Current vulnerability threat posture

CRITICAL

Why critical?
  • AI ASSISTED ASSESSMENTLatest persisted AI review classified the window as URGENT.
  • VTP FACT3 CISA KEV addition(s) recorded in the last 24 hours.
  • VTP DETERMINISTIC ASSESSMENT2538 material threat events recorded in 24 hours.
1threats require attention
1760open deterministic alerts
2538material changes / 24h
Last scheduled review
22:05 · succeeded
Last threat review
22:05 · systemd
Last baseline assessment
22:04 · systemd
Next scheduled review
06:00
Evidence current to
23:47
AI threat briefAI-assisted analysis. Evidence and analyst review remain authoritative.
Morning brief25 Sept 2026
Complete brief
Overall threat levelcriticalhigh confidence

Check Point and F5 reported active exploitation of remote code execution flaws in security gateways and management systems. Prioritize available vendor remediation and restrict exposed management or VPN services. These products can provide attackers with code execution on high-value security infrastructure.

Recommended actions
  • If you operate Check Point Security Gateways, apply the vendor update for CVE-2026-85102 and investigate exposed VPN services for vendor-documented compromise indicators.
  • If you operate Check Point Management Server or Multi-Domain Security Management, restrict administrative-interface access, apply R82.20, and check the vendor indicators for CVE-2026-93616.
  • If you operate BIG-IP APM as an OAuth Authorization Server, apply F5's listed hotfix and investigate using the vendor compromise indicators for CVE-2026-94127.

Updates since the morning brief

Latest first · Times in Paris

3 updates
  1. Reported Roundcube exploitation requires prompt patching

    SecurityWeek reported exploitation of CVE-2026-48842. The flaw permits pre-authentication SQL injection through the virtuser_query plugin. If you use affected Roundcube versions, update to 1.6.16 or 1.7.1 promptly.

    View source

Last checked at 22:05.

Earlier assessment
Earlier assessment still relevantAssessed on 25 Sept 2026
Review in your environment

Greenbone Community Feed added exploit-oriented tooling coverage for CVE-2017-0144 and CVE-2017-0148. These flaws affect SMBv1 servers on listed legacy Windows versions and can permit remote code execution through crafted packets. ENISA lists CVE-2017-0144 as known exploited. If you operate affected SMBv1 systems, identify them, limit SMB reachability, and prioritize supported remediation or isolation.

This earlier assessment still applies.CVE-2017-0144
Generated 25 Sept, 06:16 · window 24 Sept, 06:15–25 Sept, 06:15
Analysis details
AnalysisRun ID
3b096f37-dd59-42c9-947d-063cf97a11cf
Trigger type
SYSTEMD
Run cutoff
25 Sept, 22:00
Model
gpt-5.6-terra
Reasoning
low
Evidence records
14
Run-window material changes
7
Rolling 24h material changes
2538
Unique threat subjects
7
Prioritized subjects
2
Reviewed subjects
2
Failed subjects
0
Candidate alerts
2
Checkpoint committed
Yes
Sources represented
2
Independent groups
2
Sensor context
ACTIVE
Model invoked
Yes
Baseline CVEs pending
0
Baseline processed latest execution
18
Baseline added since latest execution
0
Baseline failed latest execution
0
Latest scheduled baseline processed
18
Latest scheduled baseline failed
0
Average assessment latency
48.27h
Latest baseline execution
d6cae0d5-bc5f-441e-9487-484a32490222
Latest scheduled baseline
d6cae0d5-bc5f-441e-9487-484a32490222
Analysis data cutoff
25 Sept, 22:00

Honeypot activity

First-party analytical overview

Open full activity
10
Recent findings

Separate patterns of noteworthy activity currently shown in this overview. This is not the number of attacks or raw requests.

2
Possible CVE matches

Unique CVEs that may match the observed activity. One finding can match several CVEs, so this is not a count of exploitation attempts. Exploitation and success are not confirmed.

0
Reviewed with AI

Findings for which a bounded AI review helped interpret an unresolved or conflicting signal. AI output is analytical guidance, not proof.

