{"date_iso":"2026-08-27","date_human":"Thursday, August 27, 2026","generated_utc":"2026-08-27 22:54 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/microsoft-sql-server-rce-vulnerability/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Dark Reading","The Hacker News"],"coverage":5,"cve_ids":["CVE-2019-1068"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability , tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-Microsoft-SQL-Server-RCE-Vulnerability-Exploited-in-Attacks-.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability , tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks. The flaw affects Microsoft SQL Server and can allow an attacker to execute code under the permissions of the SQL Server Database Engine service account. CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server. Successful exploitation could allow an attacker to run malicious commands on a vulnerable database server, with the level\u2026","related":[{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency","link":"https://cybersecuritynews.com/hackers-exploit-ai-infrastructure/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"Microsoft rolls out fix for Windows 11 crashes, gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-fix-for-windows-11-crashes-gaming-issues/","source":"Bleeping Computer","date_rel":"6h ago"},{"title":"Hackers target Microsoft SharePoint RCE chain with PoC exploit","link":"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/","source":"Bleeping Computer","date_rel":"26 Aug"},{"title":"NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions","link":"https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html","source":"The Hacker News","date_rel":"26 Aug"},{"title":"'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month","link":"https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month","source":"Dark Reading","date_rel":"26 Aug"}]},{"title":"Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html","reason":"Windows","category":"News","sources":["Malwarebytes Labs","Microsoft Security","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-65779","CVE-2026-66804","CVE-2026-69550"],"summary":"Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYbQmCgjQOeGU5sXrRRnYNbfxDed_Evv1vYrDL4L4NOguQ5wIxE6glQW7yQvhR1Dzs4Gbddc2ktadXWc2VkaGHE4pvMmjaXHMRuepjwrzefXNHb6B3Shk51VRBQw0etS5WWsS9JuNN4q_Y8lDSFtzKNEgi2X-NvAllwzw5_03HwGdC7iNJc6METEjcUNc/s1600/nodejs.gif","description":"Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&","related":[{"title":"CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69550","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779","source":"Microsoft Security","date_rel":"4h ago"},{"title":"Update Chrome before you browse again","link":"https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-before-you-browse-again","source":"Malwarebytes Labs","date_rel":"26 Aug"},{"title":"New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode","link":"https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html","source":"The Hacker News","date_rel":"26 Aug"},{"title":"You don't want this Sleepwalker backdoor on your Windows machine","link":"https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021","source":"The Register Security","date_rel":"24 Aug"}]},{"title":"Android Malware Hijacks Update System for Car Head Units","link":"https://www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.","source":"Dark Reading","date_rel":"26 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc461573f3500ab14/6a8f24afbec2b8b5acf318e4/carheadunit-AndreyPopov-Getty-2241387705.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Android 17 adds ECH support to make web browsing harder to track","link":"https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Beware of fake Indeed interview apps used to install spyware","link":"https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware","source":"Malwarebytes Labs","date_rel":"26 Aug"},{"title":"WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android","link":"https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html","source":"The Hacker News","date_rel":"25 Aug"}]},{"title":"CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs","link":"https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html","reason":"Citrix","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix\u2026","source":"The Hacker News","date_rel":"11h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsOm0ydTRNpwfiKMNN7TGZyoellV9LHrcra7ES8hU8PvT6haNsS-QQ5IlystrzP1eq5jiIRfyykIZyB5JKrya5K4ryBRp9gKAmsoVW7OMis-YT4T6jnpbN11M8mUnPn-2yY-caG31-iXmDAhJ9CTbRg8r1UPWWqCob_S8St7McsKCM-4I36jD_xqE8D3BS/s1600/cisa-flaws.