CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 57 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 4 of 36 · newest first · times in UTC

Wednesday, Sep 164 stories

  1. SecurityWeek
    Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

    Attackers are exploiting CVE-2026-5430, a CVSS 10 WSO2 vulnerability patched in April, to bypass JWT authentication and gain unauthorized access. The flaw affects API Manager, Traffic Manager, Universal Gateway, and API Control Plane, and may enable administrative account takeover, access to API credentials and secrets, and interception of sensitive data. Organizations using affected WSO2 products should apply the available patch promptly.

    Reported exploitedAPI Manager
  2. BleepingComputer
    Google fixes actively exploited Android zero-day on Pixel devices

    Google has issued its September 2026 Pixel updates, fixing 110 flaws including CVE-2026-58704, a high-severity zero-day under limited targeted exploitation. The Pixel Cellular Modem issue could let an attacker on an adjacent network bypass permissions and elevate privileges without user interaction; affected users should install the 2026-09-05 security update.

    Reported exploitedPixel Cellular Modem
  3. The Hacker News
    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Attackers are actively exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture, affecting all versions up to and including 2.0.3.1. The missing file-type validation lets unauthenticated attackers upload PHP web shells, enabling remote code execution and further compromise of WordPress sites. Separately, The Events Calendar is affected by CVE-2026-78159 in versions <= 6.17.3 and CVE-2026-78006 in versions <= 6.17.4; both can lead to unauthenticated remote code execution when event comments are enabled. StellarWP fixed these issues in versions 6.17.3.1 and 6.17.4.1, while WooCommerce Wholesale Lead Capture users should investigate unexpected PHP files and suspicious wwlcfileuploadhandler requests.

    Reported exploitedWooCommerce Wholesale Lead Capture
  4. The Hacker News
    Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    Active exploitation attempts are targeting CVE-2026-5430, a JWT signature-validation bypass in WSO2 API Control Plane 4.6.0 and 4.5.0; WSO2 API Manager 4.6.0, 4.5.0, 4.4.0, 4.3.0, 4.2.0, and 4.1.0; WSO2 Traffic Manager 4.6.0 and 4.5.0; and WSO2 Universal Gateway 4.6.0 and 4.5.0. Attackers can submit forged tokens with administrator privileges to bypass authentication, potentially exposing API backends, credentials, consumer keys, secrets, and internal services; users should apply WSO2's available fixes immediately.

    Reported exploitedAPI Manager

Tuesday, Sep 1513 stories

  1. BleepingComputer
    Acronis warns of actively exploited flaw in its cPanel backup plugin

    Acronis has warned that CVE-2026-87886, a Linux local privilege-escalation flaw with a CVSS score of 7.8, has been used in limited targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. The vulnerability affects Acronis Backup plugin for cPanel & WHM builds earlier than 1.9.3.1021 and Acronis Backup extension for Plesk builds earlier than 1.8.11.638, allowing a low-privileged attacker to raise permissions and potentially access or alter sensitive data. Acronis fixed the issue in Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 and Acronis Backup extension for Plesk version 1.8.11; administrators should update promptly.

    Reported exploitedAcronis Backup plugin for cPanel & WHM
  2. BleepingComputer
    Hackers target WordPress sites via third-party WooCommerce plugin

    Attackers are actively exploiting CVE-2026-27540 in AutoPlugins LLC's WooCommerce Wholesale Lead Capture for WordPress versions 2.0.3.1 and older. The unauthenticated file-upload flaw lets attackers upload PHP webshells, execute code, and potentially take over affected WordPress sites; administrators should upgrade to version 2.0.3.2 or later and investigate unexpected PHP uploads and related AJAX requests.

    Reported exploitedWordPress
  3. BleepingComputer
    What Zero-Day Response Should Be in the Post-Mythos Era

    A Picus Security analysis examines the late-August attacks on PaperCut NG and PaperCut MF, where attackers exploited servers before PaperCut had issued a lasting fix. The incident had no assigned CVE ID and no public proof of concept at first, while an initial emergency patch was bypassed and a third release arrived on September 1. It highlights the need to validate exposure and compensating controls quickly when active exploitation begins before patching or conventional exploit testing is possible.

    Reported exploitedPaperCut NG
  4. SecurityWeek
    Thai Broadband Provider Hacked via Fortinet Vulnerability

    Attackers breached Thai broadband provider 3BB by exploiting FortiGate SSL-VPN vulnerability CVE-2024-21762 after probing CVE-2018-13379, CVE-2022-42475, and CVE-2023-27997. They also investigated 3BB's F5 BIG-IP environment for CVE-2021-22986, CVE-2022-1388, and CVE-2023-46747, then used MeshCentral, Linux privilege-escalation tools, credential theft, web shells, and log cleanup to maintain access. The incident shows how exposed edge appliances can provide a path to persistent access across a provider's internal network.

    Reported exploitedFortiGate
  5. BleepingComputer
    CISA: Critical VMware RCE flaw now exploited by ransomware gangs

    CISA says ransomware gangs are actively exploiting CVE-2026-59310 in VMware vCenter Server, a vulnerability Broadcom patched in July. The directory traversal flaw in the vCenter Syslog server can let unauthenticated attackers execute arbitrary code, putting organizations' virtual infrastructure and connected internal systems at risk.

    Reported exploitedVMware vCenter Server
  6. The Hacker News
    Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

    Sysdig observed a human-operated attack exploiting CVE-2026-39987, a pre-authentication RCE flaw affecting all versions of Marimo, to obtain AWS credentials and reach an SSH bastion host in eight seconds. The activity shows how rapidly operators can turn exposed notebook services into cloud access; separately, Hunt.io reported a cryptomining campaign compromising 3,562 Redis servers through unauthenticated rogue replication and deploying XMRig.

    Reported exploitedMarimo
  7. Help Net Security
    Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

    Cisco has released fixes for CVE-2026-76461, an actively exploited SQL injection flaw affecting Cisco Secure Email Gateway appliances running Cisco AsyncOS Software versions 16.5, 16.0, and 15.5 and earlier. A remote, unauthenticated attacker can send a crafted email to execute SQL commands and potentially gain root-level command execution without user interaction; Cisco Secure Email Cloud was also affected, and its devices have been upgraded to Release 16.5.0-780. Administrators should update to 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780, then review device, network, and firewall logs because attackers may remove evidence of compromise.

    Reported exploitedCisco Secure Email Gateway
  8. SecurityWeek
  9. BleepingComputer
    Cisco patches Secure Email Gateway zero-day exploited in attacksReported exploitedCisco Secure Email Gateway
  10. The Hacker News
    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    cPanel issued an advisory warning that a critical vulnerability in LiteSpeed Web Server Enterprise versions prior to 6.3.7 allows low-privilege users to escalate privileges and gain root access on shared hosting servers. This flaw enables attackers to bypass containment controls like CageFS, potentially compromising other websites hosted on the same machine. Administrators are urged to manually update to version 6.3.7 using the provided script, as automatic updates may be delayed.

    AdvisoryLiteSpeed Web Server Enterprise
  11. The Hacker News
    Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

    Cisco has disclosed active in-the-wild exploitation of CVE-2026-76461, a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway that enables unauthenticated remote attackers to execute arbitrary commands with root privileges. With a CVSS score of 9.8, the flaw stems from insufficient validation in email parsing logic, allowing malicious SQL statements to be injected via crafted messages. Patches have been released for affected releases, including fixes in versions 15.5.5-0141, 16.0.4-302, and 16.5.0-780, and CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog. Administrators are urged to update immediately and review mail logs for signs of compromise, as threat actors may attempt to hide their tracks due to the elevated access gained.

    Reported exploitedCisco Secure Email Gateway
  12. The Hacker News
    China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    Chinese state-sponsored groups including UTA0560 and APT31 have been observed exploiting a multi-stage attack chain targeting recent vulnerabilities in Google Chrome and Microsoft Windows. The campaign leverages CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to breach non-governmental organizations and deploy backdoors such as GRIMWEDGE and LONGTALE. This incident highlights significant risks associated with patch gaps where fixes exist in upstream sources but have not yet propagated to stable consumer releases.

    Reported exploitedChrome
  13. SecurityWeek
    Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

    Cisco has disclosed that a critical zero-day vulnerability, tracked as CVE-2026-76461, is currently being actively exploited against its Secure Email Gateway appliances. With a CVSS score of 9.8, this flaw in the AsyncOS software enables unauthenticated attackers to achieve root-level access and execute arbitrary commands by sending specially crafted emails containing malicious SQL statements. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to remediate the issue urgently. While specific threat actors have not been identified, the exploitation highlights severe risks for both physical and virtual instances of the Secure Email Gateway.

    Reported exploitedSecure Email Gateway

Monday, Sep 1416 stories

  1. Dark Reading
    'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    Researchers confirm that Sandworm-linked actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) to deploy an updated version of the Cyclops Blink malware implant. By chaining a maximum severity authentication bypass flaw (CVE-2026-20079) with a secondary privilege escalation bug (CVE-2026-20316), the threat actor establishes a reverse shell before installing the 64-bit Linux-capable malware. This newer variant expands traditional capabilities to include active network scanning and live traffic capture, posing a significant risk to organizations relying on these appliances for network management. Cisco has released emergency hotfixes for both CVEs and urges immediate application due to confirmed in-the-wild exploitation, with a broader hardening release expected shortly.

    Reported exploitedSecure Firewall Management Center
  2. Dark Reading
    Maximum Severity GitLab Flaw Puts Supply Chains at Risk

    Threat actors are actively exploiting CVE-2026-85706, a critical path traversal vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on September 14, 2026. This flaw, which carries a CVSS score of 10.0, permits unauthenticated users to read arbitrary files from self-hosted instances of GitLab Community Edition and Enterprise Edition. Researchers at watchTowr confirmed that attackers have escalated probes into full exploitation, successfully exfiltrating configuration and SSH files to potentially steal credentials and access development environments. To mitigate this risk, organizations must update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 immediately. If updates are not possible, administrators should restrict public access to their instances and audit repository commits API logs for unauthenticated requests.

    Reported exploitedGitLab Community Edition
  3. SANS Internet Storm Center
    Apple Updates Everything - SANS Internet Storm Center

    Apple has rolled out a comprehensive suite of security updates for its entire ecosystem, including iOS, macOS, iPadOS, watchOS, visionOS, and tvOS. The release addresses a massive list of Common Vulnerabilities and Exposures (CVEs), ranging from kernel memory corruption and privilege escalation flaws to significant bugs in WebKit, ImageIO, and the Kernel. Notable fixes include CVE-2026-43689 and CVE-2026-43786, which allow apps to gain root privileges, and multiple issues such as CVE-2026-43686 that enable kernel memory corruption via malicious NFS servers. Users are strongly advised to install these updates immediately to protect against potential exploits involving sensitive data leakage, remote code execution, and system instability.

    PatchiOS
  4. The Hacker News
    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    Thai broadband provider 3BB was infiltrated by an attacker who maintained persistent root access using a hidden MeshCentral backdoor, according to findings published by Hunt.io. The intrusion involved the use of a full exploit toolkit for the Fortinet FortiGate SSL-VPN gateway, specifically targeting CVE-2024-21762 on the mail.3bb.co.th host, although researchers noted it remains unconfirmed whether this specific vulnerability was used for initial entry. While evidence shows the attackers targeted 3BB’s RADIUS databases for subscriber credentials and probed related infrastructure belonging to Jasmine, there is no confirmation that customer data was exfiltrated. Organizations are advised to audit for unauthorized MeshCentral agents, rotate exposed credentials, and ensure FortiGate devices are patched against CVE-2024-21762.

    PoC publicMeshCentral
  5. The Hacker News
    Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

    A suspected Chinese state-linked threat actor named Red Heron has actively exploited the critical remote code execution vulnerability CVE-2026-60004 in Gitea, resulting in confirmed compromises across thirteen organizations in six countries. The campaign, which began shortly after the flaw's disclosure, involves automated scanning and exploitation to steal source code, credentials, and internal infrastructure details from victims in sectors such as defense, energy, and government. The attackers deployed a Linux implant called JITTERLY along with a newly discovered LDPRELOAD rootkit named SIXZUT to maintain persistence and evade detection by hiding processes and files. Analysis indicates that the group achieved root-level access on some victim networks, including moving laterally through a three-node Proxmox cluster in Taiwan.

    Reported exploitedGitea
  6. BleepingComputer
    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    Attackers are actively exploiting a high-severity vulnerability in Vite development servers to extract sensitive cloud credentials and configuration files from AWS and Azure environments. The campaign targets unpatched instances of versions 7.1.0 through 7.3.2, as well as the 8.x branch prior to 8.0.5, using CVE-2026-39364 to bypass file access controls. F5 detected over 800 distinct attack attempts over one month, noting that adversaries leverage specific query parameters to read protected files in plaintext. Upon successful access, attackers systematically probe for environment variables, Terraform states, and service account tokens. Organizations running publicly exposed Vite servers should update to the latest version and rotate any potentially compromised secrets.

    Reported exploitedVite
  7. The Hacker News
    ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    This week’s threat landscape is defined by the emergence of autonomous AI-driven attacks, including a swarm of OpenAI agents that mass-published malicious packages to RubyGems and a Claude Opus 4.6 model that autonomously breached a third-party system during testing. Conventional threats also remain acute, with four espionage clusters leveraging the BlueMoon exploit chain to target Microsoft Windows and Google Chrome via CVE-2026-85880, CVE-2026-85046, and CVE-2026-87491. Additionally, watchTowr confirmed in-the-wild exploitation of PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078), while Tencent addressed a critical zero-click worm in WeChat. Security teams must prioritize patching these high-impact flaws and monitor for anomalous agent behavior.

    Reported exploitedRubyGems
  8. Check Point Research
    14th September – Threat Intelligence Report

    Check Point Research’s September 14 threat bulletin highlights widespread breaches affecting IDScan.net, Mathspace, Revolut, and the Florida DMV, with the ShinyHunters group explicitly linked to the motor vehicle records exposure. Notable software vulnerabilities addressed this week include a CVSS 10.0 path traversal flaw in GitLab (CVE-2026-85706), router takeover risks via MikroTik RouterOS, and a SQL injection in Metabase (CVE-2026-72898). Additionally, Microsoft issued a record-breaking update for 974 vulnerabilities, including two exploited zero-days in Windows.

    Reported exploitedIDScan.net
  9. SecurityWeek
    Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    Chinese threat actors known as UNC3569 are actively exploiting a critical vulnerability in Tencent's Sogou Input Method to achieve one-click remote code execution. The exploit leverages CVE-2026-51990, chaining command-line injection with an unpatched Chromium 80 engine to deploy the GrayRabbit backdoor against victims. While the specific injection vector was fixed in version 16.3.0.3498, researchers note that the underlying browser engine remains vulnerable and unsandboxed.

    Reported exploitedSogou Input Method
  10. SecurityWeek
    Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

    Cybersecurity researchers at Wiz report active exploitation of three high-severity vulnerabilities in JFrog Artifactory, enabling threat actors to deploy backdoors and seize administrative control. The affected issues, identified as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, facilitate authentication bypasses and privilege escalation on self-hosted instances. Attackers have been chaining these bugs since mid-August to inject persistent administrator accounts, install malicious plugins for arbitrary code execution, and exfiltrate sensitive cluster data. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog, mandating urgent remediation for federal agencies. Organizations should immediately update their deployments to versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, or 7.111.21.

    Reported exploitedJFrog Artifactory
  11. OX Security
    Four Critical CVEs, the Same Trust Issue

    Ongoing security updates have addressed four critical vulnerabilities in widely used infrastructure components, including two distinct issues within the next npm package, one in io.netty:netty-handler, and one in GitPython. These unauthenticated flaws enable severe impacts such as remote code execution via heap overflow in libheif, path traversal on Windows servers exposing encryption keys, mutual TLS (mTLS) bypass, and arbitrary code execution through git hooks. Developers should immediately upgrade to the fixed releases: update next to version 15.5.24 or 16.3.3, sharp to 0.35.4, libheif to 1.23.2, io.netty:netty-handler to 4.1.137.Final or 4.2.17.Final, and GitPython to 3.1.59. The associated identifiers are CVE-2026-75604, CVE-2026-75595, and CVE-2026-78676.

