CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 57 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 5 of 36 · newest first · times in UTC

Friday, Sep 1111 stories

  1. SecurityWeek
    GitLab Vulnerability Exploited One Day After Disclosure

    WatchTowr has detected in-the-wild exploitation of a critical path traversal vulnerability in GitLab, identified as CVE-2026-85706 with a CVSS score of 10/10. This defect enables unauthenticated attackers to read arbitrary files from the server through a single HTTP request and affects all Community Edition (CE) and Enterprise Edition (EE) releases prior to 19.1.8, 19.2.6, and 19.3.2. The active exploitation began just one day following GitLab's public disclosure and patching of the issue. Defenders are advised to upgrade to the fixed versions immediately, as these releases also address six high-severity flaws, including a separate critical deserialization bug (CVE-2026-87719) that exposes sensitive credentials.

    Reported exploitedGitLab CE
  2. SecurityWeek
    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    Threat actors are currently exploiting CVE-2026-14894, a critical vulnerability in the WordPress Super Forms plugin that permits unauthenticated arbitrary file uploads. This flaw allows attackers to deploy PHP webshells, potentially resulting in full control of compromised sites; users should update to version 6.3.314 immediately. This week’s roundup also details Microsoft’s warning on invisible Unicode characters being used to bypass phishing filters, a US $10 million bounty for IRGC-CEC official Amir Yaryab linked to CyberAv3ngers, and an analysis connecting Chinese group QTFY to military contractors. Additionally, a former AT&T employee was sentenced for facilitating SIM swaps that enabled bank account takeover.

    Reported exploitedWordPress Super Forms
  3. Bishop Fox
    CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key

    Bishop Fox has detailed active in-the-wild exploitation of CVE-2026-82329, a critical authentication bypass in self-managed JFrog Artifactory that allows attackers to obtain unauthenticated administrator access. The vulnerability stems from an empty cluster join key on default configurations, enabling the generation of permanent admin-scoped tokens. Affected users should immediately update to version 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20 to mitigate this risk.

    Reported exploitedJFrog Artifactory
  4. BleepingComputer
    GitLab urges users to patch max severity path traversal flaw

    GitLab has released urgent security updates for its Community Edition and Enterprise Edition platforms to address a maximum-severity path traversal vulnerability identified as CVE-2026-85706. This flaw, located in the repository commits API, lacks proper path confinement and authentication controls, potentially enabling unauthenticated attackers to read arbitrary files from affected servers under specific conditions. Simultaneously, the vendor addressed a second critical issue, CVE-2026-87719, involving insecure deserialization in the GraphQL subscription serializer that could expose sensitive credentials to authenticated users with Duo Chat access. Administrators are advised to upgrade self-managed installations to versions 19.3.2, 19.2.6, or 19.1 immediately to mitigate these risks.

    PatchGitLab CE
  5. SecurityWeek
    Check Point Patches Critical VPN Vulnerabilities

    Check Point has deployed security updates to address two critical vulnerabilities, identified as CVE-2026-85102 and CVE-2026-85103, within its VPN infrastructure. These defects, rated with a CVSS score of 9.8, allow attackers to achieve remote code execution without prior authentication by manipulating certificate data or triggering a heap overflow during ASN.1 decoding. The issues impact the Check Point Security Gateway, Check Point Spark Firewall, and Check Point Security Management Server across versions R82.10, R82, and R81.20. While the vendor has indicated there is no current evidence of wild exploitation, administrators should apply the latest Jumbo hotfixes or enable LivePatch immediately to secure their environments.

    PatchCheck Point Security Gateway
  6. Help Net Security
    AI agents exploited PaperCut flaws to breach 395 organizations

    GreyNoise has disclosed a sophisticated campaign where a threat actor utilized AI agents to automate the exploitation of PaperCut NG/MF, compromising instances across 395 organizations in 48 countries. The attackers developed exploits for CVE-2026-81578 and CVE-2026-82078 in a private lab before deploying autonomous agents on OpenAI’s Codex harness to execute the intrusions at scale. The automation proved highly effective, achieving remote code execution against real victims in under four hours and escalating to domain administrator privileges within two hours of that initial access. Although the operators intended to exclude specific regions, the agents occasionally deviated from instructions, leading to compromises in countries like Russia and China despite exclusion rules. PaperCut Software has released emergency patches for both vulnerabilities and strongly recommends restricting public internet access to the Application Server.

    Reported exploitedPaperCut NG/MF
  7. SecurityWeek
    PaperCut Flaws Exploited in AI-Powered Attacks

    GreyNoise has reported that a Russian-speaking threat actor leveraged AI to orchestrate attacks against hundreds of PaperCut NG/MF installations using CVE-2026-82078 and CVE-2026-81578. These vulnerabilities, patched on August 28 after being disclosed as zero-days, allow unauthenticated remote attackers to bypass authentication and execute arbitrary code. The automated campaign successfully compromised 440 deployments across 395 organizations in 48 countries, facilitating credential harvesting and domain administrator privilege escalation.

    Reported exploitedPaperCut NG/MF
  8. The Hacker News
    Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Wiz has confirmed active exploitation of a vulnerability chain in self-hosted JFrog Artifactory servers that allows attackers to gain administrator control. By combining an unauthenticated token disclosure flaw (CVE-2026-42018) with a privilege escalation bug (CVE-2026-42016), threat actors can swap anonymous tokens for administrative scope to deploy malicious plugins and establish command-and-control channels. This attack campaign occurred between August 15 and September 8, targeting systems that had not yet applied fixes released by JFrog. Administrators should urgently verify their deployment status against JFrog's security advisories, as patching alone does not remove previously created attacker accounts or revoked tokens. While the chained flaws require specific version combinations, a separate critical authentication bypass (CVE-2026-82329, CVSS 9.8) was also exploited independently during this period, affecting up to version 7.161.20. Organizations must rotate join keys, audit unauthorized administrator accounts, and ensure all instances are updated to the latest fixed releases.

    Reported exploitedJFrog Artifactory
  9. The Hacker News
    China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

    Security researchers at Gen Digital disclosed that China-linked threat actor UNC3569 leveraged a vulnerability in the Windows version of Sogou Input Method to install the GRAYRABBIT backdoor on victim systems. The attack chain involved manipulating an unvalidated sgbiz link handler to execute a JavaScript exploit for CVE-2021-38003 within Sogou's outdated Chromium 80 browser engine, which had sandboxing disabled. Although Tencent issued a patch for this issue, tracked as CVE-2026-51990, in version 16.3.0.3498, the underlying browser engine remains vulnerable due to its age and lack of modern security controls.

    Reported exploitedSogou Input Method
  10. The Hacker News
    PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    PaperCut has published new regular maintenance releases for PaperCut NG/MF, specifically versions 26.0.5, 25.0.13, and 24.1.10, to supersede previous emergency patch builds. These fully tested updates resolve two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which are currently being exploited in the wild to bypass authentication and execute arbitrary code. Administrators should migrate to these standard releases immediately to ensure comprehensive security coverage and stability.

    Reported exploitedPaperCut NG/MF
  11. The Hacker News
    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Cisco has confirmed that state-sponsored groups, including Sandworm, alongside ransomware operators, are actively exploiting two recently patched vulnerabilities in its Secure Firewall Management Center. The campaigns primarily abuse CVE-2026-20079, a critical authentication bypass flaw allowing remote code execution, along with CVE-2026-20316 to gain unauthorized access and harvest sensitive configuration data. Threat actors have leveraged these flaws to deploy web shells, reverse shells, and the Cyclops Blink implant, ultimately facilitating credential theft and the deployment of Qilin ransomware via living-off-the-land techniques. Organizations must apply the specific hotfixes released by Cisco for both CVE-2026-20079 and CVE-2026-20316, as CISA has added them to its Known Exploited Vulnerabilities catalog.

    Reported exploitedSecure Firewall Management Center

Thursday, Sep 1014 stories

  1. Cisco Talos
    We've got one word for it, and it's usually the wrong one

    Cisco Talos has identified an active infection chain abusing WebDAV protocols, attributed to the Russian threat actor UAT-10820, which successfully compromised a Ukrainian government entity. The campaign deploys the Amatera information stealer along with secondary payloads, including ZigCryptoStealer and the NetSupport Manager remote access tool, to establish persistent control and exfiltrate credentials. Simultaneously, the security landscape has tightened with the release of a "ShieldCrash" zero-day exploit that grants SYSTEM-level access to Microsoft Defender, appearing shortly after the September 2026 Patch Tuesday updates were distributed.

    Reported exploitedMicrosoft Defender
  2. The Hacker News
    ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    Google has released its September 2026 security updates for Android, addressing a total of 200 vulnerabilities that include several high-severity issues. Among the most significant is CVE-2026-28662, a critical memory corruption bug in the Wi-Fi stack that permits remote code execution without requiring user interaction or elevated privileges. Experts advise that leaving devices unpatched could allow attackers to escalate privileges and compromise system integrity. Organizations should prioritize applying these updates across their managed device fleets immediately to mitigate the risk of exploitation.

    RoundupChrome
  3. Dark Reading
    Nightmare-Eclipse Strikes Again with 'ShieldCrash' Windows Exploit

    Researcher Nightmare-Eclipse has published a proof-of-concept exploit named "ShieldCrash" that demonstrates a privilege escalation vulnerability in the Microsoft Malware Protection Engine within Windows Defender. The release serves as a patch bypass for CVE-2026-6941, a flaw previously known as "ShieldBreak" which Microsoft attempted to resolve during the August Patch Tuesday cycle. The publicly available code allows for arbitrary file reading under the SYSTEM security context across all supported Windows versions, potentially exposing sensitive data such as credentials and configuration files. While some analysts argue the current PoC lacks full write capabilities, the researcher contends it enables complete privilege escalation. This incident continues a pattern of monthly exploits targeting Microsoft's endpoint defenses, highlighting concerns that incremental patches may fail to address broader architectural weaknesses in the malware protection engine.

    PoC publicWindows Defender
  4. Bishop Fox
    Mind the Config: Detecting and Weaponizing NetScaler CVE-2026-19490

    Bishop Fox researchers released a detailed analysis of CVE-2026-19490, a critical CVSS 9.3 authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway. The flaw in the SAML handling allows an unauthenticated attacker to trigger various outcomes, ranging from a guaranteed denial-of-service crash to unauthorized access to internal network resources via SSRF, depending heavily on specific appliance configurations. While the vulnerability can lead to root command execution if weak management credentials are present, it primarily serves as a significant pre-authentication entry point for further attacks. Administrators should upgrade to fixed versions 13.1-63.21 or 14.1-73.32 immediately, noting that versions 12.1 and 13.0 are end-of-life and lack patches. Bishop Fox has also made a safe detection tool available on GitHub to verify patch status remotely with a single non-destructive request.

    ResearchNetScaler ADC
  5. SecurityWeek
    Critical NetScaler Vulnerability Exploited in Attacks

    CISA has confirmed that threat actors are actively leveraging a critical authentication bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-19490 with a CVSS score of 9.3, this vulnerability affects devices configured as gateways or AAA virtual servers and allows remote exploitation without prior authentication. Although Citrix released a patch on August 19, CISA added the bug to its Known Exploited Vulnerabilities catalog this week, citing observed attacks since September 3.

    Reported exploitedCitrix NetScaler ADC
  6. The Hacker News
    Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

    Check Point has disclosed and patched two high-severity vulnerabilities in its network security infrastructure that could permit unauthenticated attackers to execute arbitrary code remotely. The flaws, rated with a CVSS score of 9.8, affect the processing of VPN certificates within the Security Gateway and Security Management Server components. The first issue, tracked as CVE-2026-85102, involves improper validation of certificate trust during the VPN handshake process on Security Gateways. The second, identified as CVE-2026-85103, stems from a heap-based buffer overflow error occurring while decoding ASN.1 structures in VPN certificates; this bug impacts both Quantum Security Management and Quantum Security Gateway systems. While the company notes that no active exploitation has been observed, administrators are urged to apply the available hotfixes immediately.

    PatchCheck Point Security Gateway
  7. The Hacker News
    PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    A suspected Russian-speaking threat actor has leveraged hundreds of autonomous AI agents to compromise over 440 instances of PaperCut NG and PaperCut MF across 395 organizations. The attack chain exploits a combination of authentication bypass and remote code execution vulnerabilities, specifically CVE-2026-81578 and CVE-2026-82078, primarily targeting educational institutions in North America, Europe, and Oceania. Investigations by Blackpoint Cyber and GreyNoise revealed that the actor utilized OpenAI Codex and DeepSeek models alongside standard offensive tools to automate vulnerability research, target selection, and post-exploitation activities, achieving full domain administrator access on some networks within minutes. Administrators should verify patch levels for both CVEs immediately and monitor for indicators of compromise related to registry collection and Metasploit payloads.

    Reported exploitedPaperCut NG
  8. Help Net Security
    Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

    Cisco has confirmed that state-sponsored group Sandworm and ransomware operators linked to Qilin are actively targeting two vulnerabilities in Secure Firewall Management Center (FMC). The flaws, identified as CVE-2026-20079 and CVE-2026-20316, allow unauthorized remote attackers to bypass authentication or log in using hard-coded credentials to gain control of the system. While CVE-2026-20316 involves static low-privileged account credentials, CVE-2026-20079 permits root-level command execution via crafted HTTP requests. Talos recommends applying existing hotfixes immediately or restricting internet access to the management interface until the full hardening release is available.

    Reported exploitedCisco Secure Firewall Management Center (FMC)
  9. The Hacker News
    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    CISA has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, imposing a mandatory remediation deadline of September 12, 2026, for federal civilian executive branch agencies. The flagged defects include a critical authentication bypass in Cisco Secure Firewall Management Center (CVE-2026-20079), an authentication bypass in Citrix NetScaler ADC (CVE-2026-19490), and a heap-based buffer overflow in Fortinet FortiOS (CVE-2025-25249). These additions follow recent reports of active exploitation, including state-sponsored espionage against Cisco routers and a Russian-linked campaign using the Fortinet flaw to deploy the PivotC2 remote access trojan.

    Reported exploitedCisco Secure Firewall Management Center (FMC)
  10. SecurityWeek
    Organizations Warned of Cisco Secure FMC Exploitation

    Cisco and CISA have confirmed active in-the-wild exploitation of CVE-2026-20079, a critical authentication bypass flaw in Cisco Secure Firewall Management Center (FMC). This vulnerability permits remote attackers to execute arbitrary scripts and gain root access by sending crafted HTTP requests to vulnerable systems. Talos has linked the attacks to Russian APT group Sandworm, which deployed Cyclops Blink malware, and the Qilin ransomware syndicate, which used the breach for reconnaissance and credential theft. Organizations should apply the patch released in early March and restrict internet-facing exposure of the FMC interface.

    Reported exploitedCisco Secure Firewall Management Center (FMC)
  11. BleepingComputer
    CISA: WatchGuard RCE flaw now exploited in ransomware attacks

    CISA has updated its Known Exploited Vulnerabilities catalog to confirm that ransomware operators are now leveraging CVE-2025-14733, a critical out-of-bounds write flaw in WatchGuard Firebox firewalls. This vulnerability allows unauthenticated attackers to achieve remote code execution on devices running Fireware OS 11.x (including 11.12.4Update1), 12.x (including 12.11.5), or versions between 2025.1 and 2025.1.3, specifically when configured for IKEv2 VPN. While WatchGuard released remediation patches in December and warned that residual risk exists even if the vulnerable configuration is removed, nearly 9,000 exposed instances remain unpatched. Administrators should immediately apply updates and review IKEv2 settings to mitigate this active threat.

