Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…
Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete.
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of…
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 974 különböző biztonsági hibát javított, köztük 2 db nulladik napi (zero-day) sebezhetőséget is, amelyet a Microsoft […]
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.2, CVEs: CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060, CVE-2026-67277, CVE-2026-67276, Summary: MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. There is evidence that these vulnerabilities are under active exploitation. This is an important security update. Most configurations are not at risk, but upgrading is highly…
CISA added CVE-2025-25249 to the Known Exploited Vulnerabilities catalog. Affected product: Fortinet Multiple Products. Remediation due date: 2026-09-12.
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and…
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will…
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS. A few vulnerabilities worth mentioning: Windows Update Stack…
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August…
Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should…
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain…
Serial Number: AV26-888Date: September 8, 2026 As of September 7, 2026, Adobe is affected by a vulnerability in the following products: Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Magento Open Source All except Hotfix for…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…
MikroTik heeft meerdere kwetsbaarheden verholpen in RouterOS. De eerste kwetsbaarheid betreft een fout in de SSH-authenticatiemechanisme waarbij de exponent van RSA-sleutels niet werd geverifieerd. Hierdoor kunnen aanvallers RSA-handtekeningen vervalsen en ongeautoriseerde SSH-toegang verkrijgen. De tweede kwetsbaarheid betreft een probleem met gebruikersnamen die beginnen met een verboden teken, waardoor de trusted policy mask kan worden gemanipuleerd en privilege escalation mogelijk is binnen…
Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]
N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…
Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred útokmi na smerovače značky MikroTik. Útočníci zreťazením bezpečnostných zraniteľností operačného systému MikroTik RouterOS dokážu získať úplnú kontrolu nad zariadením bez potreby autentifikácie. MikroTik routre sú sieťové zariadenia vyrábané spoločnosťou MikroTik a využívajú vlastný operačný systém RouterOS. Využívané sú poskytovateľmi internetových služieb, v komerčnej sfére a rovnako aj v domácnostiach.... The post VAROVANIE:…
Upozorňujeme na zranitelnost ve firmware RouterOS v zařízeních MikroTik, kterou lze před autentizací zneužít k vzdálenému spuštění kódu s administrátorskými oprávněními. Aktuálně dochází k masovému zneužití této zranitelnosti. Dne 4. září 2026 byla vydána aktualizace RouterOS, v současnosti jsou však na internetu v ČR stále vystaveny tisíce zranitelných zařízení. Útočníci navíc u napadených zařízení upravují konfiguraci, aby si zajistili trvalý přístup k zařízení, který přežije jakoukoli…
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. The patch will attempt to detect compromise and set the "Flagged" status. Details: https://mikrotik.com/supportsec/september-2026-vulnerability -- Johannes B. Ullrich, Ph.D. , Dean of…
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]
Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…
SonicWall heeft kwetsbaarheden verholpen in de SMA1000 Appliance. De SMA1000 Appliance bevat twee kwetsbaarheden. De eerste is een pre-authenticatie Server-Side Request Forgery (SSRF) in de Work Place interface, waarmee een externe, niet-geauthenticeerde aanvaller ongeautoriseerde acties kan uitvoeren. De tweede kwetsbaarheid betreft post-authenticatie remote code execution, waarbij een aanvaller met geldige inloggegevens willekeurige code op afstand kan uitvoeren. Beide kwetsbaarheden zijn als…
CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.
CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Zimbra Collaboration Suite (ZCS) szoftvert érintő, CVE-2026-73570 azonosítón nyomon követett kritikus sérülékenység kapcsán. Intézetünkhöz megnövekedett számú bejelentés érkezett a CVE-2026-73570 sérülékenység aktív kihasználásáról. A sebezhetőség kihasználása hitelesítés nélküli támadók számára távoli kódfuttatást tehet lehetővé. A sérülékenység a Zimbra SNMP-monitorozási komponensét érinti, és akkor használható…
Disponibili Proof of Concept (PoC) per lo sfruttamento di 2 vulnerabilità, già sanate dal vendor, che interessano Next.js, noto framework javascript per la creazione di applicazioni web.
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…
A supply chain worm was found hiding in @7nohe/openapi-react-query-codegen, a popular code generator for TanStack Query, stealing credentials and spreading itself to every package the victim maintains. Category: Vulnerabilities & Threats
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]