F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks

2026-09-23T20:51:37Z•064f7d36052b163bcf6a8eee2e742cd736271990feef5df8dffc84dca624ea65
CVE-2026-7273CVE-2026-87902CVE-2026-93616CVE-2026-94127APMCISA-KEVCheck-PointContagious-InterviewEDR-killingF5-BIG-IPNorth-Korea-linkedVeeam-AgentWaterPlumWordPressZyxelactive-exploitationcritical-vulnerabilitycybercrimedevice-code-phishinginfostealerphishing-as-a-serviceprivilege-escalationpublic-proof-of-conceptremote-code-executionzero-day

What happened

SecurityAffairs RSS roundup covering multiple high-impact threats reported on September 22–23, 2026, including actively exploited zero-days in F5 BIG-IP APM and Check Point Security Management Server, critical WordPress and Zyxel vulnerabilities, public exploitation of Veeam Agent privilege escalation, phishing-as-a-service activity, malware campaigns, and alleged breaches. The most urgent items are the unauthenticated remote-code-execution vulnerabilities under active exploitation and the Zyxel flaw added to CISA’s KEV catalog.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
064f7d36052b163bcf6a8eee2e742cd736271990feef5df8dffc84dca624ea65
Enrichment time
2026-09-23T20:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks · Baitaphish