This week’s summary focuses on active exploitation of CVE-2026-94127, a critical zero-day vulnerability affecting F5 BIG-IP Access Policy Manager. In certain configurations, the flaw could allow unauthenticated attackers to execute code on systems that manage access to enterprise applications. F5 has released hotfixes and a temporary mitigation.
The report also covers critical VeloCloud Orchestrator and Check Point vulnerabilities, ransomware activity linked to Storm-2570, and North Korean targeting of developers.