Security news.
Today's cybersecurity news is dominated by critical vulnerabilities, with multiple zero-days actively exploited across various platforms including Arista VeloCloud, F5 BIG-IP APM, and Check Point Management Servers. Patches have been released for several high-impact flaws, while a new cPanel vulnerability allows root access, and an unpatched Ubuntu kernel flaw enables container escapes. The pervasive theme of AI also continues, with new AI-powered malware and ongoing discussions about AI safety and autonomous agents.
Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day
Arista Networks has released patches for an actively exploited zero-day flaw affecting VeloCloud Orchestrator (VCO) On-Prem deployments.
New cPanel Flaw Lets Hosting Account Run Code as Root
A critical flaw in cPanel's CalDAV and CardDAV service allows any hosting account to run code as root and take full server control, with fixes released.
Exploit Released for Unpatched Ubuntu Linux Flaw
An exploit has been released for CVE-2026-80521, a use-after-free flaw in the Linux kernel's AF_UNIX socket subsystem, allowing container escapes to gain root on the host, which remains unpatched in several Ubuntu LTS releases.
F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE
F5 has released hotfixes for CVE-2026-94127, a critical flaw in BIG-IP Access Policy Manager (APM) being actively exploited for unauthenticated remote code execution on OAuth authorization servers.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP
A Chinese threat actor (UTA0565) exploited a zero-day chain involving Chrome vulnerabilities (CVE-2026-85046, CVE-2026-87491) and a Windows flaw (CVE-2026-85880) to deploy CLEANGULP malware.
Check Point Patches Exploited Management Server Zero-Day
Check Point has released a fix for CVE-2026-93616, a critical-severity zero-day in its Security Management Server that allowed unauthenticated attackers to upload and execute arbitrary scripts in targeted attacks.
Adobe Patches Critical Flaws in Connect, AEM Forms
Adobe has released patches addressing nine critical security defects in Connect and AEM Forms that could lead to arbitrary code execution and privilege escalation.
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Microsoft has disrupted EvilTokens, a cybercrime platform that leveraged AI at every step of the attack chain, from generating social engineering messages to selecting targets.