Fallo en Red Hat OpenShift permite saltar chequeos PGP y publicar versiones maliciosas https:// blog.elhacker.net/2026/09/fall o-en-red-hat-openshift-permite.html
Security researchers disclosed on August 24–25, 2026, that two Microsoft SharePoint Server vulnerabilities—CVE-2026-55040 and CVE-2026-63520—can be chained to bypass authentication and achieve remote code execution without a password. Both flaws are listed in CISA's Known Exploited Vulnerabilities catalog with public exploits available.
A bug in Microsoft's automated network maintenance system caused a widespread outage affecting Teams, SharePoint, Excel and other Microsoft 365 services. The bug mistakenly removed IP routes from more devices than intended.
The U.S. Cybersecurity and Infrastructure Security Agency added multiple vulnerabilities to its Known Exploited Vulnerabilities catalog on September 25, 2026, including flaws in Microsoft SharePoint, MikroTik RouterOS, WordPress, and WSO2 software. All are confirmed to be under active exploitation.
CISA has added four vulnerabilities to its KEV catalog with evidence of active exploitation. Affected systems include Microsoft IKE Service Extensions, SharePoint, VMware vCenter, and Apple macOS.
On August 26, 2026, threat intelligence firm Defused reported that attackers were actively exploiting a chain of two Microsoft SharePoint vulnerabilities enabling remote code execution on unpatched servers. The disclosure included proof-of-concept exploit code.
This cluster contains unrelated fragments: Indigenous advocacy on Amazon conservation in Ecuador, a Spanish regional politician's controversy, a Galician poetry reference, European asylum policy disputes, and local Jacksonville road/school safety notices. No single coherent story emerges from these disparate items.
Six critical and high-severity vulnerabilities disclosed: DD-WRT stack buffer overflow (CVE-2021-27137), Langflow code execution flaws (CVE-2026-0770, CVE-2026-55255), WordPress Core interpretation conflict (CVE-2026-63030), Microsoft AD FS access control gap (CVE-2026-56155), and Oracle E-Business Suite privilege escalation (CVE-2026-46817). All pose remote compromise risks.
CRITICAL THREAT: CVE-2026-50522 in Microsoft SharePoint enables unauthenticated remote code execution via untrusted data deserialization. Active exploitation is confirmed!
Eight unrelated items spanning April 2024 to November 2026: WHO partnership meetings with Netherlands and Spain, a research paper on LLM agent security, a weather alert, congressional bill tracking, FCC rulemaking, and an AI labor-market report. No coherent single story.
Between September 24-25, 2026, the Cybersecurity and Infrastructure Security Agency added five actively exploited software vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Adobe Commerce/Magento, MikroTik RouterOS, Microsoft SharePoint, and WordPress Core. The vulnerabilities range from authorization bypass to remote code execution.
Between August 3 and August 20, 2026, CISA added multiple critical vulnerabilities to its active exploitation list, including authentication bypass flaws in N-able N-central, code injection in TrueConf Server, and server-side request forgery in MLflow. CVE-2026-18577 and CVE-2026-18556 affect remote access management software, while CVE-2026-72530 and CVE-2026-72529 target enterprise conferencing infrastructure.
CISA published six newly disclosed software vulnerabilities affecting LiteSpeed cPanel, Nx Console, TanStack, DD-WRT, Check Point SmartConsole, and Microsoft SharePoint, ranging from privilege escalation to remote code execution. These CVEs pose significant security risks to enterprise and open-source users.
Cluster mixes Fairphone Linux phone charging, Middle East defense pact, DOE nuclear projects, and RDP honeypot data with no single story. Reports span consumer hardware, international security, energy policy, and cybersecurity intelligence.