{"date_iso":"2026-08-28","date_human":"Friday, August 28, 2026","generated_utc":"2026-08-28 22:59 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions","link":"https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated\u2026","source":"The Hacker News","date_rel":"26 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz4GD3giiT1DIPT5Q13XvCZcwC8-STaGCZ3KbqUzQ5Q9oniGfA0Odbqfmwva6B-xSSTD2QG1wdqu5fFOleaBVFSA-t3ZfeqpcrYOEomdygWsZOONJXYcpxhRdT-EbTS_DZ0zYLrH_-1YN7TjXCsDuIj0I2G53mFT0df1HC3tjUdUQ5MCdHdEo27rDE2QEm/s1600/docusign.jpg","description":"Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that","related":[{"title":"Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn","link":"https://www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"Windows 11 KB5120998 update released with 35 changes and fixes","link":"https://www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/","source":"Bleeping Computer","date_rel":"6h ago"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Microsoft rolls out fix for Windows 11 crashes, gaming issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-fix-for-windows-11-crashes-gaming-issues/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month","link":"https://www.darkreading.com/endpoint-security/novacookies-steals-microsoft-365-sessions-320-a-month","source":"Dark Reading","date_rel":"26 Aug"}]},{"title":"Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix","link":"https://cybersecuritynews.com/deploy-amatera-stealer/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-65779","CVE-2026-66804","CVE-2026-69550"],"summary":"A fake student resume is being used to place a remote-access tool on researchers\u2019 Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Compromise-Hundreds-of-WordPress-Sites-to-Deploy-Amatera-Stealer-via-ClickFix.webp","description":"A fake student resume is being used to place a remote-access tool on researchers\u2019 Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background. The lure claims to come from a recent Beijing Institute of Technology graduate seeking research work in electrical engineering, energy systems and applied AI. That focus points to professors and laboratory staff as likely targets, rather than ordinary corporate recruiters, and turns academic\u2026","related":[{"title":"Hackers Use Fake Student Resume to Secretly Install Malware on Researchers\u2019 Computers","link":"https://cybersecuritynews.com/hackers-use-fake-student-resume/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html","source":"The Hacker News","date_rel":"27 Aug"},{"title":"CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69550","source":"Microsoft Security","date_rel":"27 Aug"},{"title":"CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804","source":"Microsoft Security","date_rel":"27 Aug"},{"title":"CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779","source":"Microsoft Security","date_rel":"27 Aug"},{"title":"New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode","link":"https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html","source":"The Hacker News","date_rel":"26 Aug"}]},{"title":"CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/linux-kernel-privilege-escalation-vulnerability-exploited/","reason":"CVE-2026-53362","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2023-49105","CVE-2026-53362"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability , tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting\u2026","source":"Cyber Security News","date_rel":"9h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/CISA-Warns-of-Linux-Kernel-Vulnerability-privilege-escalation-Vulnerability-Exploited-in-Attacks-.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability , tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks. The issue affects the Linux kernel\u2019s IPv6 networking subsystem. It could allow a local attacker to gain elevated privileges on a vulnerable system. CVE-2026-53362 is currently described as an unspecified Linux kernel vulnerability. However, CISA said the flaw can enable privilege escalation through the IPv6 networking component . Privilege\u2026","related":[{"title":"OpenAI Agents Exploited Linux Kernel Flaw on Company\u2019s Own Systems","link":"https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"27 Aug"}]},{"title":"CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs","link":"https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html","reason":"Citrix","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix\u2026","source":"The Hacker News","date_rel":"27 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsOm0ydTRNpwfiKMNN7TGZyoellV9LHrcra7ES8hU8PvT6haNsS-QQ5IlystrzP1eq5jiIRfyykIZyB5JKrya5K4ryBRp9gKAmsoVW7OMis-YT4T6jnpbN11M8mUnPn-2yY-caG31-iXmDAhJ9CTbRg8r1UPWWqCob_S8St7McsKCM-4I36jD_xqE8D3BS/s1600/cisa-flaws.