{"date_iso":"2026-09-08","date_human":"Tuesday, September 8, 2026","generated_utc":"2026-09-08 17:13 UTC","read_minutes":5,"patch_tuesday":true,"top_stories":[{"title":"BigBear phishing crew nets thousands of Microsoft 365 credentials","link":"https://www.theregister.com/security/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials/5294944","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Huntress","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to\u2026","source":"The Register Security","date_rel":"3h ago","thumbnail":"https://image.theregister.com/?imageId=5294968&width=800","description":"A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to researchers who accessed the crooks' own admin panel. Security researchers at CloudSEK say they accessed the admin panel behind BigBear 2.0, an Evilginx2-based phishing-as-a-service operation targeting Microsoft 365 users, giving them an unusually detailed look at the campaign and its haul. According to the researchers, the panel contained 5,137 records associated with 461\u2026","related":[{"title":"August updates trigger 0xc0000409 errors on Windows Server 2016","link":"https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Microsoft: Windows Server 2025 changes causing app crashes","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials","link":"https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/","source":"Infosecurity Magazine","date_rel":"7h ago"},{"title":"BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft","link":"https://cybersecuritynews.com/bigbear-2-0-evilginx2/","source":"Cyber Security News","date_rel":"8h ago"},{"title":"AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance","link":"https://www.huntress.com/blog/ad-rms-architecture-and-recon","source":"Huntress","date_rel":"13h ago"},{"title":"Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks","link":"https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html","source":"The Hacker News","date_rel":"7 Sep"}]},{"title":"Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain","link":"https://cybersecuritynews.com/hackers-disable-endpoint-protection/","reason":"Windows","category":"News","sources":["Cyber Security News","Fortinet PSIRT","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-62694","CVE-2026-62706","CVE-2026-62744"],"summary":"A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Disable-Endpoint-Protection-and-Deploy-Sliver-Across-Compromised-Windows-Domain.webp","description":"A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote administration to establish control after gaining an initial foothold. The activity was staged from an exposed server and aimed at one unnamed US organisation. Its scripts were built for a real Active Directory environment, including a planned rollout across 18 hosts, while the recovered material contained no proof that ransomware was deployed in this specific incident. Analysts\u2026","related":[{"title":"CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62706","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62694","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62744","source":"Microsoft Security","date_rel":"3h ago"},{"title":"Arbitrary process termination from exposed minifilter communication port","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-165","source":"Fortinet PSIRT","date_rel":"10h ago"},{"title":"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner","link":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html","source":"The Hacker News","date_rel":"6 Sep"}]},{"title":"WeWorm \u2013 First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android","link":"https://cybersecuritynews.com/weworm-first-0-click-worm/","reason":"Android","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A proof-of-concept zero-click worm dubbed \u201cWeWorm\u201d that it says can spread through WeChat voice calls on both iOS and Android, compromising a target\u2019s WeChat account in seconds without the victim answering the call\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/WeWorm-First-0-Click-Worm.webp","description":"A proof-of-concept zero-click worm dubbed \u201cWeWorm\u201d that it says can spread through WeChat voice calls on both iOS and Android, compromising a target\u2019s WeChat account in seconds without the victim answering the call. Calif says the bug was reported to Tencent in July and that Tencent has since mitigated the exploit for users, but the research still serves as a stark warning about how mobile messaging apps can become wormable attack surfaces at planetary scale. WeChat is not a niche target. Tencent says Weixin and WeChat together exceeded 1.4 billion monthly active users as of the end of Q1\u2026","related":[{"title":"WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls","link":"https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"THost9 Android RAT Pairs Packed Loader With ADB Worm","link":"https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/","source":"Infosecurity Magazine","date_rel":"5h ago"},{"title":"A week in security (August 31 \u2013 September 6)","link":"https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-august-31-september-6","source":"Malwarebytes Labs","date_rel":"7 Sep"}]},{"title":"Extortion crews have their eyes on high-value AI data, Google