Daily Signal — 2026-09-25
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 5/5 sources were live for this edition.
At a glance
- CVE-2026-67279 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: Eufy Omni C20, Omni X10 Pro.
- M5.3 was the strongest M4.5+ event in the USGS 24-hour feed.
- Electron | Owlright, Owlright, Owlright (StriX Launch 13) is next on the public launch manifest.
Exploited vulnerabilities
- CVE-2026-67279 — MikroTik RouterOS. Added 2026-09-25; remediation due 2026-09-28. Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-65660 — Microsoft SharePoint. Added 2026-09-25; remediation due 2026-09-28. Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-5430 — WSO2 Multiple Products. Added 2026-09-24; remediation due 2026-09-27. WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2026-67279 · MikroTik RouterOS · added 2026-09-25 · due 2026-09-28
- CVE-2026-65660 · Microsoft SharePoint · added 2026-09-25 · due 2026-09-28
- CVE-2026-5430 · WSO2 Multiple Products · added 2026-09-24 · due 2026-09-27
- CVE-2026-71362 · Adobe Commerce and Magento · added 2026-09-24 · due 2026-09-27
- CVE-2026-93952 · Arista VeloCloud Orchestrator · added 2026-09-22 · due 2026-09-25
- CVE-2026-94127 · F5 BIG-IP APM · added 2026-09-22 · due 2026-09-25
- CVE-2026-93616 · Check Point Multiple Products · added 2026-09-22 · due 2026-09-25
- CVE-2026-85102 · Check Point Multiple Products · added 2026-09-22 · due 2026-09-25
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- The current CISA advisory window contains no title or summary that explicitly names a threat actor, campaign, or ransomware operation.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M5.3 — Vanuatu region, 2026-09-25 11:12 UTC. The M4.5+ day feed contained 12 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- Electron | Owlright, Owlright, Owlright (StriX Launch 13) — Rocket Lab; Go for Launch; no-earlier-than 2026-09-26 00:26 UTC. Pad: Rocket Lab Launch Complex 1B · Rocket Lab Launch Complex 1, Mahia Peninsula, New Zealand.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: live
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-25 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.