Network Security Engineer: 2026-09-25
10 minutes in total
Critical Vulnerability in F5 BIG-IP APM
CERT-EU, 2026-09-22. Read, 3 min.
F5 disclosed CVE-2026-94127 on September 22, a heap-based buffer overflow in BIG-IP APM rated CVSS 9.8 that allows an unauthenticated attacker to achieve remote code execution, and confirmed active exploitation in the wild. CERT-EU lists versions 17.1.0 to 17.1.3, 17.5.0 to 17.5.1, and 21.1.0 as affected when configured with an access policy and an OAuth profile on a virtual server, and recommends preserving forensic evidence, applying the hotfix, and checking for signs of compromise.
Why it matters for this role: Identify BIG-IP virtual servers that run APM as an OAuth Authorization Server, since F5 has confirmed exploitation and those are the only exposed configurations.
CVE-2026-78902: XSS to RCE in pfSense with one DNS request
NetSPI, 2026-09-22. Read, 7 min.
NetSPI disclosed CVE-2026-78902 in the pfBlockerNG package for pfSense: where DNS reply logging is configured, an attacker able to make a DNS request from inside the network can store JavaScript on pfSense web management pages, which NetSPI says can lead to remote code execution with root access if an administrator views them. Netgate pushed a fixed package, version 3.2.16_1, on July 2, 2026, within 24 hours of the report.
Why it matters for this role: Check the pfBlockerNG package on each pfSense appliance, since an internal DNS request was enough to plant script in the web interface wherever DNS reply logging was on.
Sign in to take it.