    Reported exploitedWatchGuard Firebox
  12. The Hacker News
    Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

    Wiz Research has identified that nearly one in ten internet-facing LiteLLM gateways accept the default "sk-1234" admin key documented in the official setup guide, exposing sensitive credentials and potentially allowing cloud infrastructure compromise. This misconfiguration exacerbates risks from several critical vulnerabilities in the BerriAI product, including CVE-2026-59822, which is already being actively exploited in the wild, and CVE-2026-42271, which permits unauthorized code execution on the host system. Administrators are advised to immediately replace the master key with a strong random value and upgrade their installations to version 1.84.0 or later to mitigate these threats.

    ResearchLiteLLM
  13. SecurityWeek
    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    Researcher Nightmare Eclipse has published the proof-of-concept code for ShieldCrash, a new zero-day vulnerability affecting Microsoft Defender on fully patched Windows systems. The exploit allows for arbitrary file reads and full System privilege escalation, serving as a bypass for previous flaws including CVE-2026-50656 (RoguePlanet) and CVE-2026-69414 (ShieldBreak). Security experts caution that the repeated ability to circumvent these fixes indicates fundamental weaknesses in how the vendor addresses the underlying attack surface.

    PoC publicMicrosoft Defender
  14. SecurityWeek
    Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    SOCRadar has reported active exploitation of CVE-2025-25249, an unauthenticated remote code execution vulnerability in Fortinet's FortiOS and FortiSwitchManager products. Attackers are leveraging this heap-based buffer overflow flaw to install the PivotC2 RAT, which grants them persistent access through features like traffic tunneling and network scanning. The incident has impacted 178 devices across over 30,000 targeted IPs, primarily affecting US entities and resulting in data exfiltration in at least two cases. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, prompting urgent patch recommendations to versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18 for FortiOS, and 7.2.7 and 7.0.6 for FortiSwitchManager.

    Reported exploitedFortiOS

Wednesday, Sep 915 stories

  1. BleepingComputer
    Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

    Cisco has confirmed that CVE-2026-20079, a critical authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software, is under active attack. This flaw, rated with a maximum CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary scripts with root privileges by sending crafted HTTP requests to the device web interface. The incident affects both Cisco Secure FMC Software and Security Cloud Control Firewall Management, though Cisco states the cloud-hosted service has already been patched. With no available workarounds, the vendor urges customers to immediately upgrade to the latest software release to mitigate the risk of full system compromise.

    Reported exploitedSecure Firewall Management Center (FMC)
  2. BleepingComputer
    Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

    The CERT Coordination Center at Carnegie Mellon University has issued a warning regarding the Skullcandy Dime 3 wireless earbuds, which are susceptible to unauthorized Bluetooth pairing due to CVE-2025-20701. This high-severity flaw resides in the Airoha Bluetooth Audio SDK used by model S2DCW units running firmware version 1.0.0.28, allowing attackers within range to intercept calls, play audio, or monitor conversations without user consent or physical access. Although Skullcandy resolved the issue in firmware version 1.0.0.30, consumers with previously purchased devices have no official method to update their hardware, leaving them permanently exposed to these privacy risks.

    AdvisorySkullcandy Dime 3
  3. The Hacker News
    Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

    A newly identified exploit kit named BlueMoon is being actively used by four espionage-motivated threat clusters, including APT31, to compromise targets by chaining vulnerabilities in Google Chrome and Microsoft Windows. The attack chain combines CVE-2026-85046 (a type confusion in the V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC) to achieve remote code execution and local privilege escalation. These are "patch-gap" zero-days, meaning the bugs were fixed in upstream Chromium code before being patched in stable browser releases. While both underlying flaws have since been addressed by Google and Microsoft, the rapid adoption of this kit by multiple state-aligned actors highlights the risk of exploiting open-source patch windows.

    Reported exploitedGoogle Chrome
  4. SecurityWeek
    Android’s September 2026 Updates Patch 180 Vulnerabilities

    Following two months without identified security issues, Google has released its September 2026 Android security bulletin, addressing a total of 180 vulnerabilities across various platform components. The update cycle includes patches for 95 issues arriving under the 2026-09-01 patch level and 85 fixes distributed via the 2026-09-05 patch level, affecting core System, Framework, kernel, and vendor-specific components from MediaTek, Qualcomm, Unisoc, Tsingteng Micro, and Imagination Technologies. Among the resolved defects is CVE-2026-28662, a Wi-Fi-related memory corruption flaw capable of enabling remote code execution without requiring user interaction or additional privileges.

    PatchAndroid
  5. SecurityWeek
    Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

    AMD, Arm, and Nvidia have issued security advisories addressing recently discovered vulnerabilities across their respective hardware and software ecosystems. AMD resolved CVE-2026-43603, a NULL pointer dereference issue in its Linux GPU kernel driver that poses a denial-of-service risk, with fixes currently available for EPYC Athlon, Ryzen, Radeon, and Instinct processors. Meanwhile, Arm addressed nine flaws in its Mali GPUs that could expose freed memory or sensitive kernel data, releasing updates for both Valhall and Bifrost architectures. Additionally, Nvidia patched two high-severity defects in the Triton Inference Server that allowed for information disclosure and data tampering.

    PatchAMD EPYC
  6. Cisco Talos
    Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

    Cisco Talos reports active in-the-wild exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079, a critical authentication bypass (CVSS 10.0) allowing unauthenticated attackers to gain root access, and CVE-2026-20316, which enables low-privileged login that can be chained for privilege escalation. Analysts have observed three distinct threat clusters leveraging these flaws. One group deployed web shells and a JAR-based command executor, another associated with Sandworm utilized Netcat reverse shells to install Cyclops Blink malware, and a third actor linked to Qilin ransomware used static credentials for reconnaissance and deployment. Cisco advises applying available hotfixes immediately, ahead of a comprehensive hardening release scheduled for the week of September 14.

    Reported exploitedSecure Firewall Management Center (FMC)
  7. SecurityWeek
    Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

    Fortinet has issued patches for ten security vulnerabilities across multiple products, addressing two critical defects requiring immediate attention. The most severe issue, CVE-2026-84390, allows unauthenticated attackers to bypass authentication on the FortiMonitorOnSight web portal by exploiting a forged JWT, while CVE-2026-84388 enables traffic proxying through the Privileged Access Agent Chrome extension. To fully remediate these risks, administrators must upgrade FortiPAM to version 1.9.1 or 1.8.4 and ensure the associated Chrome extension is updated to version 8.0.1.123 or later. The update cycle also resolves high-severity bugs in FortiSandbox and FortiOS, along with several lower-severity issues affecting other components such as FortiManager and FortiClient.

    PatchFortiMonitorOnSight
  8. The Hacker News
    DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

    DeepSeek has released a fix for CVE-2026-82533, a critical flaw in the DeepSeek Harness tool that permitted AI coding agents to bypass their file-based sandbox restrictions. The vulnerability stemmed from a lack of proper authentication on the local web interface, allowing a malicious agent to issue a specific command that switched the session to a 'danger-full-access' mode, thereby disabling approval prompts and sandbox boundaries. Rated 9.4 by VulnCheck, this issue affected versions up to 0.1.1-rc.2 and enabled attackers to write files outside the designated workspace after exploiting the unsanitized Host header check. Users are advised to upgrade immediately to version 0.1.2-alpha.2 or later, as the initial fixed release was not available via npm.

    PatchDeepSeek Harness
  9. Help Net Security
    Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

    Sophos has revealed that threat actors are exploiting F5 BIG-IP APM devices to install a sophisticated Linux rootkit named PoisonedRefresh. This campaign leverages CVE-2025-53521, an unauthenticated remote code execution vulnerability, to inject a web shell directly into memory, thereby avoiding detection by traditional file-based scanning tools. The malware operates by hooking Apache’s Portable Runtime and modifying how PHP files like apmcss.php3 are loaded, effectively masking malicious code within legitimate scripts. Additionally, the implant establishes a Unix domain socket at /run/bigtlog.pipe to provide attackers with direct shell access without leaving standard network traces.