warns","link":"https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640","reason":"Google","category":"News","sources":["Cisco Talos","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Data theft and extortion crews are stealing companies\u2019 proprietary AI data and threatening to leak it if the victim organizations don\u2019t pay a ransom, according to Google\u2019s threat hunters. In one case that Google\u2019s\u2026","source":"The Register Security","date_rel":"5h ago","thumbnail":"https://image.theregister.com/?imageId=1681127&width=800","description":"Data theft and extortion crews are stealing companies\u2019 proprietary AI data and threatening to leak it if the victim organizations don\u2019t pay a ransom, according to Google\u2019s threat hunters. In one case that Google\u2019s Mandiant incident response team investigated, the crooks broke into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company met their extortion demand. In another breach at a company that specializes in AI media generation, attackers stole sensitive\u2026","related":[{"title":"AI Coding Tools Now a Prime Target for Threat Actors, Google Warns","link":"https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/","source":"Infosecurity Magazine","date_rel":"5h ago"},{"title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","link":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","source":"Cisco Talos","date_rel":"7h ago"},{"title":"ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2","link":"https://blog.talosintelligence.com/clickfix-moves-into-the-browser/","source":"Cisco Talos","date_rel":"7h ago"},{"title":"JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies","link":"https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html","source":"The Hacker News","date_rel":"7 Sep"}]},{"title":"Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell","link":"https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html","reason":"Adobe","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_xdakttovno7kFgFYIw5XGFGcSZibVvXYB64vih4iZpc4_WY_t7oe1X3igSPGXBa8UTkf4z4xn_GzZ_n7PmuFFvYC8Wsmb04PxYP5z-XHjZZFe_SASihwZNg1dxHXQzz8hBRo-6LhvQmwyo_MA9Kj6hrcci6ouvOX1D4f-0dNvs57M6WneQHC61yZkF_o/s1600/magento.jpg","description":"Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. \"This update resolves a critical","related":[{"title":"Adobe security advisory (AV26-888)","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888","source":"CCCS Alerts & Advisories","date_rel":"2h ago"},{"title":"Magento StyleSmuggler zero-day exploited to deploy Linux backdoor","link":"https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/","source":"Bleeping Computer","date_rel":"7 Sep"},{"title":"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores","link":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html","source":"The Hacker News","date_rel":"5 Sep"}]},{"title":"Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution","link":"https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html","reason":"Crowdstrike","category":"News","sources":["Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the\u2026","source":"The Hacker News","date_rel":"52m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEim6TzHNI7Stg7pvo_Pu0vMltU2jmnIr922wxLWIYFfaRpN3G7rVZCy76FgWwyZUCT36dRygtzxVmZPFTPSm1FuRrmqXwuvTjJhxwJE7zl34ZHuwZUEDdlrnunlem-Xo7KS6Buy1xlHYYxf-0u-d3qWer-o64MrNvrsh5V1WC7dVtGVwubINEgB1AtfQBNC/s1600/brazil-hackers.jpg","description":"A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. \"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment","related":[{"title":"Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits","link":"https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/","source":"SecurityWeek","date_rel":"7 Sep"},{"title":"Researcher Publishes CrowdStrike Privilege Escalation Zero Day","link":"https://www.infosecurity-magazine.com/news/crowdstrike-privilege-escalation/","source":"Infosecurity Magazine","date_rel":"7 Sep"}]},{"title":"SAP Security Updates September 2026 \u2013 Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport","link":"https://cybersecuritynews.com/sap-security-updates-september-2026/","reason":"Sap","category":"News","sources":["Bleeping Computer","Cyber Security News","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"SAP has released its September 2026 Security Patch Day updates , delivering 19 new security notes and one update to a previously issued note. The patches address vulnerabilities across SAP NetWeaver, SAP Extended\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/SAP-Security-Updates-September-2026-Critical-Vulnerabilities-patched-in-SAP-NetWeaver-Cloud-and-Extended-Passport.webp","description":"SAP has released its September 2026 Security Patch Day updates , delivering 19 new security notes and one update to a previously issued note. The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products. The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating. The flaw\u2026","related":[{"title":"SAP warns of maximum severity 'OVERPASS' kernel vulnerability","link":"https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"SAP Patches Critical Extended Passport Processing Vulnerability","link":"https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/","source":"SecurityWeek","date_rel":"2h