Executive assessment
Today's brief leads with New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 leads because it is marked CRITICAL, CVSS 10.0, exploited in the wild, and has fixed VCO release trains listed. Patch order: Finding 01 (CRITICAL CVSS 10.0 VeloCloud Orchestrator flaw with exploitation in the wild and fixed VCO 5.2.3.16+ and 6.4.2.8+ trains listed); Finding 02 (CRITICAL Check Point path traversal vulnerability with exploitation in the wild and fixed hotfix levels listed across affected trains); Finding 03 (CRITICAL F5 BIG-IP APM heap-based buffer overflow with exploitation in the wild, hotfixes listed, and an iRule mitigation listed); Finding 08 (HIGH Veeam vulnerability with exploitation in the wild and proof-of-concept exploit code released); Finding 05 (CRITICAL ARM64 KVM flaw with fixed kernel versions listed and host-memory read-write impact, although no exploitation is reported).
Finding 01 — New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
What changed: Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host.
Technical evidence: CVE-2026-93952; CVSS v3.1 10; weakness CWE-20; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict access to the VCO web interface to trusted administrative networks. Monitor for malicious-source access and unexpected outbound activity, and block outbound ports not required for normal operations. Arista reports that the issue is known to be actively exploited. ([arista.com](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183))
Affected: VCO 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in the 6.1.x train, 6.4.2.7 and earlier in the 6.4.x train, and 7.0.0.2 and earlier in the 7.0.x train. ([arista.com](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183))
Fix: VCO 5.2.3.16 and later in the 5.2.3 train, and VCO 6.4.2.8 and later in the 6.4.2 train. ([arista.com](https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183))
Action: Map CVE-2026-93952 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-93952)
Finding 02 — Check Point Multiple Products Path Traversal Vulnerability
What changed: CISA added CVE-2026-93616 (Check Point Multiple Products) to the Known Exploited Vulnerabilities catalogue: Path Traversal, CVSS v3.1 9.8; affected: R82.20; R82.10 Jumbo Hotfix Take 44 or lower; R82 Jumbo Hotfix Take 126 or lower; R81.20 Jumbo Hotfix Take 166 or lower; R81.10 Jumbo Hotfix Take 190 or lower (EoS).
Technical evidence: CVE-2026-93616; CVSS v3.1 9.8; weakness CWE-22; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict TCP/19009 to trusted IP addresses and limit Trusted Clients to trusted internal IP addresses. Check Point reports that the vulnerability is exploited in the wild and that a handful of customers have been attacked. ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000171/))
Affected: R82.20; R82.10 Jumbo Hotfix Take 44 or lower; R82 Jumbo Hotfix Take 126 or lower; R81.20 Jumbo Hotfix Take 166 or lower; R81.10 Jumbo Hotfix Take 190 or lower (EoS). ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000171/))
Fix: R82.20 Security Hotfix; R82.10 Jumbo Hotfix Take 45 or later; R82 Jumbo Hotfix Take 127 or later; R81.20 Jumbo Hotfix Take 170 or later; R81.10 Jumbo Hotfix Take 192 or later. ([support.checkpoint.com](https://support.checkpoint.com/results/sk/sk1000171/))
Action: Map CVE-2026-93616 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-93616)
Finding 03 — F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
What changed: CISA added CVE-2026-94127 (F5 BIG-IP APM) to the Known Exploited Vulnerabilities catalogue: Heap-based Buffer Overflow, CVSS v3.1 9.8; affected: BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1 and 21.1.0.
Technical evidence: CVE-2026-94127; CVSS v3.1 9.8; weakness CWE-122; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Apply an iRule to the affected BIG-IP APM virtual server. Monitor for multiple OAuth authentication failures followed by suspicious commands and TMM SIGABRT, and investigate this combination. CERT-EU reports that F5 confirmed active exploitation in the wild. ([my.f5.com](https://my.f5.com/manage/s/article/K000162605), [cert.europa.eu](https://cert.europa.eu/publications/security-advisories/2026-013/), [cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127))
Affected: BIG-IP APM 17.1.0–17.1.3, 17.5.0–17.5.1 and 21.1.0. ([my.f5.com](https://my.f5.com/manage/s/article/K000162605))
Fix: Hotfix-BIGIP-17.1.3.5.0.41.14-ENG, Hotfix-BIGIP-17.5.1.9.0.160.12-ENG and Hotfix-BIGIP-21.1.0.2.0.30.22-ENG. ([cyber.gc.ca](https://www.cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127))
Action: Map CVE-2026-94127 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-94127)
Finding 04 — Siemens Siveillance Control: Unrestricted Upload of File with Dangerous Type
What changed: A vulnerability has been identified in the Open Interface Services (OIS) web module affecting Siveillance Control and Siveillance Control Pro (versions OIS 3.x.y and OIS 4.x.y). This vulnerability allows an attacker to upload arbitrary files, which can lead to unauthorized root-level access on the OIS server.
Technical evidence: CVE-2026-50093; CVSS v3.1 9; weakness CWE-434; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-50093 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-03)
Finding 05 — New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
What changed: A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
Technical evidence: CVE-2026-89775; CVSS v3.1 9.3; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Disable nested virtualisation on unpatched ARM64 KVM hosts; restrict access permissions on the KVM device node. SecurityOnline reports no in-the-wild exploitation or public proof of concept. ([securityonline.info](https://securityonline.info/kvm-guest-escape-cve-2026-89775/), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-89775), [access.redhat.com](https://access.redhat.com/security/cve/CVE-2026-89775))
Fix: Linux kernel 6.18.51, 7.2.5 and 7.3-rc1. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-89775))
Action: Map CVE-2026-89775 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html)
Finding 06 — WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
What changed: A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server.
Technical evidence: CVE-2026-93485; CVSS v3.1 7.1; weakness CWE-79; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-93485 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html)
Finding 07 — Multiple vulnerabilities in Sonatype Nexus Repository 3
What changed: Sonatype Nexus Repository 3 carries 6 CVEs across 3 advisories: Deserialization of Untrusted Data; Incorrect Authorization. CVE coverage: CVE-2020-11753, CVE-2021-40143, CVE-2020-15871, CVE-2026-77124, CVE-2026-10748, CVE-2026-77125.
Technical evidence: CVE-2026-10748; CVSS v4.0 8.6; weakness CWE-502; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Review who holds the nx-licensing-create privilege and restrict it to fully trusted administrators. Sonatype reports that it was not aware of active exploitation in the wild when it published the advisory. ([support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/52335766035603-CVE-2026-10748-Nexus-Repository-3-Remote-Code-Execution-2026-06-16), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/360046233714-CVE-2020-11753-Nexus-Repository-3-Improper-Access-Controls-2020-04-16), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/4405941762579-CVE-2021-40143-Nexus-Repository-3-HTTP-Header-Injection-2021-09-01), +3 more)
Affected: All Sonatype Nexus Repository 3.x CE/Pro versions before 3.92.0; CVE-2026-77124: Sonatype Nexus Repository 3 CE/Pro versions 3.21.2 through 3.95.x. ([support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/52335766035603-CVE-2026-10748-Nexus-Repository-3-Remote-Code-Execution-2026-06-16), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/54641528273811/), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/54643114434451-CVE-2026-77125-Nexus-Repository-3-Incorrect-Authorization-on-Blobstore-Group-Endpoints-2026-09-02))
Fix: Sonatype Nexus Repository CE/Pro version 3.92.0; Sonatype Nexus Repository 3 CE/Pro version 3.96.0 ([support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/52335766035603-CVE-2026-10748-Nexus-Repository-3-Remote-Code-Execution-2026-06-16), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/360046233714-CVE-2020-11753-Nexus-Repository-3-Improper-Access-Controls-2020-04-16), [support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/4405941762579-CVE-2021-40143-Nexus-Repository-3-HTTP-Header-Injection-2021-09-01), +3 more)
Action: Map CVE-2026-10748 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-10748)
Finding 08 — Proof-of-Concept Exploit Code Released for Veeam Vulnerability
What changed: Exploitation of Veeam Agent for Microsoft Windows vulnerability could allow local privilege escalation to SYSTEM privileges.
Technical evidence: CVE-2026-32996; CVSS v4.0 7.3; weakness CWE-532; technical confidence High.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Analyst note: Restrict interactive local access and minimise unnecessary local administrator and backup-operator privileges. Monitor for suspicious reads of the Veeam Endpoint Backup log, unexpected named-pipe activity and anomalous SYSTEM-level process creation. Help Net Security reports that Arctic Wolf says attackers are exploiting CVE-2026-32996. ([gbhackers.com](https://gbhackers.com/hackers-exploit-veeam-agent-vulnerability/), [helpnetsecurity.com](https://www.helpnetsecurity.com/2026/09/22/zyxel-switches-cve-2026-7273-vulnerability-exploited/), [veeam.com](https://www.veeam.com/kb4852), +1 more)
Affected: Veeam Backup & Replication 13.0.1.2067 and all earlier version 13 builds. ([veeam.com](https://www.veeam.com/kb4852))
Action: Map CVE-2026-32996 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: digital.nhs.uk](https://digital.nhs.uk/cyber-alerts/2026/cc-4856)
Finding 09 — GitHub Enterprise Server: Server-Side Request Forgery
What changed: A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an attacker-supplied cluster configuration and issued gateway-to-agent requests whose HMAC authenticated only a timestamp, not the request path or body.
