Skip to content

Morning Brief

Wednesday, September 9, 2026 · generated 2026-09-09 17:07 UTC · ~5 min read

Top developments

Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls

Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games…

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others…

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices. The update, published on September 8…

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491…

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and…

FBI puts its cyber strategy on paper

The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett…

Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired…

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.

Ivanti Patches Critical Flaws Across Enterprise Security Products

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that…

Vulnerability watch

CVE-2026-82004 Adobe · Adobe Campaign Classic CWE-78 CRITICAL 10.0

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An att…

CVE-2026-78234 Red Hat · Red Hat build of Apache Camel - HawtIO 4 CWE-295 CRITICAL 9.9

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a…

CVE-2026-12645 Ivanti · Ivanti Neurons for ITSM CWE-862 CRITICAL 9.9

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

CVE-2026-12646 Ivanti · Ivanti Neurons for ITSM CWE-862 CRITICAL 9.9

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

CVE-2026-12647 Ivanti · Ivanti Neurons for ITSM CWE-862 CRITICAL 9.9

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

CVE-2026-12650 Ivanti · Neurons for ITSM CWE-502 CRITICAL 9.9

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

CVE-2026-26084 Fortinet · FortiSandbox PaaS CWE-284 CRITICAL 9.9

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive inf…

CVE-2026-83941 Microsoft · Microsoft Entra CWE-862 CRITICAL 9.9

Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

CVE-2026-19232 Adobe · Adobe Experience Manager as a Cloud Service CWE-863 CRITICAL 9.9

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or s…

CVE-2026-48273 Adobe · ColdFusion 2025 CWE-95 CRITICAL 9.9

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker co…

Full CVE Feed →

Worth reading

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →