⌁ DAY 41

IBM AIX and PowerVM VIOS hit by multiple critical vulnerabilities

26 beadsAug 19 → Sep 27moved 2d ago

The wire

2026-09-27

Critical Citrix NetScaler zero-day RCE vulnerabilities exploited

broke 2d ago · 15 reports · other · primary

Two unpatched remote-code-execution zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) in Citrix NetScaler ADC and Gateway are being actively exploited in attacks as of September 27, 2026. CISA and the Dutch NCSC recommend immediate patching; some IT providers recommend shutting down affected appliances.

Citrix patches exploited NetScaler zero-day vulnerabilities

broke 2d ago · 36 reports · other · tech · primary

Citrix released patches on September 27, 2026, for two critical remote-code-execution zero-day flaws (CVE-2026-88771, CVE-2026-88772) in NetScaler ADC and Gateway that researchers confirmed are being exploited globally. CISA set a deadline for organizations to apply updates.

2026-09-25

CISA flags four actively exploited software vulnerabilities

broke 4d ago · 7 reports · other · primary

The U.S. Cybersecurity and Infrastructure Security Agency added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, including flaws in Microsoft SharePoint, MikroTik RouterOS, WordPress, and WSO2 software. All are confirmed to be under active exploitation.

2026-09-24

Netflix releases new shows and content updates UK library

broke 5d ago · 12 reports · other

Between September 24–27, 2026, Netflix added or promoted multiple titles in the UK: the new series 'A Different World' (2026), 'Delusion' (2026), 'Batwheels' (2024), and documentary 'Becoming Led Zeppelin' (2025), alongside classics like 'How to Lose a Guy in 10 Days' (2003). Singer Brandy released a version of the 'A Different World' theme.

2026-09-22

CISA adds four exploited vulnerabilities to Known Exploited catalog

broke 7d ago · 10 reports · other · primary

The US Cybersecurity and Infrastructure Security Agency added four new vulnerabilities to its Known Exploited Vulnerabilities catalog on 22 September 2026, including critical Check Point path traversal and certificate validation flaws showing active exploitation. By 24 September, CISA added two additional exploited vulnerabilities.

2026-09-18

Six software vulnerabilities disclosed, including remote code execution flaws

broke 11d ago · 19 reports · other

Between 2026-09-18 and 2026-09-21, six CVEs affecting web and productivity software were publicly disclosed: Browsertrix versions 1.15.0–1.22.7 allow OS command execution via Git URL sanitization failures; SiYuan 3.8.3 and earlier allow code execution through notebook bookmark labels and document titles; Netcore NBR200V2 router allows remote code execution via VLAN memory overwrite; NivoCart permits script upload to public folders by low-privilege users; and openEQUELLA pre-2026.1.0 allows authenticated code injection in reports.

2026-09-17

Cisco ISE CVE-2026-76460: critical authentication bypass under active attack

broke 12d ago · 13 reports · other

Between September 17 and 18, 2026, Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC API endpoints that allows unauthenticated attackers to gain root access and execute arbitrary commands. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog due to active exploitation in the wild.

2026-09-14

Multiple Critical Remote-Code-Execution Vulnerabilities Disclosed

broke 15d ago · 10 reports · other

Between September 14–15, 2026, multiple critical buffer-overflow and command-injection vulnerabilities with public exploit code were disclosed in router firmware (Totolink A3002MU, D-Link DI-8300), a timecard application (TREXOM TrxTimeATTENDANCE), and a mesh platform (pig-mesh pig). All allow unauthenticated remote code execution; no patches were available as of the latest report.

2026-09-11

GitLab CVE-2026-85706: CVSS 10 flaw exploited in the wild

broke 18d ago · 13 reports · other

Following GitLab's September 11 disclosure of CVE-2026-85706 (path traversal, CVSS 10.0), by September 12, 2026, active exploitation probes were already being observed in the wild. CISA added it to the Known Exploited Vulnerabilities catalog with a three-day deadline for agencies to patch self-managed GitLab servers.

GitLab patches critical path traversal vulnerability CVE-2026-85706

broke 18d ago · 5 reports · other · tech

GitLab released urgent patches on September 11, 2026 to address CVE-2026-85706 (CVSS 10.0), a maximum-severity path traversal flaw in the repository commits API affecting self-managed installations. The vulnerability allows unauthenticated attackers to read arbitrary files; CISA added it to the exploited vulnerabilities catalog with active in-the-wild probes within days.

2026-09-09

Cisco Firewall Management Center vulnerabilities actively exploited

broke 20d ago · 25 reports · other · tech

Cisco Talos confirmed on September 10, 2026, that CVE-2026-20079 and CVE-2026-20316, maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC), were being actively exploited by state-sponsored actors, ransomware gangs, and financially motivated threat groups. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities list on September 9.

2026-09-08

CISA adds multiple critical vulnerabilities to known exploited catalog

broke 21d ago · 18 reports · primary · other

Between September 8 and 11, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added six critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Microsoft Windows, GitLab, JFrog Artifactory, and N-able N-central that allow remote code execution and privilege escalation. Active exploitation of these vulnerabilities has been documented.

Multiple critical software vulnerabilities disclosed across vendors

broke 21d ago · 11 reports · other · primary

Between September 8 and 10, 2026, critical security vulnerabilities were disclosed in Fortinet (CVE-2026-84390, CVE-2026-26084), Siemens (CVE-2026-18963, CVE-2026-50093), Apache Nutch (CVE-2026-41870), Apache Artemis (CVE-2026-67593), NVIDIA Triton, and NextGen Healthcare Mirth Connect, exposing systems to account takeover, remote code execution, denial of service, and data exfiltration.

2026-09-04

Critical Citrix NetScaler auth bypass actively exploited

broke 25d ago · 6 reports · other · tech

By September 5, 2026, threat actors were actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler ADC and Gateway appliances. Previdian confirmed active exploitation in the wild, urging immediate patching.

2026-09-02

CISA adds four critical vulnerabilities to known exploited catalog

broke 27d ago · 10 reports · primary · other

CISA added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8 that allows remote code execution via crafted HTML, to its Known Exploited Vulnerabilities catalog as of September 4, 2026. The catalog simultaneously tracked four other critical flaws in LiteLLM, Starlette, Kestra, and SonicWall appliances.

2026-09-01

Critical Sangoma Switchvox vulnerability actively exploited in wild

broke 28d ago · 11 reports · other · tech

CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP systems, was actively exploited in the wild by 3 September 2026. Security researchers at Defused Cyber and Horizon3 documented reverse-shell deployments affecting approximately 4,000 internet-exposed systems.

2026-08-31

PaperCut NG/MF vulnerabilities added to CISA catalog

broke 29d ago · 4 reports · other · primary

Two PaperCut NG/MF vulnerabilities were added to CISA's Known Exploited Vulnerabilities catalog on August 31, 2026, including CVE-2026-81578 (missing authentication for critical function) and CVE-2026-82078. The flaws allow unauthenticated remote attackers to modify system configurations.

2026-08-25

Gitea git service flaw allows remote code execution

broke 35d ago · 7 reports · other

CVE-2026-60004, a critical code-injection vulnerability in Gitea (self-hosted Git service), was exploited in the wild for remote code execution and cryptocurrency mining. On 26 August 2026, CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated patches for federal agencies.

Six critical security vulnerabilities disclosed across Linux and open-source software

broke 35d ago · 22 reports · other

On 2026-08-25, six CVEs were disclosed covering security flaws in Linux kernel SCTP networking (CVE-2026-74586, 74587, 74588), CakePHP authentication (CVE-2026-77337), Unbound DNS validator (CVE-2026-33278), and Perl regex compilation (CVE-2026-8376). Vulnerabilities range from use-after-free memory errors to remote code execution and denial-of-service conditions.

2026-08-24

SharePoint Vulnerabilities Enable Unauthenticated Remote Code Execution

broke 36d ago · 6 reports · other

Security researchers disclosed on August 24–25, 2026, that two Microsoft SharePoint Server vulnerabilities—CVE-2026-55040 and CVE-2026-63520—can be chained to bypass authentication and achieve remote code execution without a password. Both flaws are listed in CISA's Known Exploited Vulnerabilities catalog with public exploits available.

Critical Keycloak flaw allows unauthenticated account takeover

broke 36d ago · 11 reports · other

On August 24-25, 2026, Red Hat and the Keycloak project released fixes for CVE-2026-18963, a critical password-reset vulnerability (CVSS 9.1) in the open-source identity server allowing unauthenticated attackers to force password resets without email access. A sixth post about an unrelated Metabase SQL injection was captured.

2026-08-20

Citrix warns of critical vulnerabilities in NetScaler products

broke 40d ago · 3 reports · other · tech

Citrix issued an urgent security warning on August 20, 2026, regarding two vulnerabilities affecting NetScaler Gateway and NetScaler ADC networking appliances, including at least one critical unauthenticated flaw. The company urged administrators to patch systems immediately.

Multiple critical security vulnerabilities under active exploitation

broke 40d ago · 6 reports · other

CISA and security researchers warned on August 20–21, 2026 of active exploitation of multiple critical remote code execution vulnerabilities: Ray framework (CVE-2025-62593, CVSS 8.8), Zimbra Collaboration Suite (CVE-2026-73570), and Microsoft Windows IKE service. Attackers are targeting machine learning and messaging systems.

CVE-2026-73570: critical Zimbra RCE actively exploited in the wild

broke 40d ago · 6 reports · other · primary

An unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9) is under active exploitation via SMTP and SNMP notifications, affecting versions prior to 10.1.20. CISA and CERT Polska confirmed real-world attacks as of 21 August 2026.

Multiple critical software vulnerabilities disclosed in August 2026

broke 40d ago · 39 reports · other

Between 2026-08-20 and 2026-08-24, five critical vulnerabilities were disclosed across Splunk, EverShop, and GitLab, with CVSS scores of 9.1 to 9.4. A broader CVE report for 2026-08-17 listed 515 critical vulnerabilities published that week.

2026-08-19

IBM AIX and PowerVM VIOS hit by multiple critical vulnerabilities

broke 41d ago · 40 reports · other

Five CVEs affecting IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 were disclosed between August 19–21, 2026, exposing private keys, enabling authentication bypass, command injection, and other critical attacks. CVE-2026-15065, CVE-2026-16656, CVE-2026-16816, CVE-2026-17040, and CVE-2026-17118 collectively present severe risks to enterprise systems running these platforms.