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in","related":[{"title":"CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products","link":"https://www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/","source":"Infosecurity Magazine","date_rel":"7h ago"},{"title":"CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday","link":"https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploiting-citrix-netscaler-rce-flaw-in-attacks/","source":"Bleeping Computer","date_rel":"9h ago"},{"title":"Citrix security advisory (AV26-645) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645","source":"CCCS Alerts & Advisories","date_rel":"26 Aug"}]},{"title":"Learn How to Build Security Operations Ready for AI-Powered Attacks","link":"https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html","reason":"Teams","category":"News","sources":["Bleeping Computer","Microsoft Security Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqwLeHISYWaiVNUxkANuqw6ob8Exu7_9CIEt6uHbsNa7mcNUkSWZqNZHEL3_kqPPHXVq4RGTxqZZhMdybwcVVT28qCihLUi0I5ghW9Xk5sVDB2u2kJqULx-_FEcsEHuTCU5vIwReQZghbj8HjQD4zq8H1yiGSYNlmNC25YkViZxlqndOhIp1CD2s_sLlc/s1600/wiz-webinar.jpg","description":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or","related":[{"title":"\u200b\u200b\u200b\u200b\u200b\u200bWhat\u2019s new in Microsoft Security: August 2026","link":"https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/","source":"Microsoft Security Blog","date_rel":"2h ago"},{"title":"How Threat Research and MDR Help SMBs Build a Defensive Edge","link":"https://www.bleepingcomputer.com/news/security/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"What the Data Says About AI in Security Operations in 2026","link":"https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html","source":"The Hacker News","date_rel":"7h ago"},{"title":"The patch window is collapsing: Why security needs a new control plane","link":"https://azure.microsoft.com/en-us/blog/the-patch-window-is-collapsing-why-security-needs-a-new-control-plane/","source":"Microsoft Security Blog","date_rel":"25 Aug"},{"title":"Frontier AI: Vulnerability Management's Systemic Revolution","link":"https://thehackernews.com/2026/08/frontier-ai-vulnerability-managements.html","source":"The Hacker News","date_rel":"25 Aug"}]},{"title":"Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers","link":"https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html","reason":"Amazon","category":"News","sources":["404 Media","CyberScoop","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUdyQnHdjoEXFnc-5nB-6oglAbvpOYwuWqfjYkgeKH6HaqUjosKOHhmEQ_7StMkMBv53gz27Ilg-15yRaQ-hxoYi0ASuRMOCuPTHa8gP6a6PzYSewTWsDkKAx8dsMByZXDYDlRE1wRYoCvE7NuYqXdCpZ8_Y4E4tAUy0SBFl0S_XxLvpnjFRbqat0EwggW/s1600/kiro-amazon.jpg","description":"Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of","related":[{"title":"100-plus companies call for \u2018global surge\u2019 in AI-powered cyber defense","link":"https://cyberscoop.com/ai-cyber-defense-global-surge/","source":"CyberScoop","date_rel":"8m ago"},{"title":"Inside the Warehouse Where Amazon Scans and Destroys Books for AI Training","link":"https://www.404media.co/inside-the-warehouse-where-amazon-scans-and-destroys-books-for-ai-training/","source":"404 Media","date_rel":"26 Aug"},{"title":"Podcast: Cops Are Making Fake Flock Cameras and Amazon Packages","link":"https://www.404media.co/podcast-cops-are-making-fake-flock-cameras-and-amazon-packages/","source":"404 Media","date_rel":"26 Aug"}]},{"title":"Hackers Exploit ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data","link":"https://cybersecuritynews.com/hackers-exploit-owncloud/","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Exploit-ownCloud-and-WordPress-Flaws-to-Steal-Philippine-Nuclear-and-Naval-Data.webp","description":"A suspected Chinese-speaking operator exploited known ownCloud and WordPress weaknesses to collect sensitive information from a Philippine nuclear research body and a marine engineering company that serves the Philippine Navy. The intrusion shows how unpatched internet-facing systems can expose data with national-security value. The activity came to light after investigators found an openly accessible server containing attack tools, transfer logs, and stolen files. The collection reportedly included reactor-related records, staff data, planning documents, encrypted credential stores, and a\u2026","related":[{"title":"Critical Avada WordPress theme flaw enables zero-click RCE","link":"https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access","link":"https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html","source":"The Hacker News","date_rel":"25 Aug"}]},{"title":"GitLab Fixes Claude AI Agent Flaw That Could Execute Arbitrary Commands in CI Pipeline","link":"https://cybersecuritynews.com/gitlab-fixes-claude-ai-agent-flaw/","reason":"Gitlab","category":"News","sources":["Cyber Security News","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts. The flaw, tracked\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/GitLab-Fixes-Claude-AI-Agent-Flaw-That-Could-Execute-Arbitrary-Commands-in-CI-Pipelines.webp","description":"GitLab has released security updates to fix a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to execute arbitrary commands within CI pipeline contexts. The flaw, tracked as CVE-2026-18252, affects GitLab Enterprise Edition installations and carries a CVSS score of 7.3. The company issued patched versions GitLab 19.3.1, 19.2.5, and 19.1.7 on August 26, 2026. GitLab strongly urged self-managed customers to update immediately. GitLab.com is already running the