High and critical security vulnerabilities disclosed in enterprise software

On 4 September 2026, BSI (German federal cybersecurity agency) disclosed multiple vulnerabilities across SEPPmail, Kibana, Google Chrome, Microsoft Cloud services, and the vm2 JavaScript sandbox. vm2 rated critical for remote code execution; others rated high. No active exploitation was reported.

11 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage