preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security devops cve ai ai-agents cloud europe cisa-kev

LiteLLM's AI Gateway Had a Second Way In: A Fabricated Bearer Token Was Enough

CVE-2026-59822 lets an unauthenticated attacker open an authenticated session on LiteLLM’s MCP Streamable HTTP endpoint using nothing but a made-up Bearer token, thanks to an OAuth2 passthrough fallback that silently replaced failed key validation with an empty, but accepted, auth object. CISA added it to its Known Exploited Vulnerabilities catalog on September 2, separate from the supply chain compromise the same gateway suffered earlier this year.

digital-security devops cve python ai ai-agents europe cisa-kev

One Malformed Character in a Host Header Can Now Bypass Auth on Millions of AI Servers

CVE-2026-48710, nicknamed BadHost, lets an unauthenticated attacker bypass path-based security middleware in Starlette, the Python framework underneath FastAPI, vLLM, LiteLLM and countless MCP servers, by sending a single malformed character in the HTTP Host header. Belgium’s Centre for Cybersecurity issued a patch-immediately advisory, and CISA added it to its Known Exploited Vulnerabilities catalog on September 2.

digital-privacy digital-security gdpr healthcare data-breach europe compliance mfa

France's Privacy Regulator Just Fined a Hospital 500,000 Euros for Skipping MFA

CNIL fined Hopital Prive de la Loire 500,000 euros after an attacker used compromised credentials, with no multi-factor authentication in the way, to browse the medical records of 524,867 patients undetected through summer 2025. The regulator also found the hospital never notified 202,246 affected third parties, a separate violation of GDPR’s breach notification duty.

devops cloud google-cloud reliability infrastructure incident-response europe

One Engineer Disconnected a Fiber Cable. A Chunk of Google Cloud Went Down.

During routine network maintenance on September 1, a procedural error at Google caused an engineer to sequentially disconnect every fiber path across the routing devices in a us-central1-b cluster within about thirteen minutes, pushing traffic-drop rates to 100 percent at peak and leaving VMs unreachable from outside the zone for over four hours. The redundancy Google’s design assumed did not help, because the failure removed every redundant path at once.

digital-security cve vulnerability vpn network kev vulnerability-management europe patch-management

Two SonicWall Bugs, Chained Together, Turn Your VPN Gateway Into an Open Door

SonicWall disclosed two SMA1000 vulnerabilities on September 1: a perfect-10 pre-auth SSRF in the Work Place portal (CVE-2026-83548) and a high-severity command injection in the Appliance Management Console (CVE-2026-83549). Chained together they give an unauthenticated attacker remote code execution on the appliance, and CISA added both to its KEV catalog with a federal remediation deadline of September 5.

devops digital-security cve vulnerability ci-cd open-source vulnerability-management europe patch-management

A Perfect-10 Bug in a Popular Workflow Automation Tool Has a Patch Deadline of Tomorrow

CISA added Kestra OSS’s CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on September 2, giving US federal agencies until September 5 to patch a CVSS 10.0 flaw that lets an unauthenticated attacker run arbitrary code as root inside the workflow engine. The bug is a one-line authentication mistake, and any organisation running Kestra to orchestrate CI/CD or data pipelines needs to treat the same deadline as urgent, regardless of who set it.

digital-security cve vulnerability-management infrastructure patch-management europe incident-response

Your Office Phone System Just Became a Way In. A SQL Injection Bug in Sangoma Switchvox Is Being Exploited Now

An unauthenticated SQL injection flaw in Sangoma Switchvox, CVE-2026-9586, is being actively exploited to deploy reverse shells and cryptomining malware on internet-exposed VoIP servers. CISA added it to the Known Exploited Vulnerabilities catalog on September 2, and a patch has existed since July 14, meaning every unpatched instance still online has had close to two months to be found.

digital-security devops self-hosted virtualization proxmox cve patch-management europe vulnerability-management

A Three-Year-Old Proxmox Bug Just Started Being Exploited, and the Fix Doesn't Exist for Your Version

Proxmox published advisory PSA-2026-00043-1 on September 1, warning that CVE-2023-54391, a critical authentication bypass in Proxmox VE 7.x, is being actively exploited with public proof-of-concept code. The catch: the fix only ever shipped in 8.0.4, and Proxmox VE 7.x has been end of life since July 2024, so any instance still on that branch has no patch to install, only an upgrade.

digital-security wordpress web-development cve patch-management cms europe small-business

One Contact Form Field Is All It Takes to Hand Over Your WordPress Site

Elementor patched CVE-2026-32475 on August 19, a critical unauthenticated file upload flaw in Elementor Pro’s File Upload form field that lets an attacker plant and run PHP code on any of the roughly 6 million sites running the plugin. Wordfence has already blocked over 190,000 exploitation attempts, and any site still on 4.2.1 or earlier with a published form using that field is exposed.

digital-security devops ai-agents vulnerability-management cve cisa-kev open-source self-hosted europe

Two Critical Bugs, One Weekend: Langflow and Rails Are Being Hit by the Same Attackers

VulnCheck watched attackers chain reconnaissance, credential probing and command-and-control setup against Langflow (CVE-2026-0768, root RCE) and Ruby on Rails (CVE-2026-66066, the KindaRails2Shell file-read-to-RCE flaw) over the same weekend, hitting UK honeypots dozens of times as they hunted for AWS keys, OpenAI keys and Rails secrets.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!