corrected software, while GitLab Dedicated customers do not need to take action. The\u2026","related":[{"title":"Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps","link":"https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops","source":"Wiz Research","date_rel":"6h ago"}]},{"title":"ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories","link":"https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html","reason":"Sharepoint","category":"News","sources":["Microsoft Security","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-65660"],"summary":"A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwWCb2shFhaav60Wjr2-8DoStCVaQrYqkE6EBZ8F5sREap-Khi19y-w9NVmFHyHosV6xVB0fTeN_DcSpGIyCZ621SnjqZozRVG70ceOey_D8djA5r5rpP9tFkRSESgs4kHZilTMoz2y8uqX-iTLR0JjjZkhypYjCCAEvQKzyU7xarQpt3sYvJc-fnWSWlb/s1600/threats.jpg","description":"A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different","related":[{"title":"CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65660","source":"Microsoft Security","date_rel":"4h ago"}]},{"title":"Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes","link":"https://thehackernews.com/2026/08/fake-apple-support-ai-calls-target.html","reason":"Apple","category":"News","sources":["Malwarebytes Labs","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as\u2026","source":"The Hacker News","date_rel":"26 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ7ibePn1YRPkAC27RIrMl_O-41pR7ieF0Mkpr8WUTkzCddWjpttUiIrXWI3CYGukgNR8eoppnOFUYjzSbEm66XiK4ttGge7-KicMnSf49N5L-wKXyf4NIzWi1Yi5JbKQXPYpmtWfZfMADrNswG9-ZfOOE9LjWwUFl7twHmvEskgU9iXPR5AGEQ4hUETo/s1600/iphone-passcode.jpg","description":"Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures across","related":[{"title":"Fake Apple Pay charge brings the classic tech support scam to your phone","link":"https://www.malwarebytes.com/blog/scams/2026/08/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone","source":"Malwarebytes Labs","date_rel":"6h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-60004","vendor":"Gitea","product":"Gitea","severity":"CRITICAL","score":9.8,"description":"Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.","cwe":"CWE-94","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-08-28","epss":0.824,"url":"https://cve.blackmesa.ca/?q=CVE-2026-60004"},{"id":"CVE-2026-32566","vendor":"WordPress","product":"ACPT (Pro) - Custom Post Types Plugin for WordPress","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":0.0045,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32566"},{"id":"CVE-2026-78286","vendor":"INFINITUM FORM","product":"Geo Controller","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0053,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78286"},{"id":"CVE-2026-78292","vendor":"hashthemes","product":"Hash Form","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":0.0053,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78292"},{"id":"CVE-2026-74232","vendor":"Zbtlink","product":"L3_V2_8","severity":"CRITICAL","score":9.8,"description":"Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2\u2026","cwe":"CWE-300","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74232"},{"id":"CVE-2026-74233","vendor":"Zbtlink","product":"WE1326","severity":"CRITICAL","score":9.8,"description":"Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and M\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-74233"},{"id":"CVE-2026-59354","vendor":"Broadcom","product":"Spring Security (OAuth2 Authorization Server module)","severity":"CRITICAL","score":9.6,"description":"In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields su\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":0.0025,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59354"},{"id":"CVE-2026-59270","vendor":"Spring","product":"Spring Security","severity":"CRITICAL","score":9.4,"description":"Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.\nSpring Security 7.1.0\nSpring Security 7.0.0 - 7.0.6\nSpr\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":0.0029,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59270"},{"id":"CVE-2026-32479","vendor":"CODEPRESS IT Solutions LLC","product":"Visitor Traffic Real Time Statistics Pro","severity":"CRITICAL","score":9.3,"description":"Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-32479"},{"id":"CVE-2026-78260","vendor":"ePayco","product":"Epayco","severity":"CRITICAL","score":9.3,"description":"Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":0.0038,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78260"}],"vendor_spikes":[{"vendor":"Unknown","count":66,"critical_count":0},{"vendor":"Spring","count":40,"critical_count":1},{"vendor":"WordPress","count":24,"critical_count":1},{"vendor":"Dell","count":13,"critical_count":1},{"vendor":"Apple","count":8,"critical_count":0},{"vendor":"WeblateOrg","count":8,"critical_count":0},{"vendor":"wintercms","count":7,"critical_count":0},{"vendor":"WP Manage Ninja","count":7,"critical_count":1},{"vendor":"Microsoft","count":6,"critical_count":0},{"vendor":"TOOOLS","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":280,"has_news_data":true,"has_cve_data":true}