026-89078CVE-2026-91799CVE-2026-91843CVE-2026-93577CVE-2026-93616KEVCVE-2026-93952KEVCVE-2026-94127KEV

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-041

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,126 reports from 154 sources, 2,670 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs