VulncastBriefing archive

Daily Brief - 2026-09-23

· 5 vulnerabilities · 6 min listen

▶ Listen to this briefing

CVE-2026-28325

high · CVSS 8.8 · SolarWinds Observability

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

  • Insecure Deserialization
  • Remote Code Execution
  • web application
  • monitoring

CVE-2026-89275

critical · CVSS 10 · Adobe Campaign Classic

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

  • Code Injection
  • Remote Code Execution
  • enterprise software

CVE-2026-93616

critical · CVSS 9.8 · Check Point Management Server

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

  • Directory Traversal
  • Remote Code Execution
  • network appliance

CVE-2026-93952

critical · CVSS 10 · VMware VeloCloud Orchestrator

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

  • Broken Access Control
  • software defined networking

CVE-2026-94127

critical · CVSS 9.8 · F5 BIG-IP APM

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • Remote Code Execution
  • network appliance