As of 2026-08-26, attackers are actively exploiting a critical-severity vulnerability in Gitea, a self-hosted Git service, according to the US Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability enables code injection attacks.
Security researchers identified six critical vulnerabilities (CVSS 9.0–10.0) across Alibaba Fastjson, Avada Core, industrial control systems, Joomla plugins, Schneider Electric SCADA, and VaahCMS, all exploitable under default configurations with no patches available yet.
Infosec Mastodon instance accounts posted links to software security vulnerabilities and exploits between 23–24 July 2026, including remote code execution flaws in Feast, AdRem NetCrunch, Brekeke SIP Server, BentoML, and kernel driver issues. No coherent story; a feed of unrelated vulnerability announcements.
Between 2026-08-26 and 2026-08-28, Ubiquiti and ServiceNow released patches for multiple maximum-severity vulnerabilities affecting their products. Ubiquiti patched three remote-exploitable flaws; ServiceNow addressed three AI Platform vulnerabilities enabling code injection, SQL injection, and privilege escalation.
Between 20 and 21 August 2026, multiple critical CVEs were publicly disclosed affecting TRENDnet routers (CVE-2026-76589/76590, CVSS 9.4), IBM AIX systems (CVE-2026-16885, CVSS 9.8), WordPress plugins, and other software, with public exploits available and no patches released. Administrators were advised to restrict access and monitor systems.
Between 2026-08-20 and 2026-08-24, five critical vulnerabilities were disclosed across Splunk, EverShop, and GitLab, with CVSS scores of 9.1 to 9.4. A broader CVE report for 2026-08-17 listed 515 critical vulnerabilities published that week.
WP Recipe Maker version 10.8.1 and earlier contains CVE-2026-89274, a critical code-injection flaw allowing unauthenticated attackers to execute arbitrary shortcodes via unsanitized comment ratings. The vulnerability was disclosed on 2026-09-19 with a near-perfect severity rating.
UA: Динаміка безповоротних втрат рашистів у війні проти України з 24 лютого 2022 року станом на сьогоднішній ранок https:// index.minfin.com.ua/ua/russian -invading/casualties/ EN: Trends of # ruscist irrecoverable losses in the war against Ukraine since February 24, 2022, to thi
social/@goinfawr/1172757 09103756665 I see the Chamber Seating Plan hasn't been updated to include Scott Sinclair's leaving the UCP, but by my count includes the vote of the two (2) mla's that left the governing party to become independents. So a NO CONFIDENCE ballot count would currently sit at 40 ayes to 46 nays.
ServiceNow released critical security patches on 28 August 2026 for three CVSS 10.0 vulnerabilities in its AI Platform that allow unauthenticated attackers to execute code injection, SQL injection, and privilege escalation without credentials. The flaws have not yet been exploited in the wild.
Six critical and high-severity vulnerabilities disclosed: DD-WRT stack buffer overflow (CVE-2021-27137), Langflow code execution flaws (CVE-2026-0770, CVE-2026-55255), WordPress Core interpretation conflict (CVE-2026-63030), Microsoft AD FS access control gap (CVE-2026-56155), and Oracle E-Business Suite privilege escalation (CVE-2026-46817). All pose remote compromise risks.
🚨 Critical Tutor LMS vulnerability: CVE-2026-78175 A critical vulnerability in Tutor LMS can chain broken access control → PHP object injection → arbitrary file write → remote code execution. 8 The issue is particularly concerning because a low-privileged subscriber account can reach the vulnerable withdrawal-account functionality.
Two critical OS command injection vulnerabilities were disclosed on 2026-09-28 and 2026-09-29 affecting Netcore NBR200V2 and NAP930 routers/network appliances. Public exploit code is available for both CVE-2026-101002 and CVE-2026-102240, with no vendor patches released; security advisories recommend isolating affected devices.
CVE-2026-60004, a critical code-injection vulnerability in Gitea (self-hosted Git service), was exploited in the wild for remote code execution and cryptocurrency mining. On 26 August 2026, CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated patches for federal agencies.
The U.S. Cybersecurity and Infrastructure Security Agency added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, including flaws in Microsoft SharePoint, MikroTik RouterOS, WordPress, and WSO2 software. All are confirmed to be under active exploitation.