vulnerability news
549 stories · page 3 of 12
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft has reportedly addressed 18 vulnerabilities spanning its Azure and AI-branded product lines. The majority of these patched flaws were identified as privilege escalation vulnerabilities, indicating a focus on issues that could allow an attacker to gain elevated access within affected systems.

AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom
A zero-click remote code execution (RCE) vulnerability, dubbed “Plugin4Shell,” has been identified in several prominent AI coding agents, potentially allowing attackers full access to data and assets reachable by the compromised agent. The flaw affects Anthropic’s Claude Code, OpenAI’s Codex, Google's Gemini CLI, Microsoft’s Copilot, and Microsoft-owned GitHub Copilot.

Cisco alerts customers to second actively exploited zero-day in as many days
Cisco has issued an alert to customers regarding a second actively exploited zero-day vulnerability discovered within days, affecting its Identity Services Engine (ISE) product. The flaw, identified as CVE-2026-76460, carries a maximum severity rating of 10.0 and was exploited in the wild prior to Cisco's disclosure and subsequent patch release on Wednesday, September 17, 2026.

Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has issued an urgent warning regarding a maximum-severity zero-day vulnerability in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products, which is actively being exploited in the wild. The flaw, identified as CVE-2026-76460, allows remote attackers to bypass authentication by exploiting an API weakness, regardless of the system's configuration.

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Cisco has released an emergency security patch for a zero-day vulnerability affecting its Identity Services Engine (ISE) product, following reports of active exploitation. The flaw allows remote, unauthenticated attackers to bypass authentication mechanisms by sending specially crafted requests to affected ISE instances. This critical update addresses a significant security risk given the…

First Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulatory authorities have reportedly received a notification concerning what is being described as the first agentic AI data breach. The incident involved an artificial intelligence agent that autonomously executed a sequence of actions, including a successful login, the discovery of a vulnerability, and subsequent access to personal data. This event is being highlighted as a…

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Attackers are actively exploiting a critical vulnerability in the Issabel Framework, a web-based component of the open-source unified communications PBX software. This flaw, identified as CVE-2026-89026, allows for unauthenticated remote operating system (OS) command execution, posing a significant risk to affected systems.

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has released a security update addressing a high-severity vulnerability in its Pixel Cellular Modem, acknowledging that the flaw has been exploited in limited, targeted attacks in the wild. The issue, identified as CVE-2026-58704, carries a CVSS score of 8.0, indicating a significant risk.

DeepZero: Open-source hunting for vulnerable Windows drivers
DeepZero, an open-source engine designed to automate the discovery of exploitable vulnerabilities in Windows kernel drivers, has identified multiple confirmed flaws within a subset of the Snappy Driver Installer corpus. Some of these findings are reportedly still undergoing the disclosure process. The project, maintained by Rehman Ahmadzai, is available for free on GitHub.

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
Apple has released a substantial security update across its operating systems and software, addressing over 260 Common Vulnerabilities and Exposures (CVEs). This marks the largest single patch cycle in the company's history. While no vulnerabilities are currently reported as being under active exploitation, the disclosure of these flaws often prompts attackers to attempt to exploit them.

Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis has issued a warning about a high-severity local privilege escalation vulnerability, identified as CVE-2026-87886, affecting its backup plugins for cPanel & WHM and Plesk. The company states that this flaw is being actively exploited in targeted attacks.

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs
Oracle released its September 2026 Critical Security Patch Update (CSPU) on September 15, addressing 672 unique Common Vulnerabilities and Exposures (CVEs) through 673 security updates across 17 product families. This monthly release cycle, introduced in May 2026, aims to provide a faster cadence for high-severity issues compared to the quarterly Critical Patch Updates (CPUs).

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Email Gateway, identified as CVE-2026-76461, to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that federal civilian executive branch (FCEB) agencies address the flaw by September 17, 2026, to protect their networks from active exploitation.

Hackers target WordPress sites via third-party WooCommerce plugin
Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, enabling them to upload PHP backdoors to compromised sites. The flaw, identified as CVE-2026-27540, affects plugin versions 2.0.3.1 and older.

