The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.

Critical vulnerabilities have been reported in the Belgian eID software, a system utilized by an estimated two million individuals. These flaws reportedly impact applications across a significant portion of Belgium's financial sector, specifically affecting software used by eight of the ten largest banks, as well as over 60 government agencies. The widespread adoption of this software suggests a potentially broad exposure to the identified security issues.
The nature of "critical flaws" in eID software typically implies vulnerabilities that could lead to severe consequences, such as unauthorized access to personal data, identity theft, or the forging of digital identities. Such systems are designed to provide secure authentication and digital signatures, making any compromise a serious concern for both individual users and the integrity of digital transactions and government services. Without specific technical details, it is difficult to pinpoint the exact mechanism of these flaws, but they often involve weaknesses in cryptographic implementations, secure key storage, or the authentication protocols themselves.
eID systems, like the Belgian one, commonly rely on a combination of smart card technology, specialized card readers, and client-side software to function. The reported vulnerabilities could reside in any of these components, from the drivers for the card readers to the core application logic that processes digital certificates and user authentication requests. Flaws in such software could potentially allow attackers to bypass authentication mechanisms, elevate privileges, or even remotely execute malicious code on systems where the eID software is installed.
The scope of this issue is notable due to the reported adoption by major financial institutions and numerous government entities. Products in this category are often integrated deeply into critical infrastructure, meaning that a compromise could have cascading effects beyond individual user accounts. For banks, this could mean risks to online banking transactions, while for government agencies, it could impact the security of citizen services and sensitive data access.
Typical mitigation guidance for vulnerabilities in eID software generally involves immediate patching of the affected software. Users are usually advised to ensure their eID software is updated to the latest version as soon as a fix is released by the vendor. Additionally, organizations using such software in their infrastructure are often recommended to conduct thorough security audits, implement multi-factor authentication where possible, and monitor for any suspicious activity that might indicate exploitation of the vulnerabilities.
The discovery of critical flaws in national eID software underscores the ongoing challenges in securing digital identity systems. As societies increasingly rely on digital platforms for banking, government services, and personal identification, the integrity and resilience of these foundational technologies become paramount. This incident highlights the continuous need for rigorous security testing, prompt vulnerability disclosure, and efficient patch management within critical digital infrastructure.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.