{"date_iso":"2026-09-03","date_human":"Thursday, September 3, 2026","generated_utc":"2026-09-03 17:01 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft to Expand Memory Integrity Protection Across Windows Devices","link":"https://cybersecuritynews.com/memory-integrity-protection-windows/","reason":"Microsoft","category":"News","sources":["Any.Run Malware Analysis","Bleeping Computer","Cyber Security News","Dark Reading","Malwarebytes Labs","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations. The change\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-to-Expand-expand-memory-integrity-protection-across-Windows-devices.webp","description":"Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations. The change is designed to protect Windows from sophisticated attacks that attempt to tamper with critical operating system components, while requiring little or no additional configuration. Memory Integrity, built on Virtualization-based Security (VBS), uses hardware-assisted virtualization to isolate sensitive Windows components and prevent malicious code from modifying protected kernel\u2026","related":[{"title":"Microsoft: KB5120998 mouse reset bug affects only non-English PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Microsoft says KB5120998 Windows update resets desktop settings","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Microsoft Teams, Outlook Crashes Following August 2026 Updates on ARM-Based Devices","link":"https://cybersecuritynews.com/microsoft-teams-outlook-crashes/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users","link":"https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users","source":"Dark Reading","date_rel":"2 Sep"},{"title":"Fake Software Installers Disable Windows Update and Weaken Microsoft Defender","link":"https://thehackernews.com/2026/09/fake-software-installers-disable.html","source":"The Hacker News","date_rel":"2 Sep"}]},{"title":"Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs","link":"https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html","reason":"Google","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program\u2026","source":"The Hacker News","date_rel":"22h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu5sAuC-e7tUigtaAj0gicqzy_kWZTZRujpV3IxqGW1wr_VCuXbKXG7M-nNIac5QO2GY_KtEQ8HfnUENc6JZpS8haeGQIvOH4EddDvrQTJwXY2kkZcz41JbeT1_YhVuyrArJV4sUB3hrT9dFIazMbT-_8hLxg0jrQzHLPLv_h3bNb98puP5yVwgA1zoIsQ/s1600/aiai.jpg","description":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. \"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them","related":[{"title":"Outsider Phishing Kit Survives Takedown With 700 New Pages","link":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Google security advisory (AV26-874)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-874","source":"CCCS Alerts & Advisories","date_rel":"2 Sep"},{"title":"Two critical Chrome flaws put users at risk on malicious websites","link":"https://www.malwarebytes.com/blog/bugs/2026/09/two-critical-chrome-flaws-put-users-at-risk-on-malicious-websites","source":"Malwarebytes Labs","date_rel":"2 Sep"},{"title":"Microsoft Defender flags legitimate Google search links as malicious","link":"https://www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/","source":"Bleeping Computer","date_rel":"2 Sep"},{"title":"Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems","link":"https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html","source":"The Hacker News","date_rel":"1 Sep"}]},{"title":"Rockwell Automation 1756-ENBT Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05","reason":"Rockwell","category":"Advisory","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","CISA ICS Advisories","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT\u2026","source":"CISA Alerts & Advisories","date_rel":"5h ago","thumbnail":"","description":"View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters\u2026","related":[{"title":"Rockwell Automation ArmorStart LT","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"Rockwell Automation ControlFLASH","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"Rockwell Automation 1756-ENBT Module","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-05","source":"CISA ICS Advisories","date_rel":"5h ago"},{"title":"Rockwell Automation ArmorStart LT","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-04","source":"CISA ICS Advisories","date_rel":"5h ago"},{"title":"Rockwell Automation ControlFLASH","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-03","source":"CISA ICS Advisories","date_rel":"5h ago"},{"title":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products","link":"https://www.securityweek.com/rockwell-automation-patches-over-a-dozen-vulnerabilities-across-products/","source":"SecurityWeek","date_rel":"2 Sep"}]},{"title":"New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and Accessibility","link":"https://cybersecuritynews.com/streamrat-android-trojan/","reason":"Android","category":"News","sources":["Cyber Security News","Malwarebytes Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote actions and deceptive login windows, turning an app download