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has confirmed a data breach that potentially exposed personal information for approximately 246,000 individuals, primarily government employees and associated personnel. The breach originated from an exploited vulnerability in a VPN device utilized by the Government Solution Service (GSS).

Maximum Severity GitLab Flaw Puts Supply Chains at Risk
A critical path traversal vulnerability, identified as CVE-2026-85706, has been reported in GitLab, impacting both its Community Edition (CE) and Enterprise Edition (EE) instances. The flaw carries a maximum CVSS score of 10.0, indicating its severe potential for exploitation and the significant risk it poses.

Hackers Exploit Maximum Severity Flaw in GitLab
GitLab has urged users to patch a critical vulnerability, identified as CVE-2026-85706, following reports of active exploitation. The flaw, described as an "improper limitation of a pathname to a restricted directory" or "path traversal," affects all versions of GitLab CE/EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

AWS puts AI vulnerability detection to the test, and false positives pile up
Amazon Web Services (AWS) has introduced a new benchmark designed to evaluate how effectively artificial intelligence models can differentiate between genuine security vulnerabilities and code that merely appears risky but is actually safe. The "Deception Benchmark" aims to address the challenge of high false-positive rates in AI-driven vulnerability detection, which can lead to increased…

Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors identified as UNC3569, a group suspected of operating on behalf of China, have been observed actively exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows. The flaw, tracked as CVE-2026-51990, is a one-click remote code execution (RCE) vulnerability that allows attackers to deploy the GrayRabbit backdoor.

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
GitLab has confirmed that a critical path traversal vulnerability, identified as CVE-2026-85706, is being actively exploited in the wild, with initial probes detected within 24 hours of its public disclosure. The flaw, which carries a CVSS score of 10.0, affects the repository commits API in GitLab Community Edition and Enterprise Edition.

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Attackers have deployed a Linux rootkit on F5 BIG-IP APM devices, utilizing a method that hides a web shell in memory rather than writing it to disk. This technique makes detection more challenging for traditional security tools. F5 BIG-IP APM is a system designed for enforcing access policies.

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) has issued a warning regarding the imminent exploitation of two critical vulnerabilities in Check Point VPN products, identified as CVE-2026-85102 and CVE-2026-85103. The agency has assessed the likelihood of exploitation and the potential impact as high, urging organizations to apply security updates promptly.

Critical GitLab Vulnerability Exploited in Internet-Wide Probes
GitLab has released emergency patches for two high-severity vulnerabilities in its software development platform, one of which carries the maximum possible severity score and is already being actively probed by attackers across the internet. The company urged operators of self-managed installations to upgrade immediately, while confirming its own hosted service and single-tenant Dedicated…

More JFrog Artifactory bugs under attack, and all 3 have patches
Multiple attackers are actively exploiting three recently patched vulnerabilities in JFrog Artifactory, gaining administrative control over vulnerable instances and subsequently installing malicious plugins and backdoors. The affected party, JFrog, has not publicly commented on these attacks, but security researchers have confirmed in-the-wild exploitation across various environments.

Metasploit Wrap Up: This One Goes to Sixteen!
A recent update to the Metasploit framework has introduced sixteen new modules, including ten exploit modules, five of which address vulnerabilities listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The new exploits target products from Cisco, PaperCut, SonicWall, JetBrains, and Langflow, among others.

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Canonical has released Ubuntu 24.04.5 LTS, an update to its Noble Numbat long-term support distribution, which integrates security updates and stability fixes directly into new installation media. This point release aims to reduce the number of post-installation updates for new deployments.

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is now being exploited by ransomware groups. CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, at which point it was already being actively exploited.

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software. The flaw, which carries a maximum CVSS score of 10.0, allows unauthenticated, remote attackers to execute scripts and commands with root privileges on affected devices by sending specially crafted HTTP requests to the web interface.

Scans for Proxmox Servers, (Wed, Sep 9th)
Reports indicate that threat actors have begun actively scanning for Proxmox Virtual Environment (VE) servers, following the recent disclosure of a vulnerability in older versions of the platform. The scans specifically target Proxmox VE version 7, a version that has reached its end-of-life and is no longer officially supported by the vendor.

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Fortinet has released patches addressing critical vulnerabilities found in its FortiMonitorOnSight product and a related Chrome extension. The reported flaws are described as critical and unauthenticated, enabling attackers to bypass authentication mechanisms and potentially proxy a user's browser traffic.

