Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.
bleepingcomputer.com
· 2026-09-15
Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.
darkreading.com
· 2026-09-14
A maximum-severity flaw in GitLab's Community and Enterprise editions, patched September 10, is being actively exploited to pull arbitrary files from self-hosted GitLab servers without authentication. WatchTowr researchers say attackers have moved from probing to full exploitation, extracting configuration files, secrets, and SSH settings from compromised systems. CISA has added the bug to its Known Exploited Vulnerabilities list, ordering federal agencies to patch or take affected instances offline.
darkreading.com
· 2026-09-14
Nintendo disclosed a security flaw affecting original Switch consoles that exploits the QR codes used by the Send to Smartphone feature and Super Mario Kart: Home Circuit's wireless pairing. If someone scans the QR code before the owner does, they can connect to the console and run unauthorized code or steal stored account data. Nintendo fixed the issue, tracked as CVE-2026-82079, in firmware update 23.0.0 released September 9.
cnet.com
· 2026-09-14
F5's honeypots detected a month-long scanning campaign exploiting CVE-2026-39364, a high-severity flaw in Vite versions 7.1.0-7.3.2 and pre-8.0.5, that lets unauthenticated attackers bypass access controls via crafted query parameters like ?raw or ?import&raw. Over 800 attacks and roughly 32,000 events were recorded, with attackers hunting for environment files, AWS and Azure credentials, Terraform state files, and system files like /etc/passwd. Most activity came from the US, Belgium, and the Netherlands, with some attackers routing through Google Cloud IPs and also exploiting older Vite access-control bugs.
bleepingcomputer.com
· 2026-09-14
CISA has added a maximum-severity GitLab vulnerability, CVE-2026-85706, to its known exploited vulnerabilities catalog after security firm watchTowr detected attackers scanning the internet for unpatched servers. The flaw allows unauthenticated attackers to read credentials and sensitive files from GitLab instances via a single crafted HTTP request to the repository commits API. GitLab patched the issue in versions 19.3.2, 19.2.6, and 19.1, but federal agencies now have just three days to remediate under a binding directive.
bleepingcomputer.com
· 2026-09-14
Gen Digital researchers found the China-linked group UNC3569 actively exploiting a one-click remote code execution bug (CVE-2026-51990) in Tencent's Sogou Input Method for Windows, an app used by hundreds of millions in China. Attackers chain a malicious sgbiz: link, an unrestricted browser navigation flaw, and an outdated, unsandboxed Chromium 80 engine to silently install the GrayRabbit backdoor once a victim clicks a crafted link.
bleepingcomputer.com
· 2026-09-13
The Dutch NCSC has issued an alert about two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, warning that attacks exploiting them are likely to begin soon even though no public proof-of-concept exploit exists yet. Check Point released patches for both bugs on September 9, covering Security Gateways and Management Servers across multiple supported and end-of-support versions.
bleepingcomputer.com
· 2026-09-12
Wiz researchers found multiple threat actors exploiting two Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, to escalate from a low-privileged anonymous session to full administrator access in under five minutes in some cases. Once inside, attackers installed malicious Groovy plugins to run commands and deployed a custom Rust-based backdoor with command-and-control capabilities, alongside webshells and stolen configuration data. A separate critical flaw, CVE-2026-82329, has also been used by other attackers to mint admin tokens on unpatched instances.
bleepingcomputer.com
· 2026-09-11
GitLab issued emergency patches for CVE-2026-85706, a maximum-severity path traversal flaw in its repository commits API that lets unauthenticated attackers read arbitrary files on vulnerable servers. The company also fixed a second critical bug, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer that could let authenticated Duo Chat users steal credentials and Advanced Search configurations. Both flaws are addressed in versions 19.3.2, 19.2.6, and 19.1.
bleepingcomputer.com
· 2026-09-11
GreyNoise reports that a likely Russian-speaking threat actor deployed hundreds of AI agents using OpenAI's Codex and DeepSeek models to build and launch exploits against two PaperCut NG/MF vulnerabilities. The campaign, which began August 31, compromised at least 440 servers across 395 organizations in 48 countries, mostly in education, with credentials stolen from 280 victims and admin access gained at 12 organizations.
bleepingcomputer.com
· 2026-09-10
Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.
bleepingcomputer.com
· 2026-09-10