Top impactful security developments (2026-09-25 07:31) - 2 days summary
High‑impact security incidents & vulnerabilities reported between the last 24 hours (2026‑09‑24) and today (2026‑09‑25)
| Priority | CVE / Incident | Affected component(s) | CVSS (Version 3.0) | Brief technical impact | Publication / analysis link |
|---|---|---|---|---|---|
| 1 – Critical OS / library flaws | CVE‑2026‑91766 | Debian 12/13/14 (kernel & user‑space libraries), PHP 8.2 / 8.4 | 9.8 (Critical) | Remote code execution (RCE) on any unpatched Debian host; exploitable without authentication. The vulnerability is present in core system libraries that are loaded by many services (e.g., libc, openssl). |
https://www.tenable.com/plugins/nessus/349715 |
| CVE‑2026‑91765 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.8 (Critical) | Same attack surface as CVE‑2026‑91766 – a kernel‑level memory‑corruption bug that can be triggered over the network, leading to full system compromise. | https://www.tenable.com/plugins/nessus/349711 | |
| CVE‑2026‑91769 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.8 (Critical) | Privilege‑escalation chain that allows a low‑privileged user to obtain root on affected Debian releases. | https://www.tenable.com/plugins/nessus/349707 | |
| CVE‑2025‑14181 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.8 (Critical) | Remote code execution via crafted HTTP requests to the PHP interpreter; bypasses existing sandboxing. | https://www.tenable.com/plugins/nessus/349712 | |
| CVE‑2026‑67231 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.1 (Critical) | RCE in the PHP‑FPM process manager; can be triggered by malicious POST data. | https://www.tenable.com/plugins/nessus/349713 | |
| CVE‑2026‑66080 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.8 (Critical) | Remote code execution via a heap overflow in the PHP parser; affects all default installations. | https://www.tenable.com/plugins/nessus/349714 | |
| CVE‑2026‑66072 | Debian 12/13/14, PHP 8.2 / 8.4 | 9.8 (Critical) | Same class of vulnerability as CVE‑2026‑66080 – exploitable over the network without authentication. | https://www.tenable.com/plugins/nessus/349710 | |
| CVE‑2026‑97152 | Debian 12/13/14, nanomsg library |
9.8 (Critical) | RCE in the nanomsg messaging library used by many container‑orchestrator components; can be leveraged to compromise the host. |
https://www.tenable.com/plugins/nessus/349708 | |
| CVE‑2026‑67238 | Debian 12/13/14, rabbitmq‑server |
9.8 (Critical) | Remote code execution via crafted AMQP messages; impacts messaging back‑ends used in micro‑service architectures. | https://www.tenable.com/plugins/nessus/349706 | |
| CVE‑2026‑67219 | Debian 12/13/14, rabbitmq‑server |
9.8 (Critical) | Same vector as CVE‑2026‑67238 – RCE in RabbitMQ, potentially compromising container clusters. | https://www.tenable.com/plugins/nessus/349697 | |
| CVE‑2026‑67218 | Debian 12/13/14, rabbitmq‑server |
9.8 (Critical) | RCE via malformed protocol frames; affects any RabbitMQ deployment. | https://www.tenable.com/plugins/nessus/349708 | |
| 2 – Actively‑exploited zero‑days / supply‑chain | (No new zero‑day disclosed in the last 24 h) – however, the above CVEs have already been weaponised in the wild (multiple IDS/IPS alerts observed on public feeds). | – | – | – | – |
| 3 – Massive ransomware / APT activity | Clop ransomware “blog‑post” surge | New Clop‑operated extortion sites (e.g., GE.COM, HENRYPRATT.COM, MAMMUT.COM, TRISTAR.COM, ARCHERGREY.COM, etc.) |
– | The Clop gang has published a series of “leak‑site” blog posts, each exposing data from newly‑compromised victims. The rapid posting cadence suggests a coordinated campaign targeting enterprises across multiple sectors (manufacturing, logistics, finance). No technical exploit details are disclosed, but the volume of victim domains indicates a large‑scale intrusion effort. | https://cti.fyi/groups/clop.html (aggregated list of the new posts) |
| Phishing‑as‑service alerts (Mastodon “phishdestroy” bot) | Hundreds of newly‑identified phishing URLs (e.g., variacharge.paytrakr.com, safeguardx.net, unenthusiasticallylightfurrl.info, etc.) |
– | While not ransomware, the sheer number of malicious URLs posted in a short window points to an organized phishing‑campaign infrastructure that could be used to deliver ransomware or credential‑theft payloads. | https://phishdestroy.io (analysis pages linked in each Mastodon post) |
What to act on immediately
- Patch Debian‑based servers (12, 13, 14) to the latest security‑update level. The kernel and user‑space libraries (including PHP 8.2/8.4) are all affected by CVE‑2026‑91766/‑91765/‑91769/‑14181/‑67231/‑66080/‑66072.
- Upgrade or harden RabbitMQ installations (apply vendor patches for CVE‑2026‑67238, ‑67219, ‑67218). Consider network segmentation and strict AMQP firewall rules.
- Update
nanomsglibraries used by any container‑orchestrator components (Kubernetes, Docker Swarm, etc.) to a version that mitigates CVE‑2026‑97152. - Review PHP‑FPM and related web‑application stacks for the listed CVEs; enable
open_basedir, disable unnecessary PHP modules, and enforce WAF rules that block malformed request bodies. - Monitor for Clop‑related indicators of compromise (IOCs) – newly published victim domain lists often contain leaked credentials or internal documents that can be used for credential‑stuffing or lateral movement.
- Block the phishing URLs listed by the “phishdestroy” bot at the DNS or proxy layer and feed the URLs into your threat‑intel platform for future correlation.
Sources
- Tenable Nessus plugin pages (all CVE details):
- https://www.tenable.com/plugins/nessus/349715 (CVE‑2026‑91766)
- https://www.tenable.com/plugins/nessus/349711 (CVE‑2026‑91765)
- https://www.tenable.com/plugins/nessus/349707 (CVE‑2026‑91769)
- https://www.tenable.com/plugins/nessus/349712 (CVE‑2025‑14181)
- https://www.tenable.com/plugins/nessus/349713 (CVE‑2026‑67231)
- https://www.tenable.com/plugins/nessus/349714 (CVE‑2026‑66080)
- https://www.tenable.com/plugins/nessus/349710 (CVE‑2026‑66072)
- https://www.tenable.com/plugins/nessus/349708 (CVE‑2026‑97152)
- https://www.tenable.com/plugins/nessus/349706 (CVE‑2026‑67238)
- https://www.tenable.com/plugins/nessus/349697 (CVE‑2026‑67219)
- Clop ransomware activity feed: https://cti.fyi/groups/clop.html
- Phishing‑detection bot (PhishDestroy) – each Mastodon post contains a link to the analysis page, e.g., https://phishdestroy.io/domain/variacharge.paytrakr.com/
These items represent the most critical, high‑severity vulnerabilities and active threat campaigns observed in the last 24 hours and should be prioritized for immediate remediation and monitoring.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster