On 2026-09-10 to 2026-09-12, security researchers identified active exploitation of multiple critical vulnerabilities: CVE-2026-85103 in Check Point Quantum Security Gateway/Management, CVE-2026-0309 and CVE-2026-0307 in Palo Alto Networks PAN-OS and GlobalProtect, and three high-severity Linux Kernel flaws (CVE-2026-80981, CVE-2026-89494, CVE-2026-89563). All showed evidence of attacker activity.
Between September 9 and 11, 2026, security researchers disclosed six new vulnerabilities affecting widely-used enterprise software: three affecting Microsoft Windows (CVE-2026-69845, CVE-2026-83997, CVE-2026-83992), two in IBM products (CVE-2026-86093 in Db2, CVE-2026-9667 in WebSphere), and one in IBM DataStage on Cloud Pak for Data (CVE-2026-82099). All were flagged as having increased or important severity levels.
Between September 7 and 9, 2026, cybersecurity researchers reported multiple new vulnerabilities affecting Dell Secure Connect Gateway, D-Link routers, Microsoft Windows, and Fortinet FortiOS, with several rated as severe or high-severity. Active exploitation of Fortinet vulnerabilities was also noted.
Between 30 August and 1 September 2026, security researchers disclosed five critical vulnerabilities affecting D-Link network storage devices (DSM-G600, DNS-340L, DNS-345, DNS-320L), SUSE yast2-samba-client, and Dell PowerStore 500T, with severity ratings increased on several. The D-Link devices represent a cluster of related vulnerabilities in storage networking products.