Skip to main content
F5 BIG-IP APM Unauthenticated Remote Code Execution Actively Exploited on OAuth-Configured Systems (CVE-2026-94127)

Scope: F5 BIG-IP Access Policy Manager, Virtual Servers Configured with Both an APM Access

Arista VeloCloud Orchestrator Maximum Severity Flaw Exploited With No Available Workaround (CVE-2026-93952)

Scope: Arista VeloCloud Orchestrator (VCO) On-Prem Deployments

Linux Kernel Actively Exploited Vulnerabilities Remain Unpatched Past Federal Deadline (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)

Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers

FomoPeek Trojanized iOS App Hides Kernel Exploit to Steal Cryptocurrency Wallet Data

Scope: iOS Devices with FomoPeek or Similarly Sideloaded Cryptocurrency Applications Insta

OpenAI Codex Sandbox Escapes "Heapjack" and "Overpatch" Allow Unsandboxed Command Execution

Scope: OpenAI Codex Desktop (Prior to Build 26.818.21641) and Codex CLI (Prior to Version

CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities, Federal Deadline Today (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)

Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers

Subscribe to Advisories