ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardNewslettersPast editions › ITsecurity Daily — Wednesday, 23 September 2026: F5 BIG-IP APM under active attack via critical 0-day RCE — patch is out

ITSECURITY.GURU

ITsecurity Daily

Daily Briefing

F5 BIG-IP APM under active attack via critical 0-day RCE — patch is out

Good morning. The Register reported that attackers are exploiting a critical zero-day remote code execution flaw in F5 BIG-IP APM, and that both CISA and F5 warn it is under active exploitation. The Register also reported that a patch is available. Prioritise this one: BIG-IP APM sits at the network edge as an access proxy, and a remotely exploitable RCE there is a route into everything behind it. Match your estate against F5's advisory and apply the vendor's fix.

Two more products were reported under active exploitation. BleepingComputer reported that Check Point has confirmed active exploitation of a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of its Security Gateway product. BleepingComputer separately reported that threat actors have moved from probing WordPress sites affected by a critical flaw to exploiting it, writing files to disk that execute shell commands when accessed. Check your Check Point Security Gateway and WordPress installs against each vendor's advisory and patch.

Google shipped a Chrome stable channel update fixing six flaws. Google's advisory record lists CVE-2026-93374, CVE-2026-93373 and CVE-2026-93372, each carrying a CVSS base score of 9.6 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), and CVE-2026-93382, CVE-2026-93381 and CVE-2026-93377, each scored 8.8 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Google lists Chrome up to the fix in 153.0.8010.52 as affected. Update to 153.0.8010.52 and confirm your fleet has restarted to apply it (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html).

Read the full briefing →

Zoom out: Three separate products — F5 BIG-IP APM, Check Point Security Gateway and WordPress — were reported under active exploitation.

Vulnerability in focus

CVE-2026-93374 — Google. CVSS 9.6

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

Elsewhere

  • Help Net Security: What to do first when you get 90 days to secure AI agent data Read it
  • Help Net Security: Your security program knows about the firewall, but does it know about the elevator? Read it
  • Help Net Security: Ubuntu kernel CVE fixes are moving to a weekly release schedule Read it
  • Help Net Security: Europe’s technology backbone is becoming a cyber target Read it
  • The Register: OpenAI agents ‘infiltrated Australian government website’ Read it
  • BleepingComputer: Placeholder domain used in dev docs now serves ClickFix attacks Read it
  • Help Net Security: Americans’ views on data centers have turned more negative Read it
  • The Record: UK regulator to investigate Pornhub parent company for alleged age verification failings Read it
  • BleepingComputer: Check Point warns of hackers exploiting Security Gateway VPN RCE flaw Read it
  • SecurityWeek: IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin Read it
  • The Record: No evidence of successful foreign meddling in 2024 election, spy agencies found Read it
  • BleepingComputer: Hackers start exploiting critical WordPress flaw for code execution Read it

Sources

Every briefing is on the site, with the advisory record behind it. All briefings

You are receiving this because you subscribed at itsecurity.guru.

Headlines from other outlets belong to them; each one credits its outlet and leads to their own report.

All past editions · Get them by email