into\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-StreamRAT-Android-Trojan-Gives-Hackers-Full-Remote-Control-Through-VNC-and-Accessibility.webp","description":"StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote actions and deceptive login windows, turning an app download into an account takeover. The campaign targeted Spanish-speaking Android users through advertisements on Meta platforms and TikTok. One observed advertising push reached 570,000 Meta users between 11 June and 3 July 2026, mainly in Spain. It identified the malware while tracking the streaming-themed Steamtv Esp campaign. The operators used a phishing site and a multi-stage\u2026","related":[{"title":"StreamRat Android malware spreads through Meta and TikTok ads","link":"https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads","source":"Malwarebytes Labs","date_rel":"55m ago"},{"title":"Your phone or computer may soon ask how old you are","link":"https://www.malwarebytes.com/blog/privacy/2026/09/your-phone-or-computer-may-soon-ask-how-old-you-are","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control","link":"https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html","source":"The Hacker News","date_rel":"2 Sep"}]},{"title":"Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root","link":"https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj9su2Wd6Yb88IvMpg5v1P8IyPg4KWKTeBXjerFgxz0U5WLKO2U50jymR-fKujsKeMFZ3q1VEupMRFZUz5gD47JRzVceagYJJ3bCTT8t532rY63po54kanBCPX4_hmKsxe-1b52IGrYc__TH5Y2F13G6L32HNKPQxL34iqzEPuBGynDCu6xFdKHplXvdY/s1600/cisco-flaws.jpg","description":"Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is","related":[{"title":"Cisco security advisory (AV26-876)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-876","source":"CCCS Alerts & Advisories","date_rel":"3h ago"},{"title":"Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities","link":"https://www.securityweek.com/cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"The Agentic SOC \u2013 From AI Theater to Real Defense","link":"https://www.recordedfuture.com/blog/agentic-soc-real-defense","reason":"Teams","category":"Threat Intel","sources":["Dark Reading","Microsoft Security Blog","Recorded Future Intelligence"],"coverage":3,"cve_ids":[],"summary":"Moving beyond \"AI theater\" with measurable KPIs: Security teams must distinguish between genuine value and \"productivity theater.\" Success requires defining concrete KPIs\u2014such as cost improvement, risk reduction, and\u2026","source":"Recorded Future Intelligence","date_rel":"1 Sep","thumbnail":"https://www.recordedfuture.com/blog/media_1525b59948077b8743930ba01d9f3e5404773d89c.png?width=1200&format=pjpg&optimize=medium","description":"Moving beyond \"AI theater\" with measurable KPIs: Security teams must distinguish between genuine value and \"productivity theater.\" Success requires defining concrete KPIs\u2014such as cost improvement, risk reduction, and speed\u2014to measure true ROI, rather than deploying AI tools without a clear strategic purpose. Mitigate new autonomous risks: The shift to an agentic SOC introduces distinct threats, such as indirect prompt injection, and creates visibility gaps that traditional SIEM platforms are not built to handle. Organizations should shift from post-event observability to proactive control\u2026","related":[{"title":"Impersonating IT support: how threat actors turn a remote session into enterprise-wide access","link":"https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/","source":"Microsoft Security Blog","date_rel":"18h ago"},{"title":"AI\u2019s Vulnerability Surge May Be More Manageable Than First Feared","link":"https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared","source":"Dark Reading","date_rel":"19h ago"}]},{"title":"Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials","link":"https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html","reason":"CVE-2026-9586","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-48710","CVE-2026-9586"],"summary":"Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586\u2026","source":"The Hacker News","date_rel":"2 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb9lLZ-CHEFECU3vn2ObupuzweLn7l23dnUcs2Qd1H5hsxut3nQKqe6W3lbh_cSyVF4PDgdfuSauhpeMKmW6wZGYW3kpVdhTfWhfpISTtfRzw25VOSvJNR8dnh_WWKwyZ0VnWe8nndwwfnWN-gPSdqmLBhJW2vkqjCkfMo8Eo-sucoSIr6JMT-7HxHnsCw/s1600/admin.jpg","description":"Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as","related":[{"title":"Hackers exploit Sangoma Switchvox flaw to deploy reverse shells","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"CISA Adds Seven Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"2 Sep"}]},{"title":"BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory","link":"https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html","reason":"Windows","category":"News","sources":["Microsoft Security","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-50376","CVE-2026-62768","CVE-2026-62880"],"summary":"Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. \"Unlike the\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9vYkFCrVzaEl0WQj4XBILj6pIxDJ92eWgVrkOa_pdvJJoKF95JCX7VmQzY0HPZkhg5IMvjfCu15YCs5AMJ22NM6SBX7j7sCgpfiaUZZAL4Uc5vP0-q9VKN4LNSY4a701mmRCgLJQxCjnmnsSAxD7gFnyf9-dRaSxPZuGqLuOIQ415vCOjH-DZRtYSBHA/s1600/access-for-sale.jpg","description":"Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. \"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial","related":[{"title":"CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768","source":"Microsoft Security","date_rel":"2 Sep"},{"title":"CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880","source":"Microsoft Security","date_rel":"2 Sep"},{"title":"CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376","source":"Microsoft Security","date_rel":"2 Sep"}]},{"title":"Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone","link":"https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html","reason":"Zeroclick Pegasus Student","category":"News","sources":["Infosecurity Magazine","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. \"Our\u2026","source":"The Hacker News","date_rel":"8h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaEvtAyNP-TiY3M6wMUFNKymiK_BeQH_MEIzeFf79X0fNFV0gyV3MiegzULqTG6bC-20nprEpTHySkf3Hf0N72sLy-oVN6_ndqU4OwSm37Cx0OYrr2MbzpiII3ly4tEv891mjYhbSV18Eg94BBSitXG8XnON3QjpRqGkErk15L1FoeYT94R8WGlK8xUuJt/s1600/iphone-exploit.jpg","description":"The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. \"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware,\" the Citizen Lab said. \"We found high-confidence indicators of","related":[{"title":"Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone","link":"https://www.infosecurity-magazine.com/news/pegasus-zero-click-exploit/","source":"Infosecurity Magazine","date_rel":"1h ago"}]},{"title":"Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data","link":"https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html","reason":"Reuters Thomson Exposed","category":"News","sources":["The Hacker News","The Record"],"coverage":2,"cve_ids":[],"summary":"Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX1nx19KbhbT0_rYFjMzqgJuG35q7QvJiMrikolTZV9sWztkSoSFUr95E-h-9vHv-GBGmRHAyh5Du0DDMYMr1m0VbD5YgYO6dVoY7p8d6Z5BbORiBOGgJfZjg4euf9uwUkGO4ZX8QZXUpuU0CFUwNV46UozcdMJ9SyZ4T4cy4pAI9ho7xYQ8cDJaFdfKM/s1600/reuters.jpg","description":"Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names","related":[{"title":"US and Canadian court data exposed in Thomson Reuters breach","link":"https://therecord.media/thomson-reuters-cyberattack-data","source":"The Record","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-4357","vendor":"WordPress","product":"Embed HTML5 Game","severity":"CRITICAL","score":10.0,"description":"The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-4357"},{"id":"CVE-2026-77009","vendor":"WordPress","product":"WatchMan-Site7","severity":"CRITICAL","score":9.9,"description":"The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77009"},{"id":"CVE-2026-81294","vendor":"Paul Ryan","product":"Authorizer","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81294"},{"id":"CVE-2026-84795","vendor":"craftcms","product":"cms","severity":"CRITICAL","score":9.8,"description":"Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges \u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84795"},{"id":"CVE-2025-9314","vendor":"WordPress","product":"Developer Tools","severity":"CRITICAL","score":9.8,"description":"The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-9314"},{"id":"CVE-2026-53611","vendor":"AS203038","product":"looking-glass","severity":"CRITICAL","score":9.8,"description":"Looking Glass is a modern, stateless network-diagnostic platform \u2014 a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-53611"},{"id":"CVE-2026-20212","vendor":"Cisco","product":"Cisco NX-OS Software","severity":"CRITICAL","score":9.8,"description":"A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges.\r\n\r\nThis vulnerability exists because TCP ports 43210 and 43211 ar\u2026","cwe":"CWE-1327","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20212"},{"id":"CVE-2026-20274","vendor":"Cisco","product":"Cisco IOS XR Software","severity":"CRITICAL","score":9.8,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a\u2026","cwe":"CWE-664","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20274"},{"id":"CVE-2026-20279","vendor":"Cisco","product":"Cisco IOS XR Software","severity":"CRITICAL","score":9.8,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20279"},{"id":"CVE-2026-19117","vendor":"Delinea","product":"Secret Server (On-Prem)","severity":"CRITICAL","score":9.8,"description":"Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as\nthat user. This issue affects on-premises deployments only.","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19117"}],"vendor_spikes":[{"vendor":"Jenkins","count":33,"critical_count":0},{"vendor":"WordPress","count":30,"critical_count":3},{"vendor":"Drupal","count":26,"critical_count":1},{"vendor":"Elastic","count":15,"critical_count":0},{"vendor":"craftcms","count":13,"critical_count":1},{"vendor":"Cisco","count":11,"critical_count":3},{"vendor":"F5","count":7,"critical_count":0},{"vendor":"Microsoft","count":6,"critical_count":0},{"vendor":"Red Hat","count":6,"critical_count":1},{"vendor":"nuclio","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":246,"has_news_data":true,"has_cve_data":true}