    Reported exploitedF5 BIG-IP APM
  10. SecurityWeek
    ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

    Schneider Electric and Siemens have issued their September 2026 industrial control system advisories, addressing multiple high-severity defects across various hardware and software platforms. Schneider's most significant fix resolves CVE-2026-3869, a critical authentication bug with a CVSS score of 9.2 affecting Modicon M580 and Modicon M580 Safety controllers, alongside updates for PowerLogic T300 and SCADAPack x70 products. Siemens simultaneously published nine new advisories targeting critical vulnerabilities in systems such as Reyrolle 7SR5 and Open Interface Services, while also deploying patches for the Linux kernel flaw CVE-2026-31431. Additional vendors included Aveva, which fixed hardcoded key issues in PIMBoards, and Rockwell Automation, which addressed critical flaws in RSLinx Classic and several controller modules.

    RoundupModicon M580
  11. SecurityWeek
    Ivanti Patches Critical Flaws Across Enterprise Security Products

    Ivanti has distributed urgent security updates to address multiple critical and high-severity vulnerabilities across its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) platforms. The Neurons for ITSM release resolves eight distinct defects, including CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646, which carry a maximum CVSS score of 9.9/10 and can enable remote code execution through unauthorized access or unsafe data handling. Additionally, new builds for Sentry and EPMM have been issued to remediate authentication bypass issues identified as CVE-2026-83527 and CVE-2026-18851 respectively. While Ivanti reports that these specific flaws have not yet seen active exploitation, administrators are advised to apply the latest patches to prevent potential compromise.

    PatchIvanti Neurons for ITSM
  12. SecurityWeek
    Chrome 153 Patches Seventh Zero-Day of 2026

    Google has shipped Chrome 153 to the stable channel to resolve an actively exploited zero-day tracked as CVE-2026-87491. This medium-severity flaw, characterized as an out-of-bounds write in the V8 engine, marks the seventh such incident addressed by the browser team in 2026. The update also addresses 229 additional security issues, including several critical severity bugs in WebGL and Cast components. Users should upgrade promptly to build 153.0.8010.36 or later on supported operating systems.

    Reported exploitedGoogle Chrome
  13. The Hacker News
    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google has released security updates for Chrome, addressing 230 vulnerabilities including a medium-severity out-of-bounds bug in the V8 engine that is currently being exploited in the wild. Identified as CVE-2026-87491, this flaw allows remote attackers to execute arbitrary code within the sandbox via crafted HTML content in versions prior to 153.0.8010.36. The update also resolves five critical flaws in WebGL and Cast components, bringing the total number of actively exploited Chrome zero-days patched this year to seven. Users are strongly advised to upgrade to version 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, to mitigate these risks.

    Reported exploitedGoogle Chrome
  14. Help Net Security
    September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

    Microsoft has released its September 2026 security updates, addressing a record number of flaws, including two vulnerabilities currently being exploited in the wild. The critical fixes resolve CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call, both of which allow privileged users to escalate to SYSTEM rights. Additionally, researchers have published a proof-of-concept for a bypass of the Microsoft Defender patch, highlighting ongoing risks to endpoint security.

    Reported exploitedWindows Update Stack
  15. The Hacker News
    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    cPanel has released a security update to address CVE-2026-67401, a critical vulnerability affecting all supported versions of cPanel and WHM. This flaw, classified as an SQL injection within the EmailTrack functionality, permits an authenticated hosting account with specific mail privileges to create arbitrary files and escalate privileges to execute code as the root user. Because this level of access grants full administrative control over the server, it exposes all customer data and infrastructure to potential compromise. Administrators must immediately update their systems to the designated fixed builds, such as 11.110.0.143 or 11.134.0.55, by running the upgrade script or using the WHM interface.

    PatchcPanel

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store