
F5 BIG-IP APM CVE-2026-94127: exploited zero-day enables RCE
F5 confirms exploitation of CVE-2026-94127 and CISA lists it in KEV. Exposure requires an APM access policy with an OAuth profile; prioritise fixes and checks.
Read the analysisSECURCHECK · CYBER NEWS
Vendor alerts and steps for affected systems.
A sourced overview of tax, education and training incidents, with a clear distinction between confirmed exposure and claims.

F5 confirms exploitation of CVE-2026-94127 and CISA lists it in KEV. Exposure requires an APM access policy with an OAuth profile; prioritise fixes and checks.
Read the analysis
WordPress released fixes for path traversal in page-template resolution that can lead to code execution under specific conditions.
Read the analysis
Canada's Cyber Centre reports exploitation of CVE-2026-48842, fixed in Roundcube in May. Affected versions, scope and administrator actions.
Read the analysis
PaperCut confirms exploitation of NG/MF. A tally cited by the French health CERT identifies 395 organisations in 48 countries, including 31 in France.
Read the analysisGoogle reports indications of limited, targeted exploitation of CVE-2026-58704. The September Pixel security update addresses the flaw.
Read the analysis
JetBrains issued fixes for unauthenticated remote code execution in TeamCity On-Premises and later reported attempted exploitation.
Read the analysis
Check Point reports active exploitation of CVE-2026-50751 in certain VPN deployments using the deprecated IKEv1 protocol.
Read the analysisWe distinguish confirmed facts from claims and update articles when primary sources publish new information. These reports are not a real-time incident feed.