Between 2026-09-07 and 2026-09-09, security researchers disclosed six critical vulnerabilities across enterprise and network products with CVSS scores of 9.1–10.0, including unauthenticated remote code execution in JetBrains Hub, D-Link routers, Google Cloud ADK, SAP CAP, and Check Point Quantum Security Gateway, plus credential theft in a payment processing module. No patches were available as of the latest report date.
12 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https:// radar.offseq.com/threat/cve-20 26-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b # OffSeq # CVE202686510 # RouterSecurity # Infosec
SAP CAP's @sap/cds-mtxs (<=4.0.2) has a CRITICAL flaw (CVE-2026-76969): insufficiently protected credentials let unauthenticated attackers steal creds and delete/replace tenant data. No patch yet — monitor SAP updates. https:// radar.offseq.com/threat/cve-20 26-76969-cwe-522-insufficiently-protected-credentials-in-sapse-sap-cloud-application-programming-ee3e359619813d60 # OffSeq # SAP # infosec #
CVE-2026-12855: HIGH-severity vuln in InsydeH2O firmware (HP). Local attackers with high privileges may execute arbitrary code due to improper input validation. No patch yet — restrict local admin access. https:// radar.offseq.com/threat/cve-20 26-12855-cwe-20-improper-input-validation-in-insyde-software-insydeh2o-96c11fc7beb122a7 # OffSeq # Vulnerability # Firmware # Infosec
CVE-2026-16272 (CVSS 9.1, CRITICAL) in PayTR Virtual Pos iFrame API (v9x) WHMCS Module v9.0.0: Use of less trusted source can compromise confidentiality and integrity. No patch yet — restrict access and monitor vendor updates. https:// radar.offseq.com/threat/cve-20 26-16272-cwe-348-use-of-less-trusted-source-in-paytr-payment-and-electronic-money-institution-04a905be1a132f6a # OffSeq # CVE2026_162