10
Matched by rules

Findings produced by VTP's signatures and technical matching rules without relying on an AI judgment. A rule match still does not prove successful exploitation.

0
No CVE identified

Exploit-like activity for which VTP could not identify a sufficiently reliable CVE match. The activity is retained without inventing an attribution.

Possible CVE matches

These CVEs share technical details with activity seen by the honeypots. The list shows possible associations, not confirmed exploitation or successful compromise.

Observed activity may match these CVEs. Exploitation is not confirmed.

ACTIVE · First-party sensor telemetry is active. Observations are available to authenticated analysts.

These figures describe reviewed findings, not every request received.

VTP groups related sensor events before showing them. A zero would mean that no disclosure-safe finding is shown here; it would not prove that exploitation did not occur.

See evidence and possible CVE matches

Priority threats

Review queue

Latest successful AnalysisRun only · maximum 5
01
URGENTAI assessment60% analytical confidence

CVE-2026-71362

Adobe Commerce authorization flaw added to CISA KEV

adobe / commerce

CISA KEV now includes CVE-2026-71362, and BleepingComputer reports it is being leveraged in attacks. The incorrect-authorization flaw can let an attacker gain elevated access to sensitive resources without user interaction. If you use Adobe Commerce or Magento, urgently apply Adobe’s recommended update or mitigation and investigate unexpected privileged access.

AI priorityCRITICAL
Public exploitationKEV
Exploit availabilityTECHNICAL DETAILS
First-party telemetryACTIVE
Why VTP prioritized this

AI rationale

  • The named report says CISA added Adobe Commerce CVE-2026-71362 to KEV as leveraged in attacks.
  • Adobe describes an incorrect-authorization mechanism that can elevate access to sensitive resources without user interaction.
  • CISA KEV establishes known exploitation globally, making remediation a priority for affected deployments.

Evidence normalization

1 cited publications resolve to 1 underlying evidence chains.

0 dependent reports are visible but are not counted as independent confirmation. 1 reports have unresolved independence.

Open analysis 2 evidence records · 2 sources

Last 24 hours

What changed?

Open threat feed
  1. VTP FACT

    EPSS changed materially from 0.09 to 0.91

    Predictive context changed; this is not exploitation evidence.

    CVE-2026-85706
  2. VTP FACT

    EPSS changed materially from 0.02 to 0.28

    Predictive context changed; this is not exploitation evidence.

    CVE-2026-76461
  3. VTP FACT

    EPSS changed materially from 0.02 to 0.90

    Predictive context changed; this is not exploitation evidence.

    CVE-2026-71362
  4. VTP FACT

    EPSS changed materially from 0.15 to 0.89

    Predictive context changed; this is not exploitation evidence.

    CVE-2026-48908
  5. VTP FACT

    EPSS changed materially from 0.27 to 0.62

    Predictive context changed; this is not exploitation evidence.

    CVE-2025-62593
  6. VTP FACT

    EPSS changed materially from 0.07 to 0.65

    Predictive context changed; this is not exploitation evidence.

    CVE-2024-57728
  7. VTP FACT

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-85706.

    CVE-2026-85706
  8. VTP FACT

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-20929.

    CVE-2026-20929
  9. VTP FACT

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-18729.

    CVE-2026-18729
  10. VTP FACT

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

    CVE-2015-8279
  11. VTP FACT

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

    CVE-2015-8280
  12. VTP FACT

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

    CVE-2015-8281

Evidence / intelligence processing overview

Evidence radar · last 24 hours

Live counters may include evidence ingested after the latest AI cutoff.
Public intelligence items
50
Authoritative advisories
8
Technical research
1
Specialized press
35
New CVEs
600
KEV additions
3
PoCs identified
0
Functional exploits
0
Exploitation-related signals
3
Independent primary confirmations
1

Publication volume is not confirmation volume. Dependent reports remain traceable without multiplying evidence.

Latest intelligence stream

Recent source records

View all intelligence
First-party sensor telemetry is active. Observations are available to authenticated analysts. Dashboard snapshot generated 25 Sept, 23:57.