Technical evidence: CVE-2026-18730; CVSS v4.0 8.2; weakness CWE-918; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Restrict network access to the GHES Manage API to trusted administrative networks. Restrict and monitor outbound network paths from GHES to documented cluster and update endpoints. Wavense reports no known exploitation or public exploit. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-18730/), [wavense.com](https://www.wavense.com/cve/CVE-2026-18730), [cve.org](https://www.cve.org/CVERecord?id=CVE-2026-18730))
Affected: GitHub Enterprise Server releases in the 3.17, 3.18, 3.19, 3.20 and 3.21 series. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-18730))
Fix: GitHub Enterprise Server 3.17.21, 3.18.15, 3.19.12, 3.20.8 and 3.21.6. ([cve.org](https://www.cve.org/CVERecord?id=CVE-2026-18730))
Action: Map CVE-2026-18730 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-18730)
Finding 10 — MongoDB C Driver: Double Free
What changed: A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice.
Technical evidence: CVE-2026-84964; CVSS v4.0 8.2; weakness CWE-415; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Analyst note: Use OCSP stapling. ([github.com](https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-fw3j-wh78-34mj))
Fix: MongoDB C Driver 1.30.9 and 2.5.2. ([github.com](https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-fw3j-wh78-34mj))
Action: Map CVE-2026-84964 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-84964)
Finding 11 — Multiple vulnerabilities in MCP Atlassian
What changed: MCP Atlassian carries 12 CVEs across 2 advisories: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path; OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions; Incomplete fix for redirect-based SSRF via unhooked requests session in Jira user-permission lookup; Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters; SSRF Protection Bypass; Reflected XSS in OAuth Setup Callback Handler; Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool; Insecure File Permissions on OAuth Token Storage; SSRF redirect protection missing for basic-auth and OAuth authentication branches; Incomplete path traversal fix allows intra-CWD module overwrite and RCE; Upload Attachment Tools; confluence_upload_attachment allows exfiltration of server credentials. CVE coverage: CVE-2026-77258, CVE-2026-77250, CVE-2026-77249, CVE-2026-77247, CVE-2026-77274, CVE-2026-77272, CVE-2026-77262, CVE-2026-77268, CVE-2026-77261, CVE-2026-77271, CVE-2026-77270, CVE-2026-77259.
Technical evidence: CVE-2026-77258; CVSS v3.1 7.7; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Analyst note: Set READ_ONLY_MODE=true to block attachment upload tools, and restrict the OAuth callback listener to loopback; for the MCP HTTP listener, bind to loopback or require authentication on non-loopback interfaces. On systems using OAuth, set ~/.mcp-atlassian to mode 0700 and its oauth-.json files to 0600. ([github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-vc25-24vv-fxxm), [github.com](https://github.com/advisories/GHSA-g2r2-3j32-j27x), [github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-p6hp-93wp-fh6p), +6 more)
Affected: mcp-atlassian versions earlier than 0.22.0 ([github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-93xw-j965-9mx3), [github.com](https://github.com/advisories/GHSA-f26r-j276-ggg4), [github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-6cr4-ccf3-x7h4))
Fix: mcp-atlassian 0.22.0 ([github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-93xw-j965-9mx3), [github.com](https://github.com/advisories/GHSA-f26r-j276-ggg4), [github.com](https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-6cr4-ccf3-x7h4))
Action: Map CVE-2026-77258 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: github.com](https://github.com/advisories/GHSA-93xw-j965-9mx3)
Finding 12 — Multiple vulnerabilities in Nuclei
What changed: CVE coverage: CVE-2026-76803, CVE-2026-76805, CVE-2026-76802, CVE-2026-76819, CVE-2026-76804. The cited advisories disclose: Local File Read via MySQL Client Sandbox Bypass; Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode; Arbitrary Command Execution via DAST Code Signature Bypass; Arbitrary Code Execution via Goja JavaScript Engine Vulnerability; Local File Read via Workflow File-Protocol Gate Bypass.
Technical evidence: CVE-2026-76803; CVSS v3.1 5.3; weakness CWE-284; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-76803 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-xhmx-w2j4-rw3q)
Finding 13 — Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle.
What changed: GitHub Advisory Database published GHSA-8fcf-v89g-xpg6 for CVE-2026-88010 (Traefik): Observable Timing Discrepancy, CVSS v4.0 6.3.
Technical evidence: CVE-2026-88010; CVSS v4.0 6.3; weakness CWE-208; technical confidence Medium.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-88010 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-8fcf-v89g-xpg6)
Finding 14 — ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
What changed: The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...].
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation reported by the source, not independently corroborated
fixed version or patch state unknown
[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/)
Finding 15 — Still active: New Windows Defender zero-day blocks Microsoft antivirus updates
Coverage status: First reported 2026-09-11; ongoing coverage.
What changed: A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits:** grounded severity unavailable
exploitation reported by the source, not independently corroborated
fixed version or patch state unknown
[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html)