These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Two hours after Microsoft shipped its September 2026 Patch Tuesday, the researcher behind two earlier Windows Defender zero-days published a third proof of concept, ShieldCrash, that reads SYSTEM-level files on fully patched Windows 10, Windows 11 and Windows Server machines. Microsoft’s own patch for CVE-2026-69414, the ShieldBreak flaw it fixed only after bypass research forced its hand in August, is the fix ShieldCrash is reported to get around, and there is still no confirmed timeline for closing the gap.
Poland’s national CSIRT coordinated disclosure of a two-step attack chain, dubbed MikroTrick, that lets an attacker take full control of a MikroTik RouterOS device over SSH without ever supplying a valid password. CVE-2026-67276, an SSH public-key check that never validates the exponent, combines with CVE-2026-86060 to hand over root. MikroTik shipped fixes on September 3, CISA added the flaws to its Known Exploited Vulnerabilities catalog on September 10 with a September 13 deadline for US federal agencies, and CERT Polska says exploitation from internet-facing devices was already underway from at least September 2.
CVE-2026-85706, a maximum-severity path traversal flaw in GitLab’s repository commits API, went from patch to in-the-wild exploitation attempts in a single day. GitLab fixed it on September 10, CISA added it to its Known Exploited Vulnerabilities catalog on September 11 with a September 14 federal deadline, and researchers estimate more than 20,000 self-managed GitLab instances worldwide are still exposed.
New research published today by email testing firm MailGenius finds that BIMI projects, the standard that puts a verified brand logo next to authenticated email, almost always stall on DMARC enforcement rather than on the certificate itself. A Certificate Transparency snapshot of over 20,000 BIMI certificates shows adoption growing fast, but the unglamorous work of getting every sending system to authenticate under a single enforced policy is what most teams underestimate.
The PGP key signing GitHub CLI’s Linux APT and RPM packages expired on September 5, 2026. Any pipeline, base image, or server that installs or updates gh from those repositories without trusting the replacement key now fails with a signature verification error, often in the least convenient place: a CI job that has run unchanged for years.
From 11 September 2026, manufacturers of any product with digital elements sold in the EU must report actively exploited vulnerabilities within 24 hours through ENISA’s new Single Reporting Platform, which itself only went live today. The obligation and the tool to comply with it launched on the same date, leaving little runway for the testing and dry runs most compliance teams would normally insist on.
Attackers are exploiting CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager, to plant a custom remote access tool called PivotC2 on internet-exposed FortiGate appliances. Fortinet patched the flaw in January 2026, but researchers have logged scanning against roughly 30,000 IP addresses and confirmed 178 compromised sessions, and CISA only added it to its Known Exploited Vulnerabilities catalog on September 9.
CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, lets an unauthenticated attacker ride a leftover session from system startup into root access on the box that manages an organisation’s firewalls. Cisco has confirmed active exploitation linked to state-sponsored groups and ransomware operators, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 deadline for US federal agencies.
CVE-2026-87491, an out-of-bounds write in Chrome’s V8 engine, was already being exploited in the wild when Google fixed it in Chrome 153.0.8010.36/.37 on September 8, five days after patching a separate actively exploited V8 flaw, CVE-2026-85046. It is the seventh Chrome zero-day of 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9.
Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, the largest release on record, including two Windows privilege escalation flaws already being exploited in the wild. Neither zero-day gives an attacker remote entry on its own, but combined with almost any foothold they hand over full SYSTEM control, and a list this size means most patch teams cannot triage the rest of the queue this week.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.