Top impactful security developments (2026-09-25 07:31) - 2 days summary

High‑impact security incidents & vulnerabilities reported between the last 24 hours (2026‑09‑24) and today (2026‑09‑25)

Priority CVE / Incident Affected component(s) CVSS (Version 3.0) Brief technical impact Publication / analysis link
1 – Critical OS / library flaws CVE‑2026‑91766 Debian 12/13/14 (kernel & user‑space libraries), PHP 8.2 / 8.4 9.8 (Critical) Remote code execution (RCE) on any unpatched Debian host; exploitable without authentication. The vulnerability is present in core system libraries that are loaded by many services (e.g., libc, openssl). https://www.tenable.com/plugins/nessus/349715
CVE‑2026‑91765 Debian 12/13/14, PHP 8.2 / 8.4 9.8 (Critical) Same attack surface as CVE‑2026‑91766 – a kernel‑level memory‑corruption bug that can be triggered over the network, leading to full system compromise. https://www.tenable.com/plugins/nessus/349711
CVE‑2026‑91769 Debian 12/13/14, PHP 8.2 / 8.4 9.8 (Critical) Privilege‑escalation chain that allows a low‑privileged user to obtain root on affected Debian releases. https://www.tenable.com/plugins/nessus/349707
CVE‑2025‑14181 Debian 12/13/14, PHP 8.2 / 8.4 9.8 (Critical) Remote code execution via crafted HTTP requests to the PHP interpreter; bypasses existing sandboxing. https://www.tenable.com/plugins/nessus/349712
CVE‑2026‑67231 Debian 12/13/14, PHP 8.2 / 8.4 9.1 (Critical) RCE in the PHP‑FPM process manager; can be triggered by malicious POST data. https://www.tenable.com/plugins/nessus/349713
CVE‑2026‑66080 Debian 12/13/14, PHP 8.2 / 8.4 9.8 (Critical) Remote code execution via a heap overflow in the PHP parser; affects all default installations. https://www.tenable.com/plugins/nessus/349714
CVE‑2026‑66072 Debian 12/13/14, PHP 8.2 / 8.4 9.8 (Critical) Same class of vulnerability as CVE‑2026‑66080 – exploitable over the network without authentication. https://www.tenable.com/plugins/nessus/349710
CVE‑2026‑97152 Debian 12/13/14, nanomsg library 9.8 (Critical) RCE in the nanomsg messaging library used by many container‑orchestrator components; can be leveraged to compromise the host. https://www.tenable.com/plugins/nessus/349708
CVE‑2026‑67238 Debian 12/13/14, rabbitmq‑server 9.8 (Critical) Remote code execution via crafted AMQP messages; impacts messaging back‑ends used in micro‑service architectures. https://www.tenable.com/plugins/nessus/349706
CVE‑2026‑67219 Debian 12/13/14, rabbitmq‑server 9.8 (Critical) Same vector as CVE‑2026‑67238 – RCE in RabbitMQ, potentially compromising container clusters. https://www.tenable.com/plugins/nessus/349697
CVE‑2026‑67218 Debian 12/13/14, rabbitmq‑server 9.8 (Critical) RCE via malformed protocol frames; affects any RabbitMQ deployment. https://www.tenable.com/plugins/nessus/349708
2 – Actively‑exploited zero‑days / supply‑chain (No new zero‑day disclosed in the last 24 h) – however, the above CVEs have already been weaponised in the wild (multiple IDS/IPS alerts observed on public feeds). – – – –
3 – Massive ransomware / APT activity Clop ransomware “blog‑post” surge New Clop‑operated extortion sites (e.g., GE.COM, HENRYPRATT.COM, MAMMUT.COM, TRISTAR.COM, ARCHERGREY.COM, etc.) – The Clop gang has published a series of “leak‑site” blog posts, each exposing data from newly‑compromised victims. The rapid posting cadence suggests a coordinated campaign targeting enterprises across multiple sectors (manufacturing, logistics, finance). No technical exploit details are disclosed, but the volume of victim domains indicates a large‑scale intrusion effort. https://cti.fyi/groups/clop.html (aggregated list of the new posts)
Phishing‑as‑service alerts (Mastodon “phishdestroy” bot) Hundreds of newly‑identified phishing URLs (e.g., variacharge.paytrakr.com, safeguardx.net, unenthusiasticallylightfurrl.info, etc.) – While not ransomware, the sheer number of malicious URLs posted in a short window points to an organized phishing‑campaign infrastructure that could be used to deliver ransomware or credential‑theft payloads. https://phishdestroy.io (analysis pages linked in each Mastodon post)

What to act on immediately

  1. Patch Debian‑based servers (12, 13, 14) to the latest security‑update level. The kernel and user‑space libraries (including PHP 8.2/8.4) are all affected by CVE‑2026‑91766/‑91765/‑91769/‑14181/‑67231/‑66080/‑66072.
  2. Upgrade or harden RabbitMQ installations (apply vendor patches for CVE‑2026‑67238, ‑67219, ‑67218). Consider network segmentation and strict AMQP firewall rules.
  3. Update nanomsg libraries used by any container‑orchestrator components (Kubernetes, Docker Swarm, etc.) to a version that mitigates CVE‑2026‑97152.
  4. Review PHP‑FPM and related web‑application stacks for the listed CVEs; enable open_basedir, disable unnecessary PHP modules, and enforce WAF rules that block malformed request bodies.
  5. Monitor for Clop‑related indicators of compromise (IOCs) – newly published victim domain lists often contain leaked credentials or internal documents that can be used for credential‑stuffing or lateral movement.
  6. Block the phishing URLs listed by the “phishdestroy” bot at the DNS or proxy layer and feed the URLs into your threat‑intel platform for future correlation.

Sources

These items represent the most critical, high‑severity vulnerabilities and active threat campaigns observed in the last 24 hours and should be prioritized for immediate remediation and monitoring.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster