Check Point has issued security updates for CVE-2026-91843, a stack-based buffer overflow in the login process of its Security Management Server and Log Server products. The flaw allows unauthenticated attackers to remotely execute code with root privileges in low-complexity attacks requiring no user interaction. Check Point says it isn't aware of active exploitation but has provided detection guidance and interim mitigations for customers who can't immediately apply the fix.
bleepingcomputer.com
· 2026-09-18
CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.
darkreading.com
· 2026-09-17
Cisco has issued patches for a maximum-severity flaw in its Identity Services Engine and ISE-PIC products that allows attackers to bypass authentication on an API endpoint and gain unauthorized administrative access, regardless of configuration. Cisco's security team confirmed the vulnerability, tracked as CVE-2026-76460, is being actively exploited and there are no workarounds available, making immediate patching the only defense.
bleepingcomputer.com
· 2026-09-17
Google disclosed that a vulnerability in Pixel phones' modem software, tracked as CVE-2026-58704, was exploited in a limited number of targeted attacks before being patched this week. The flaw allowed attackers to escalate privileges from the isolated modem component into the phone's broader system without any user interaction, a so-called zero-click exploit. Google has not identified who carried out the attacks.
techcrunch.com
· 2026-09-16
CISA has added a critical ScreenConnect vulnerability, now designated CVE-2026-84869, to its known exploited vulnerabilities catalog after confirming attackers are actively abusing it. The flaw stems from missing authorization checks that let low-privilege users transfer and execute files during active remote sessions without host confirmation, and it has been fixed in ScreenConnect 26.6.5. Federal agencies have been given three days to patch, while Shadowserver reports over 1,000 unpatched, internet-exposed ScreenConnect servers, mostly in North America and Europe.
bleepingcomputer.com
· 2026-09-16
Google's September 2026 security bulletin fixes 110 vulnerabilities in Pixel devices, including a high-severity flaw (CVE-2026-58704) in the Cellular Modem component that is being exploited in limited, targeted attacks. The bug stems from a logic error that lets an attacker on an adjacent network bypass permissions and escalate privileges without user interaction. The update, rolling out at patch level 2026-09-05, also addresses 12 critical remote code execution bugs and 89 privilege escalation issues.
bleepingcomputer.com
· 2026-09-16
Researchers from the DREAM Security Research Team disclosed a pre-authentication buffer overflow in the LINEMODE SLC negotiation handler of GNU inetutils' Telnet server, a flaw dating back to 1994. Because many vendors' Telnetd implementations, including those in major Linux distributions, derive from the same codebase, the bug's reach extends well beyond a single project.
labs.watchtowr.com
· 2026-09-16
Microsoft's latest Patch Tuesday addressed close to 1,000 vulnerabilities, but the scale of the update introduced new problems for some users. The company has since issued out-of-band emergency patches to correct issues caused by the original round of fixes.
darkreading.com
· 2026-09-15
Acronis has patched a high-severity local privilege escalation flaw, tracked as CVE-2026-87886, in its backup add-ons for cPanel/WHM and Plesk. The company says it has seen limited, targeted exploitation attempts against affected deployments, based on a report from one potentially affected customer. Fixed versions are 1.9.3 HF3 for cPanel/WHM and 1.8.11 for Plesk.
bleepingcomputer.com
· 2026-09-15
Hackers are exploiting an unauthenticated file-upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin for WordPress, versions 2.0.3.1 and earlier, to install PHP webshells. Wordfence says its firewall has blocked over 100,000 attack attempts, with spikes in June, July and August, and the shells allow attackers to gather site information and upload further malicious files.
bleepingcomputer.com
· 2026-09-15
PaperCut disclosed active exploitation of PaperCut NG/MF servers on August 27 with no CVE, no available exploit sample, and no patch. An emergency fix issued the next day was bypassed within hours, and a third patch only arrived on September 1, leaving customers exposed for roughly six days while attackers were already using the flaw in live attacks. A security researcher uses the episode to argue that the industry's old assumptions about response timelines no longer hold.
bleepingcomputer.com
· 2026-09-15
CISA has updated its Known Exploited Vulnerabilities catalog to flag ransomware gangs actively exploiting a critical VMware vCenter directory traversal flaw, CVE-2026-59310, patched by Broadcom in July. The bug had already been abused by a suspected APT group to compromise over 361 IP addresses across 47 countries, and Shadowserver now tracks more than 450 exposed vCenter servers online.
bleepingcomputer.com
· 2026-09-15