Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Microsoft has reportedly issued its monthly security updates, addressing a substantial number of vulnerabilities, including a Windows kernel driver zero-day that is actively being exploited in the wild. This critical flaw is said to be present in a core Windows kernel driver responsible for managing network socket operations. The update package reportedly includes patches for 398 distinct vulnerabilities across various Microsoft products and services.
The zero-day vulnerability, identified as CVE-2026-68820 with a CVSS score of 7.0, is described as a privilege escalation flaw. It allows an attacker who has already established a foothold on a compromised system to elevate their privileges to SYSTEM level. This level of access grants an attacker extensive control over the operating system, potentially enabling them to install programs, view, change, or delete data, and create new accounts with full user rights.
The affected component is a fundamental Windows kernel driver, indicating its deep integration within the operating system's core functionalities. Kernel drivers operate at a highly privileged level, making vulnerabilities within them particularly dangerous as they can bypass many standard security controls. The specific function involved, network socket operations, suggests that the flaw could be triggered during network-related activities or by manipulating how the system handles network connections.
For this class of privilege escalation vulnerability, the typical attack vector involves an initial compromise through another means, such as phishing, exploiting a different application vulnerability, or social engineering. Once an attacker has user-level access, they can then leverage the kernel driver flaw to gain SYSTEM privileges. This "post-exploitation" phase is a common objective for adversaries seeking to establish persistent access and control over a target machine.
Mitigation for such issues generally involves prompt application of vendor-supplied security patches. Organizations are advised to prioritize the deployment of updates that address actively exploited vulnerabilities. Beyond patching, implementing a defense-in-depth strategy is crucial, which includes endpoint detection and response (EDR) solutions, robust network segmentation, least privilege principles for user accounts, and regular security awareness training to prevent initial compromises.
The discovery and active exploitation of a Windows kernel driver zero-day underscore the persistent threat landscape faced by users of widely adopted operating systems. Such flaws are highly prized by attackers due to their potential for significant impact and their ability to bypass traditional security measures. The rapid release of a patch by Microsoft highlights the urgency associated with addressing vulnerabilities that are actively being leveraged in real-world attacks, emphasizing the critical importance of timely patching for maintaining system security.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.