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in","related":[{"title":"CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products","link":"https://www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/","source":"Infosecurity Magazine","date_rel":"27 Aug"},{"title":"CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday","link":"https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploiting-citrix-netscaler-rce-flaw-in-attacks/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"Citrix security advisory (AV26-645) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645","source":"CCCS Alerts & Advisories","date_rel":"26 Aug"}]},{"title":"19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code","link":"https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html","reason":"Chrome","category":"News","sources":["Malwarebytes Labs","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining\u2026","source":"The Hacker News","date_rel":"20m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_QtvF-9M9imh55UP7qeyFUNhKknBwEcmcbIa34vndzIHinEk754vasbvTqILRNrtp6BDpuR8VzAyk0_Wt1tJB4hjUlgaO5Rb6Wru-WoXlrCPIXLr0I_oBhA7BwQDoO3MH82uloaG-qXyHAloI7r2zuWNfygFNeiSYAZeWyDn8_smuzrgvsvk0eQEX5klW/s1600/1000103889.jpg","description":"Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active","related":[{"title":"Update Chrome before you browse again","link":"https://www.malwarebytes.com/blog/bugs/2026/08/update-chrome-before-you-browse-again","source":"Malwarebytes Labs","date_rel":"26 Aug"}]},{"title":"Learn How to Build Security Operations Ready for AI-Powered Attacks","link":"https://thehackernews.com/2026/08/learn-how-to-build-security-operations.html","reason":"Teams","category":"News","sources":["Bleeping Computer","Microsoft Security Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate\u2026","source":"The Hacker News","date_rel":"27 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRqwLeHISYWaiVNUxkANuqw6ob8Exu7_9CIEt6uHbsNa7mcNUkSWZqNZHEL3_kqPPHXVq4RGTxqZZhMdybwcVVT28qCihLUi0I5ghW9Xk5sVDB2u2kJqULx-_FEcsEHuTCU5vIwReQZghbj8HjQD4zq8H1yiGSYNlmNC25YkViZxlqndOhIp1CD2s_sLlc/s1600/wiz-webinar.jpg","description":"Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or","related":[{"title":"\u200b\u200b\u200b\u200b\u200b\u200bWhat\u2019s new in Microsoft Security: August 2026","link":"https://www.microsoft.com/en-us/security/blog/2026/08/27/whats-new-in-microsoft-security-august-2026/","source":"Microsoft Security Blog","date_rel":"23h ago"},{"title":"How Threat Research and MDR Help SMBs Build a Defensive Edge","link":"https://www.bleepingcomputer.com/news/security/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"What the Data Says About AI in Security Operations in 2026","link":"https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html","source":"The Hacker News","date_rel":"27 Aug"},{"title":"The patch window is collapsing: Why security needs a new control plane","link":"https://azure.microsoft.com/en-us/blog/the-patch-window-is-collapsing-why-security-needs-a-new-control-plane/","source":"Microsoft Security Blog","date_rel":"25 Aug"}]},{"title":"Android Malware Hijacks Update System for Car Head Units","link":"https://www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs"],"coverage":3,"cve_ids":[],"summary":"Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.","source":"Dark Reading","date_rel":"26 Aug","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc461573f3500ab14/6a8f24afbec2b8b5acf318e4/carheadunit-AndreyPopov-Getty-2241387705.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Android 17 adds ECH support to make web browsing harder to track","link":"https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-web-browsing-harder-to-track/","source":"Bleeping Computer","date_rel":"27 Aug"},{"title":"Beware of fake Indeed interview apps used to install spyware","link":"https://www.malwarebytes.com/blog/scams/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware","source":"Malwarebytes Labs","date_rel":"26 Aug"}]},{"title":"Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers","link":"https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html","reason":"Amazon","category":"News","sources":["404 Media","CyberScoop","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via\u2026","source":"The Hacker News","date_rel":"27 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUdyQnHdjoEXFnc-5nB-6oglAbvpOYwuWqfjYkgeKH6HaqUjosKOHhmEQ_7StMkMBv53gz27Ilg-15yRaQ-hxoYi0ASuRMOCuPTHa8gP6a6PzYSewTWsDkKAx8dsMByZXDYDlRE1wRYoCvE7NuYqXdCpZ8_Y4E4tAUy0SBFl0S_XxLvpnjFRbqat0EwggW/s1600/kiro-amazon.jpg","description":"Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindgard. The latest version of","related":[{"title":"100-plus companies call for \u2018global surge\u2019 in AI-powered cyber defense","link":"https://cyberscoop.com/ai-cyber-defense-global-surge/","source":"CyberScoop","date_rel":"21h ago"},{"title":"Inside the Warehouse Where Amazon Scans and Destroys Books for AI Training","link":"https://www.404media.co/inside-the-warehouse-where-amazon-scans-and-destroys-books-for-ai-training/","source":"404 Media","date_rel":"26 Aug"},{"title":"Podcast: Cops Are Making Fake Flock Cameras and Amazon Packages","link":"https://www.404media.co/podcast-cops-are-making-fake-flock-cameras-and-amazon-packages/","source":"404 Media","date_rel":"26 Aug"}]},{"title":"PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions","link":"https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html","reason":"Exploited Papercut Zeroday","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3avAnoYOOKqF8JpZv9Lng1lKE0AqmHOqM-Mq2T297NQrtDBM90yMYIzzVMHgzqytcCvFz7LuBXoPp-d9mRh0_dywBaM8NxZaiKPG0gDuYbSt2oRJdxSkHG5tWjxAMKvWUYZe6YINf_-7i5zUS7xGrDcaXulRvT5jVihWDJzAHSlaXQ6UYlHa6cPMpxbDC/s1600/papercut.jpg","description":"PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's \"aware of confirmed customer incidents and is treating this matter with the highest priority.\" An","related":[{"title":"PaperCut warns of NG, MF flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"23h ago"}]},{"title":"Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports","link":"https://cybersecuritynews.com/hackers-steal-data-of-three-uk-airports/","reason":"Cyberattack Customers Airports","category":"News","sources":["Cyber Security News","The Record"],"coverage":2,"cve_ids":[],"summary":"Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London\u2026","source":"Cyber Security News","date_rel":"10h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Steal-Data-of-8.7-Million-Customers-in-Cyberattack-on-Three-UK-Airports.webp","description":"Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London Stansted Airport. The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes and vehicle registration details. The attackers also demanded a ransom for the stolen data, but MAG said it refused to pay. MAG stated that passenger safety, airport operations and aviation security were not affected by the breach\u2026","related":[{"title":"Cyberattack on Manchester Airports Group exposes data of 8.7 million customers","link":"https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info","source":"The Record","date_rel":"27 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82222","vendor":"Liquid Web / StellarWP","product":"GiveWP","severity":"CRITICAL","score":10.0,"description":"Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.\n\nThis issue affects GiveWP: from n/a through 4.16.7.1.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82222"},{"id":"CVE-2026-19092","vendor":"WordPress","product":"Tutor LMS","severity":"CRITICAL","score":9.8,"description":"The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":0.0035,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19092"},{"id":"CVE-2026-81934","vendor":"Redis","product":"Redis","severity":"CRITICAL","score":9.8,"description":"Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary co\u2026","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","epss":0.0059,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81934"},{"id":"CVE-2026-69658","vendor":"Ebyte","product":"Ebyte NE2-D11 Firmware","severity":"CRITICAL","score":9.8,"description":"MQTT credentials and control traffic are transmitted in cleartext, \nexposing sensitive information to network-level attackers. This may \nenable unauthorized device impersonation and disruption of messaging \nfunctions.","cwe":"CWE-319","kev":false,"kev_action":"","kev_due":"","epss":0.0024,"url":"https://cve.blackmesa.ca/?q=CVE-2026-69658"},{"id":"CVE-2026-71187","vendor":"Ebyte","product":"Ebyte NE2-D11 Firmware","severity":"CRITICAL","score":9.8,"description":"The Ebyte device relies on client side authentication logic that can be \nreproduced by unauthenticated users. An attacker may generate valid \nauthentication requests and bypass authentication to obtain \nadministrative access to the device.","cwe":"CWE-603","kev":false,"kev_action":"","kev_due":"","epss":0.0052,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71187"},{"id":"CVE-2026-73125","vendor":"Ebyte","product":"Ebyte NE2-D11 Firmware","severity":"CRITICAL","score":9.8,"description":"Ebyte device web management interface does not consistently enforce \nauthentication before granting access to administrative functionality. \nAn unauthenticated remote attacker could access sensitive configuration \ninformation, modify device\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0053,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73125"},{"id":"CVE-2026-76179","vendor":"Ebyte","product":"Ebyte NE2-D11 Firmware","severity":"CRITICAL","score":9.8,"description":"An improper protection of authentication tokens vulnerability exists in \ncertain Ebyte gateway products. Authentication tokens used by the web \nmanagement interface are insufficiently protected during client-side \nsession handling, which ma\u2026","cwe":"CWE-598","kev":false,"kev_action":"","kev_due":"","epss":0.0043,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76179"},{"id":"CVE-2026-76943","vendor":"Xiiaozet","product":"Xiiaozet LK100W","severity":"CRITICAL","score":9.8,"description":"Xiiaozet LK100Wt contains an authentication weakness within an \nadministrative service that may allow an attacker to bypass intended \naccess controls and obtain command execution capabilities. Successful \nexploitation could allow unauthoriz\u2026","cwe":"CWE-288","kev":false,"kev_action":"","kev_due":"","epss":0.0067,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76943"},{"id":"CVE-2026-78239","vendor":"Xiiaozet","product":"Xiiaozet LK100W","severity":"CRITICAL","score":9.8,"description":"Xiiaozet LK100W exposes a critical management function that can be \ninvoked without authentication, allowing a remote attacker to enable \nadministrative services that should be restricted. Successful \nexploitation may permit unauthorized ac\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":0.0055,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78239"},{"id":"CVE-2026-82082","vendor":"Green-Computing","product":"NUMail","severity":"CRITICAL","score":9.8,"description":"NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":0.015,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82082"}],"vendor_spikes":[{"vendor":"Linux","count":126,"critical_count":0},{"vendor":"Unknown","count":40,"critical_count":0},{"vendor":"Spring","count":35,"critical_count":0},{"vendor":"WordPress","count":32,"critical_count":2},{"vendor":"WatchGuard","count":29,"critical_count":0},{"vendor":"Open-Xchange GmbH","count":25,"critical_count":1},{"vendor":"Ebyte","count":12,"critical_count":4},{"vendor":"Microsoft","count":11,"critical_count":0},{"vendor":"MongoDB","count":9,"critical_count":0},{"vendor":"budibase","count":8,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":480,"has_news_data":true,"has_cve_data":true}