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google has reportedly issued an urgent update for its Chrome browser, addressing a critical zero-day vulnerability that has been actively exploited in the wild. The flaw, identified as an out-of-bounds write bug within the V8 JavaScript and WebAssembly engine, allows for code execution within the browser's sandbox environment. This update is part of a broader patch release addressing numerous…

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Microsoft's September 2026 Patch Tuesday release included a record number of fixes, addressing two zero-day vulnerabilities that have been actively exploited in the wild. The update also contained patches for several other critical issues, including a cluster of 20 "wormable" bugs and a DNS flaw described as a successor to SigRed.

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
A critical pre-authentication remote code execution (RCE) vulnerability affecting N-able N-central has been observed under active exploitation in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies patch affected systems by September…

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Microsoft has released its monthly Patch Tuesday security update, addressing a record 974 vulnerabilities across its product suite. This extensive update includes fixes for two actively exploited zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, both of which allow for privilege escalation and have a CVSS rating of 7.8.

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security updates for September 2026, addressing a total of 973 vulnerabilities across its product line. Among these, 113 were classified as "critical." The company confirmed that two of these vulnerabilities have already been exploited in the wild.

Microsoft Plugs Nearly 1,000 Security Holes
Microsoft has released an unprecedented number of security updates, addressing 974 vulnerabilities across its Windows operating systems and other software. This marks the largest single patch batch in the company's history, significantly surpassing the previous record of 570 fixes issued in July. The total number of vulnerabilities patched by Microsoft in 2026 has now exceeded 2,600, more than…

Themeum Tutor LMS Vulnerability Exploited Same Day as Disclosure
A critical vulnerability in the Themeum Tutor LMS plugin was exploited on the same day its CVE was published, leaving no patch window for users. The flaw is listed in VulnCheck's Known Exploited Vulnerabilities catalogue.

TranslatePress Flaw Exploited Before CVE Published
A critical vulnerability in the TranslatePress WordPress plugin was exploited before its official CVE publication date, leaving no patch window for administrators.

Mathspace breach exposes data on over a million students and parents
Mathspace, an Australian educational technology company, has confirmed a data breach affecting over one million students, parents, and school staff in Australia and New Zealand. The company stated that an unpatched vulnerability in its self-hosted Metabase internal reporting system allowed unauthorized parties to gain administrator access and exfiltrate data.

GeoTools SQL Injection Flaw Exploited Same Day as Disclosure
A critical SQL injection vulnerability in GeoTools was exploited on the same day it was publicly disclosed, leaving no patch window for affected users. The flaw impacts versions prior to 33.6, 34.5, and 33.6.

TYPO3 Powermail Extension Exploited Same Day CVE Published
CVE-2026-77136, a template engine vulnerability in TYPO3's Powermail extension, was reportedly exploited on the same day its CVE record was published. No patch window existed.

CVE-2024-58374: Hongjing e-HR SQL Injection Exploited on Disclosure Day
A critical SQL injection vulnerability in Hongjing Century e-HR was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.

Ruijie Networks Routers Exploited Same Day CVE-2023-7330 Was Published
CVE-2023-7330, an unrestricted file upload vulnerability in Ruijie Networks NBR Series Routers, was exploited on the same day it was disclosed, leaving no patch window.

Proxmox VE Auth Bypass Exploited Same Day as Disclosure
CVE-2023-54391, a critical authentication bypass in Proxmox VE, was exploited on the same day it was published, leaving no patch window. The vulnerability affects end-of-life versions.

ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has issued a warning regarding a newly identified vulnerability in its ScreenConnect remote access platform, affecting both cloud and on-premises deployments. The company has not yet assigned a CVE ID to this flaw but has provided temporary mitigation steps while it develops a permanent patch, expected later this week.

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
MikroTik has issued an urgent advisory for its RouterOS, confirming active exploitation of a critical vulnerability chain, dubbed "MikroTrick," that allows unauthenticated attackers to gain full control of devices with SSH exposed to the internet. The company released patches on September 3, 2026, but evidence suggests exploitation began as early as September 2, making it a zero-day event.