CISA has updated its Known Exploited Vulnerabilities catalog to warn that ransomware operators are now actively abusing a critical remote-code-execution bug in WatchGuard Firebox firewalls, first flagged as exploited back in December. The flaw, an out-of-bounds write bug affecting multiple Fireware OS versions, lets unauthenticated attackers run code remotely, particularly on devices configured for IKEv2 VPN. Shadowserver data shows nearly 9,000 Firebox devices remain unpatched online nine months after fixes were released.
bleepingcomputer.com
· 2026-09-10
Cisco has verified that attackers are actively exploiting CVE-2026-20079, a maximum-severity (CVSS 10.0) flaw in its Secure Firewall Management Center software that lets unauthenticated remote attackers bypass login and run commands as root. The company first disclosed the bug in March without evidence of exploitation, but updated its advisory this week to acknowledge PSIRT detected active attacks in August, though it hasn't shared attacker identity or attack timeline details. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch.
bleepingcomputer.com
· 2026-09-09
CERT/CC disclosed that Skullcandy Dime 3 earbuds running firmware 1.0.0.28 accept Bluetooth pairing from nearby devices without any user approval, due to a flaw in the Airoha Bluetooth Audio SDK tracked as CVE-2025-20701. Skullcandy has released firmware 1.0.0.30 to fix the bug, but there is no way for users to update their earbuds manually or through the companion app.
bleepingcomputer.com
· 2026-09-09
Microsoft released patches for 974 vulnerabilities across Windows and other products, its largest single update batch ever, surpassing July's record of 570 fixes. The release includes two actively exploited zero-day flaws that let attackers escalate privileges, plus 113 critical-rated bugs including a dangerous DNS weakness and a Windows Shell remote code execution flaw scoring 9.8 out of 10 in severity.
krebsonsecurity.com
· 2026-09-08
Microsoft's September security update addressed 974 unique CVEs, the largest Patch Tuesday release yet, including two zero-day flaws already being actively exploited. Windows accounted for the vast majority of fixes at 723, with Office, SQL, SharePoint and Azure making up the rest, while 13 issues were rated Critical.
darkreading.com
· 2026-09-08
Sophos researchers detailed a second-stage Linux rootkit infecting F5 BIG-IP APM systems, likely delivered after attackers exploited the critical CVE-2025-53521 remote code execution flaw. The malware infects Apache's httpd process, hooks internal functions to intercept PHP file loading, and injects a web shell into memory rather than writing files to disk, while also altering SELinux settings and persisting through firmware upgrades. ESET separately analyzed the same threat under the name PoisonedRefresh.
bleepingcomputer.com
· 2026-09-08
SAP's September 2026 security update fixes 20 vulnerabilities, headlined by CVE-2026-44756, a critical buffer overflow in the SAP Kernel's Extended Passport Protocol library dubbed OVERPASS by Onapsis researchers. The bug allows unprivileged attackers to remotely execute commands with admin rights via SAP's Internet Communication Manager, and Onapsis estimates over 10,000 internet-facing SAP systems are exposed. SAP also patched CVE-2026-58240, dubbed S4GET, a missing authentication issue in the NetWeaver Message Server that lets unauthenticated attackers compromise an entire SAP cluster.
bleepingcomputer.com
· 2026-09-08
Adobe issued an emergency hotfix for a maximum-severity flaw in Magento and Adobe Commerce that attackers have exploited since at least September 4 to install a hidden backdoor. Security firm Sansec found the malware disguised its command server as an NTP time server, though compromised sites still leaked telltale fake 'Payment Transaction Failed' emails. Adobe's fix, labeled VULN-39341, covers Adobe Commerce, Commerce B2B, and Magento Open Source across multiple version branches.
bleepingcomputer.com
· 2026-09-08
Attackers are combining two newly disclosed MikroTik RouterOS vulnerabilities, an SSH authentication bypass (CVE-2026-67276) and a privilege escalation bug (CVE-2026-86060), to seize full control of routers with SSH exposed to the internet. Poland's CERT, which found the flaws with AI assistance, calls the combined exploit 'MikroTrick' and confirms it is being used in real-world attacks. MikroTik patched the issues in RouterOS versions released September 3, alongside a related bandwidth-test flaw that can leak memory or crash devices.
bleepingcomputer.com
· 2026-09-07
N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218, a maximum-severity remote code execution bug that lets unauthenticated attackers run code on unpatched, internet-exposed servers. Shadowserver counts nearly 1,500 exposed N-central instances, mostly in the US and Europe, while security firm Huntress suspects the flaw, along with two related authentication-bypass bugs, may already have been exploited as a zero-day in at least one customer breach.
bleepingcomputer.com
· 2026-09-07
Security firm Rietta rolled out an emergency hotfix across its client base on July 29, 2026, after a Ruby on Rails ActiveStorage vulnerability—later named KindaRails2Shell and tracked as CVE-2026-66066—jumped from an unrated update to a 9.5/10 CVSS severity score within hours. The flaw, discovered by researchers at Ethiack, allows arbitrary file read and remote code execution through variant processing in Active Storage, a core Rails component used in Rails 8 and newer.
rietta.com
· 2026-09-04
Security researchers at Previdian and Belgium's national cyber center report that hackers are actively probing a critical authentication-bypass vulnerability in Citrix NetScaler appliances, tracked as CVE-2026-19490. The flaw affects NetScaler devices configured as AAA virtual servers or Gateways, and exploitation attempts began after a working proof-of-concept was posted online. Citrix patched the issue in mid-August but had not confirmed active exploitation as of its most recent advisory.
bleepingcomputer.com
· 2026-09-04