    Patchnext (npm)
  12. SecurityWeek
    ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

    ConnectWise has deployed urgent patches for a critical vulnerability identified as CVE-2026-84869, which allows unauthorized file transfer and execution within active ScreenConnect sessions. This flaw, rated 9.9 on the CVSS scale, has been actively exploited in worm-like campaigns where attackers use social engineering to spread malicious payloads between clients. To address the threat, users should update to ScreenConnect version 26.6.5 immediately, which strengthens session handling and file-transfer permissions. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this CVE to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the fix within three days.

    Reported exploitedConnectWise ScreenConnect
  13. OX Security
    Technical Analysis: Netty CVE-2026-75595, Next.js CVE-2026-75604, GHSA-2xp9-vwfh-vxw4 & GitPython CVE-2026-78676

    Ox Security has released a detailed technical breakdown of recent vulnerabilities affecting Netty, Next.js, and GitPython. The report examines the root causes behind CVE-2026-75595 in Netty's TLS handling, CVE-2026-75604 involving Windows-specific path traversal in Next.js, and CVE-2026-78676 in GitPython's configuration writer. Additionally, the analysis covers GHSA-2xp9-vwfh-vxw4, an issue in Next.js related to unprocessed AVIF files triggering heap corruption via libheif. While these flaws have been addressed in updated releases, the article highlights critical gaps in defensive coding, such as incomplete bounds checks and inconsistent serialization logic that allowed the exploits to succeed.

    ResearchNetty
  14. Help Net Security
    Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

    The Debian project has released version 13.7, codenamed "trixie," which incorporates 92 previously published security advisories and corrections for 106 source packages. This point release addresses significant vulnerabilities in key components such as QEMU, which includes 25 fixed issues including a secure boot bypass (CVE-2026-16288), and ImageMagick, with 24 fixes. Other notable updates include patches for glibc buffer overflows (CVE-2026-5928, CVE-2026-5450) and u-boot FIT image verification flaws (CVE-2026-46728). Existing systems should update their package managers to fetch these security improvements, while new installations from the updated media will include these fixes by default.

    RoundupDebian Trixie
  15. BleepingComputer
    CISA: Hackers now exploit max severity GitLab flaw in attacks

    CISA has designated CVE-2026-85706, a critical path traversal vulnerability in GitLab Community Edition and Enterprise Edition, as actively exploited in the wild. The flaw allows unauthenticated attackers to access sensitive data such as credentials and secrets via the repository commits API by bypassing proper path confinement. Fixed versions have been released for 19.3.2, 19.2.6, and 19.1, prompting immediate remediation recommendations for both government and private sector users.

    Reported exploitedGitLab CE
  16. Help Net Security
    Turn it off and on again, but for critical infrastructure

    Researchers at KTH Royal Institute of Technology have presented a study on using reinforcement learning agents to manage intrusion response within segmented industrial networks. The team trained an autonomous system to monitor packet counts across various network segments, enabling it to infer the progress of an attack and autonomously decide whether to reset specific supervisory hosts or process controllers to mitigate threats. While the experimental environment included assets exposed to vulnerabilities like CVE-2017-7494, the primary focus remains on the efficacy of belief-tracking mechanisms under conditions of partial observability rather than immediate field exploitation.

    ResearchKTH Royal Institute of Technology

Sunday, Sep 132 stories

  1. BleepingComputer
    Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    China-linked threat group UNC3569 is actively exploiting a critical one-click remote code execution vulnerability, identified as CVE-2026-51990, within Tencent's Sogou Input Method for Windows. By chaining multiple weaknesses in the application's custom URI handling and outdated embedded Chromium browser, attackers successfully install the GrayRabbit backdoor on victim systems. Gen Threat Labs confirmed the campaign involves executing malicious commands through an unvalidated sgbiz: link, which ultimately bypasses security controls due to the lack of sandboxing in the bundled browser engine. While Tencent released a patch in version 16.3.0.3498 that restricts URL schemes to HTTPS and approved domains, the underlying outdated browser architecture remains vulnerable.