ago"}]},{"title":"StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day","link":"https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero","reason":"CVE-2026-75650","category":"Research","sources":["Bleeping Computer","Tenable Blog"],"coverage":2,"cve_ids":["CVE-2026-75650"],"summary":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a\u2026","source":"Tenable Blog","date_rel":"3h ago","thumbnail":"","description":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different\u2026","related":[{"title":"Adobe fixes critical Magento zero-day exploited to backdoor servers","link":"https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/","source":"Bleeping Computer","date_rel":"3h ago"}]},{"title":"PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution","link":"https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html","reason":"Chrome","category":"News","sources":["Fortinet PSIRT","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. \"Requiring prior administrative or code\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA3-5bNylOMc_s8MAT2ibQnV33cnJXadwKPRXjYgAL0GcZWOXuwtM-s5HS4ryVu5ewnhfAqBtOiuSseLcUSyDIfxf5XKF6mAwrpyG-v3Y-siqjJY8I5zVEMXwfkKPwBNAqaO2sQFI-q2oA4MWiagZFUlknIPKADDfvOo8s2Ifsa_xBAojg1rD5ZGUErC85/s1600/chrome-malware.jpg","description":"Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. \"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences","related":[{"title":"Improper Authentication of FortiPAM Server","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-168","source":"Fortinet PSIRT","date_rel":"10h ago"},{"title":"\u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More","link":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html","source":"The Hacker News","date_rel":"7 Sep"}]},{"title":"Mathspace discloses data breach affecting over 1 million people","link":"https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/","reason":"Mathspace Million People","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.","source":"Bleeping Computer","date_rel":"7 Sep","thumbnail":"","description":"","related":[{"title":"Mathspace Data Breach Exposes Over 1 Million People","link":"https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/","source":"SecurityWeek","date_rel":"6h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-86296","vendor":"D-Link","product":"DIR-822A","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possibl\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86296"},{"id":"CVE-2026-75650","vendor":"Adobe","product":"Adobe Commerce","severity":"CRITICAL","score":10.0,"description":"Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabil\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75650"},{"id":"CVE-2026-44756","vendor":"SAP","product":"SAP Extended Passport (EPP) Processing","severity":"CRITICAL","score":10.0,"description":"A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially r\u2026","cwe":"CWE-120","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-44756"},{"id":"CVE-2026-86299","vendor":"Linksys","product":"RE7000","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/p\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86299"},{"id":"CVE-2026-86510","vendor":"D-Link","product":"DIR-822A","severity":"CRITICAL","score":9.9,"description":"A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The explo\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86510"},{"id":"CVE-2026-76578","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","severity":"CRITICAL","score":9.8,"description":"A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a rela\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76578"},{"id":"CVE-2026-18922","vendor":"Red Hat","product":"Red Hat Directory Server 11.7 E4S for RHEL 8","severity":"CRITICAL","score":9.8,"description":"A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated succ\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18922"},{"id":"CVE-2026-7861","vendor":"Next4Biz Information Technologies Inc.","product":"CSM (Customer Service Management)","severity":"CRITICAL","score":9.8,"description":"Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection.\n\nThis issue affects CSM (Customer Service Management): through 07092026.\u00a0NOTE: The vendor was\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-7861"},{"id":"CVE-2026-86478","vendor":"JetBrains","product":"YouTrack","severity":"CRITICAL","score":9.8,"description":"In JetBrains YouTrack before 2025.3.161254, \n2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86478"},{"id":"CVE-2026-86480","vendor":"JetBrains","product":"Hub","severity":"CRITICAL","score":9.8,"description":"In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86480"}],"vendor_spikes":[{"vendor":"Dell","count":36,"critical_count":2},{"vendor":"JetBrains","count":29,"critical_count":2},{"vendor":"SAP","count":17,"critical_count":4},{"vendor":"Siemens","count":13,"critical_count":2},{"vendor":"Red Hat","count":11,"critical_count":2},{"vendor":"ASUS","count":11,"critical_count":0},{"vendor":"WordPress","count":10,"critical_count":0},{"vendor":"MISP","count":9,"critical_count":0},{"vendor":"pmmp","count":9,"critical_count":0},{"vendor":"thephpleague","count":8,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":11,"new_cve_count":247,"has_news_data":true,"has_cve_data":true}