These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
CVE-2026-76461 is a CVSS 9.8 flaw in Cisco Secure Email Gateway’s email-parsing engine that lets an attacker execute commands as root simply by sending a specially crafted message through the appliance, no credentials or clicks required. Cisco disclosed and patched it on September 14 after confirming active exploitation, and CISA’s federal remediation deadline is September 17, tomorrow.
Wordfence disclosed CVE-2026-78006 on September 12, a CVSS 9.8 unauthenticated PHP object injection flaw in The Events Calendar, a WordPress plugin with over 600,000 active installs. An attacker who posts a crafted comment on any event page, no login required, can trigger arbitrary code execution before comment moderation even runs. StellarWP shipped the fix in version 6.17.4.1 on September 10, alongside a second, unrelated unauthenticated RCE (CVSS 8.1) in the same release. Proof-of-concept exploit code is already public.
CVE-2026-87827, a maximum-severity CVSS 10.0 flaw in KGUARD DVR firmware dated 2016 and earlier, exposes an unauthenticated system command execution service on every network interface, letting a remote attacker fully compromise the device with no credentials at all. The Mirai_ptea (Rimasuta) and Mirai_aurora botnet variants are already exploiting it in the wild to recruit devices for malware propagation and DDoS. KGUARD’s fix, present in firmware from 2017 onward, only restricts the service to localhost; there is no update for the affected legacy models, which remain sold and in service across small offices and retail sites.
ConnectWise disclosed CVE-2026-84869, a CVSS 9.9 flaw that let the guest side of an active ScreenConnect remote support or access session transfer and execute files on the host machine without the host’s confirmation, including elevated actions. ConnectWise shipped ScreenConnect 26.6.5 on September 8, CISA confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog on September 11, and set September 14, today, as the deadline for US federal agencies to remediate. ScreenConnect is one of the most widely deployed remote support tools among European MSPs and IT teams.
Revolut confirmed a data breach after an unauthorized party used an email account inside a real government agency’s domain to submit fraudulent requests for customer information. Because the messages carried valid domain authentication, Revolut treated them as genuine and disclosed KYC documents, identity-verification selfies, account statements and Bitcoin-related transaction histories for a limited, apparently high-net-worth, set of customers. Revolut says systems and funds were unaffected and has notified law enforcement and regulators, but the incident is a case study in a specific failure mode: trusting the sender’s domain instead of verifying the request itself.
Two hours after Microsoft shipped its September 2026 Patch Tuesday, the researcher behind two earlier Windows Defender zero-days published a third proof of concept, ShieldCrash, that reads SYSTEM-level files on fully patched Windows 10, Windows 11 and Windows Server machines. Microsoft’s own patch for CVE-2026-69414, the ShieldBreak flaw it fixed only after bypass research forced its hand in August, is the fix ShieldCrash is reported to get around, and there is still no confirmed timeline for closing the gap.
Poland’s national CSIRT coordinated disclosure of a two-step attack chain, dubbed MikroTrick, that lets an attacker take full control of a MikroTik RouterOS device over SSH without ever supplying a valid password. CVE-2026-67276, an SSH public-key check that never validates the exponent, combines with CVE-2026-86060 to hand over root. MikroTik shipped fixes on September 3, CISA added the flaws to its Known Exploited Vulnerabilities catalog on September 10 with a September 13 deadline for US federal agencies, and CERT Polska says exploitation from internet-facing devices was already underway from at least September 2.
CVE-2026-85706, a maximum-severity path traversal flaw in GitLab’s repository commits API, went from patch to in-the-wild exploitation attempts in a single day. GitLab fixed it on September 10, CISA added it to its Known Exploited Vulnerabilities catalog on September 11 with a September 14 federal deadline, and researchers estimate more than 20,000 self-managed GitLab instances worldwide are still exposed.
New research published today by email testing firm MailGenius finds that BIMI projects, the standard that puts a verified brand logo next to authenticated email, almost always stall on DMARC enforcement rather than on the certificate itself. A Certificate Transparency snapshot of over 20,000 BIMI certificates shows adoption growing fast, but the unglamorous work of getting every sending system to authenticate under a single enforced policy is what most teams underestimate.
The PGP key signing GitHub CLI’s Linux APT and RPM packages expired on September 5, 2026. Any pipeline, base image, or server that installs or updates gh from those repositories without trusting the replacement key now fails with a signature verification error, often in the least convenient place: a CI job that has run unchanged for years.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.