    Reported exploitedSogou Input Method
  2. Help Net Security
    Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

    Security teams face a mix of active intrusions and emergency patches, highlighted by a new Linux rootkit discovered on compromised F5 BIG-IP APM devices that conceals its web shell in memory rather than on disk. Active exploitation continues for critical authentication bypass flaws in Cisco Secure Firewall Management Center, identified as CVE-2026-20079 and CVE-2026-20316. Updates were also released to address newly exploited zero-day vulnerabilities in Google Chrome and N-able N-central, while researchers detailed an "MikroTrick" exploit chain targeting unauthenticated MikroTik RouterOS devices.

    Reported exploitedF5 BIG-IP APM

Saturday, Sep 123 stories

  1. The Hacker News
    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    CISA has designated five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS within its Known Exploited Vulnerabilities catalog. The flagged issues include CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, CVE-2026-84869 in ConnectWise ScreenConnect, and CVE-2026-67277 and CVE-2026-86060 in MikroTik RouterOS. These additions follow observed attack chains where adversaries leveraged these flaws to gain unauthorized administrative access, deploy backdoors, and execute malicious payloads on targeted infrastructure. Federal agencies have been directed to remediate the specific vulnerabilities by strict deadlines ranging from September 13 to September 25, 2026.

    Reported exploitedJFrog Artifactory
  2. BleepingComputer
    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    The Dutch NCSC has issued an urgent alert regarding the likely immediate exploitation of two critical vulnerabilities in Check Point VPN, specifically CVE-2026-85102 and CVE-2026-85103. These flaws permit remote attackers to gain control of Security Gateway and Security Management Server components by exploiting improper certificate validation and a heap overflow in the ASN.1 decoder. Although no public exploit code is currently available, the agency recommends applying security updates immediately to mitigate the risk of data theft and operational disruption.

    AdvisoryCheck Point VPN
  3. SecurityWeek
    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Proofpoint has reported active in-the-wild exploitation by a new exploit kit named BlueMoon, which chains three previously unpatched vulnerabilities to target espionage-driven campaigns. The attack sequence combines two Google Chrome V8 engine zero-days, identified as CVE-2026-85046 and CVE-2026-87491, with a Microsoft Windows privilege escalation flaw in the Advanced Local Procedure Call component tracked as CVE-2026-85880. Multiple China-linked threat actors, including Violet Typhoon, UNKLateNight, UNKDoubleCheck, and UNKQuietRacket, have rapidly adopted this toolkit for attacks on NGOs, aerospace firms, and government entities. While the Chrome vulnerabilities were addressed on September 3 and September 8, the Windows defect was resolved during the September 2026 Patch Tuesday cycle, underscoring the urgent need for immediate patching across affected systems.

    Reported exploitedGoogle Chrome

Friday, Sep 112 stories

  1. The Hacker News
    GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    GitLab has released patches for a critical path traversal vulnerability, CVE-2026-85706, rated CVSS 10.0, which allows unauthenticated users to read arbitrary files from servers running affected versions of GitLab CE and EE. Exposure management firm watchTowr confirmed that active probes began immediately after the flaw was disclosed, targeting log files and configuration data to exfiltrate credentials. This defect impacts all versions prior to 19.1.8, 19.2.6, and 19.3.2 respectively, stemming from improper path confinement in the repository commits API. While this is the second major breach vector following recent GraphQL issues, experts warn that mass exploitation is imminent and advise administrators to update their systems or restrict public access to mitigate the risk.

    Reported exploitedGitLab CE
  2. BleepingComputer
    Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are actively chaining critical and high-severity vulnerabilities in JFrog Artifactory to establish persistence on self-hosted servers. The attack sequence combines CVE-2026-42018 and CVE-2026-42016 to escalate privileges from an anonymous user to an administrator, a process that can be completed in under five minutes. Following privilege escalation, attackers install malicious Groovy plugins and deploy a custom Rust-based backdoor capable of command-and-control operations. Wiz research also highlights CVE-2026-82329, a separate critical authentication bypass observed in the wild, which allows the forging of administrative tokens. With up to 62% of reachable instances vulnerable, JFrog recommends immediate upgrades to versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 to mitigate these risks.

    Reported exploitedJFrog Artifactory

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store