{"date_iso":"2026-09-09","date_human":"Wednesday, September 9, 2026","generated_utc":"2026-09-09 17:07 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls","link":"https://cybersecuritynews.com/microsoft-expands-windows-family-safety/","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Cyber Security News","CyberScoop","Dark Reading","Huntress","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","SecurityWeek","Tenable Blog","The Hacker News","The Record","The Register Security","Zero Day Initiative"],"coverage":19,"cve_ids":["CVE-2026-81963","CVE-2026-85880"],"summary":"Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Expands-Windows-Family-Safety-With-Built-In-Age-Verification-and-Parental-Controls.webp","description":"Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games, services, and AI experiences provide protections that match a user\u2019s age. The initiative uses the Microsoft account as the central identity layer for family safety on Windows. Microsoft accounts can identify whether a user is a child, teen, or adult, determine whether parental consent or controls apply, and record whether age verification has been completed. This model allows\u2026","related":[{"title":"Microsoft fixes record 964 flaws, including 2 exploited zero-days","link":"https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days","source":"Malwarebytes Labs","date_rel":"7h ago"},{"title":"New Phishing Attack Creates Malicious Pages Inside the Victim\u2019s Browser","link":"https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026","link":"https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/","source":"Infosecurity Magazine","date_rel":"7h ago"},{"title":"New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access","link":"https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/","source":"Bleeping Computer","date_rel":"9h ago"},{"title":"Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed","link":"https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html","source":"The Hacker News","date_rel":"10h ago"},{"title":"Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days","link":"https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html","source":"The Hacker News","date_rel":"12h ago"}]},{"title":"Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA","link":"https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html","reason":"Google","category":"News","sources":["Cisco Talos","Dark Reading","Infosecurity Magazine","SecurityWeek","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create \"stolen keys\" that grant illicit access to tools from model providers like Google, Anthropic, and others\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYP_zrhRTZRWnPPcDkUrE7dBh2Bf5eaQmlBxyl7euTRGjS0C8boQppnrmjY0CIVjGrS_PF13V1W3BPVI3RDPZY59s_7xIkI8LnFkg3Tn_Q0x7_tbCs_sMkvhZMREtFLW3IOJSNNmQrKCDI88FCWhfymdWkEWtdMMRzivv3lZXImjreAz0d74VXt2K80ipH/s1600/tokens.jpg","description":"Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create \"stolen keys\" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API","related":[{"title":"AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns","link":"https://www.securityweek.com/ai-is-giving-lesser-resourced-attackers-nation-state-level-reach-google-warns/","source":"SecurityWeek","date_rel":"10m ago"},{"title":"ClickFix Moves into the Browser to Steal Cryptocurrency","link":"https://www.infosecurity-magazine.com/news/clickfix-browser-cryptocurrency/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Attackers Use Multi-Hop Google Redirects for Phishing Campaign","link":"https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign","source":"Dark Reading","date_rel":"20h ago"},{"title":"AI Coding Tools Now a Prime Target for Threat Actors, Google Warns","link":"https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/","source":"Infosecurity Magazine","date_rel":"8 Sep"},{"title":"Extortion crews have their eyes on high-value AI data, Google warns","link":"https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640","source":"The Register Security","date_rel":"8 Sep"},{"title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","link":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","source":"Cisco Talos","date_rel":"8 Sep"}]},{"title":"Android Security Update September 2026 \u2013 Fix for Critical Flaws that Enable RCE Attacks","link":"https://cybersecuritynews.com/android-security-update-september-2026/","reason":"Android","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-65812"],"summary":"Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices. The update, published on September 8\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Android-Security-Update-September-2026-Fix-for-Critical-Flaws-that-Enable-RCE-Attacks.webp","description":"Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices. The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should install the latest available update as soon as their device manufacturer releases it. The most serious flaws affect the Android System component. Google said these critical vulnerabilities could lead to remote code execution, or RCE, without requiring additional execution privileges or user\u2026","related":[{"title":"Android\u2019s September 2026 Updates Patch 180 Vulnerabilities","link":"https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/","source":"SecurityWeek","date_rel":"36m ago"},{"title":"Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls","link":"https://www.infosecurity-magazine.com/news/wechat-zeroclick-worm-hijack/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Gigabud Uses Android App Cloning to Evade Fraud Detection","link":"https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Microsoft Teams for Android Vulnerability Exposes Sensitive Information","link":"https://cybersecuritynews.com/microsoft-teams-android-vulnerability/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection","link":"https://cybersecuritynews.com/hackers-clone-banking-apps/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls","link":"https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html","source":"The Hacker News","date_rel":"8 Sep"}]},{"title":"Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox","link":"https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Fortinet PSIRT","SecurityWeek","The Hacker News","The Record"],"coverage":5,"cve_ids":["CVE-2026-87491"],"summary":"Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZvl2DE9GFM-4rdFgtQOOp1Dk3Xgp7xWysUv5zKTFwxqWYTurcgXgE-PDMn3_2AAIihh4YeiRvmwpb6GVDB1-8kxqasUWwX-FFa4mA41kXpFbzdt9hOvzW4xcyKBFttqIzbFSl-1SSSO0P_URv3Sy9QamkQZ55qzX5Y9Kmv5NdBCBHXCcUziiO6mfrqURE/s1600/chrome-zeroday.jpg","description":"Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. \"Out-of-bounds write in V8 in Google Chrome prior to","related":[{"title":"Multiple Chinese hacking groups seen using identical Chrome zero-day exploit","link":"https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups","source":"The Record","date_rel":"36m ago"},{"title":"Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension","link":"https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"Google warns of new Chrome zero-day bug exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/","source":"Bleeping Computer","date_rel":"10h ago"},{"title":"Improper Authentication of FortiPAM Server","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-168","source":"Fortinet PSIRT","date_rel":"8 Sep"},{"title":"PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution","link":"https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html","source":"The Hacker News","date_rel":"7 Sep"},{"title":"\u26a1 Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More","link":"https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html","source":"The Hacker News","date_rel":"7 Sep"}]},{"title":"SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution","link":"https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html","reason":"Sap","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and\u2026","source":"The Hacker News","date_rel":"10h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwUnFS6EAvkjYM7AC_3-k8C6QSAmpatuThkiXaa1WxvtiZU7M-n384kpPN4-VSAQfwL8PCTPUVd3iYeTDn_V5ZoZGEfuizJSZghdAw4Ldq_wFg7rxWyKBbwdMctiiBaykAmL40L6wappUeeyIr58u8SFFSszCP-rszf5ioHsaz0dtKilEpkw1LTEmtaCtZ/s1600/sap-flaws.jpg","description":"SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP","related":[{"title":"SAP Patches Maximum Severity \u201cOverpass\u201d Flaw","link":"https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/","source":"Infosecurity Magazine","date_rel":"8h ago"},{"title":"SAP security advisory \u2013 September 2026 monthly rollup (AV26-894)","link":"https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-september-2026-monthly-rollup-av26-894","source":"CCCS Alerts & Advisories","date_rel":"23h ago"}]},{"title":"FBI puts its cyber strategy on paper","link":"https://therecord.media/fbi-releases-first-public-cybersecurity-strategy","reason":"Teams","category":"News","sources":["Recorded Future Intelligence","The Record"],"coverage":2,"cve_ids":[],"summary":"The first public cybersecurity strategy issued by the FBI \"directs our teams, our field offices, our global presence\" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett\u2026","source":"The Record","date_rel":"1h ago","thumbnail":"http://cms.therecord.media/uploads/david_trinks_Vvh_9ooe_EZ_0_unsplash_b2cf67bd03.jpg","description":"","related":[{"title":"Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring","link":"https://www.recordedfuture.com/blog/unified-brand-identity-monitoring","source":"Recorded Future Intelligence","date_rel":"17h ago"}]},{"title":"Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI","link":"https://www.tenable.com/blog/ai-agent-security-openai-tenable-cyberagents-exchange-inspector","reason":"Exchange","category":"Research","sources":["Microsoft Security","Tenable Blog"],"coverage":2,"cve_ids":["CVE-2026-55007"],"summary":"Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That\u2019s why for its new CyberAgents Exchange registry, Tenable paired\u2026","source":"Tenable Blog","date_rel":"4h ago","thumbnail":"","description":"Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That\u2019s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector. Key takeaways The Exchange Inspector combines Tenable\u2019s exposure detection with OpenAI\u2019s GPT Cyber models and with human oversight to rigorously vet submissions made to the CyberAgents Exchange. Securing AI agents requires analyzing a broad attack surface that includes\u2026","related":[{"title":"CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55007","source":"Microsoft Security","date_rel":"8 Sep"}]},{"title":"ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws","link":"https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/","reason":"Siemens","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.","source":"SecurityWeek","date_rel":"6h ago","thumbnail":"","description":"","related":[{"title":"[Control Systems] Siemens security advisory (AV26-890)","link":"https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-890","source":"CCCS Alerts & Advisories","date_rel":"23h ago"}]},{"title":"Ivanti Patches Critical Flaws Across Enterprise Security Products","link":"https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/","reason":"Ivanti","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.","source":"SecurityWeek","date_rel":"6h ago","thumbnail":"","description":"","related":[{"title":"Ivanti security advisory (AV26-897)","link":"https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-897","source":"CCCS Alerts & Advisories","date_rel":"21h ago"}]},{"title":"CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild","link":"https://cybersecuritynews.com/n-able-n-central-rce/","reason":"Exploited Ncentral Nable","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able\u2019s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/N-able-N-central-RCE.webp","description":"The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able\u2019s N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets. The vulnerability, tracked as CVE-2026-86218 , carries a perfect CVSS score of 10.0 and allows unauthenticated remote code execution, making it one of the most dangerous flaws to hit the managed service provider ecosystem this year. CISA classifies CVE-2026-86218 as a static code injection vulnerability tied to\u2026","related":[{"title":"N-able N-central Pre-Auth RCE Flaw Exploited in the Wild","link":"https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html","source":"The Hacker News","date_rel":"12h ago"}]}],"worth_reading":[{"title":"StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day","link":"https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero","reason":"CVE-2026-75650","category":"Research","sources":["CISA Alerts & Advisories","Tenable Blog"],"coverage":2,"cve_ids":["CVE-2026-75650"],"summary":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a\u2026","source":"Tenable Blog","date_rel":"8 Sep","thumbnail":"","description":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different\u2026","related":[{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"8 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82004","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An att\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82004"},{"id":"CVE-2026-78234","vendor":"Red Hat","product":"Red Hat build of Apache Camel - HawtIO 4","severity":"CRITICAL","score":9.9,"description":"A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78234"},{"id":"CVE-2026-12645","vendor":"Ivanti","product":"Ivanti Neurons for ITSM","severity":"CRITICAL","score":9.9,"description":"A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12645"},{"id":"CVE-2026-12646","vendor":"Ivanti","product":"Ivanti Neurons for ITSM","severity":"CRITICAL","score":9.9,"description":"A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12646"},{"id":"CVE-2026-12647","vendor":"Ivanti","product":"Ivanti Neurons for ITSM","severity":"CRITICAL","score":9.9,"description":"A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12647"},{"id":"CVE-2026-12650","vendor":"Ivanti","product":"Neurons for ITSM","severity":"CRITICAL","score":9.9,"description":"A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-12650"},{"id":"CVE-2026-26084","vendor":"Fortinet","product":"FortiSandbox PaaS","severity":"CRITICAL","score":9.9,"description":"A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive inf\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-26084"},{"id":"CVE-2026-83941","vendor":"Microsoft","product":"Microsoft Entra","severity":"CRITICAL","score":9.9,"description":"Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83941"},{"id":"CVE-2026-19232","vendor":"Adobe","product":"Adobe Experience Manager as a Cloud Service","severity":"CRITICAL","score":9.9,"description":"Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or s\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19232"},{"id":"CVE-2026-48273","vendor":"Adobe","product":"ColdFusion 2025","severity":"CRITICAL","score":9.9,"description":"ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker co\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-48273"}],"vendor_spikes":[{"vendor":"Microsoft","count":977,"critical_count":40},{"vendor":"Google","count":328,"critical_count":2},{"vendor":"Adobe","count":167,"critical_count":6},{"vendor":"WordPress","count":61,"critical_count":0},{"vendor":"Unknown","count":40,"critical_count":2},{"vendor":"MongoDB","count":24,"critical_count":0},{"vendor":"Samsung Mobile","count":23,"critical_count":0},{"vendor":"Tanium","count":21,"critical_count":0},{"vendor":"n8n-io","count":14,"critical_count":0},{"vendor":"Okta","count":14,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":15,"new_cve_count":1892,"has_news_data":true,"has_cve_data":true}