{"date_iso":"2026-09-11","date_human":"Friday, September 11, 2026","generated_utc":"2026-09-11 17:00 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"US Government Accuses Chinese AI Firms of Distilling Frontier Models","link":"https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Huntress","Infosecurity Magazine","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.","source":"Dark Reading","date_rel":"9 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt33b13b556aa2e63e/6aa1a92888ea9adc3dabaf29/distillery-ArtistGNDphotography-GettyImages-2195175104.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","source":"Huntress","date_rel":"just now"},{"title":"Google security advisory (AV26-904)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-904","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"},{"title":"Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA","link":"https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html","source":"The Hacker News","date_rel":"9 Sep"},{"title":"ClickFix Moves into the Browser to Steal Cryptocurrency","link":"https://www.infosecurity-magazine.com/news/clickfix-browser-cryptocurrency/","source":"Infosecurity Magazine","date_rel":"9 Sep"},{"title":"Attackers Use Multi-Hop Google Redirects for Phishing Campaign","link":"https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign","source":"Dark Reading","date_rel":"8 Sep"}]},{"title":"Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections","link":"https://cybersecuritynews.com/windows-11-security-update-kb5124008/","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Cyber Security News","CyberScoop","Dark Reading","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","Tenable Blog","The Hacker News","The Register Security"],"coverage":15,"cve_ids":["CVE-2026-81963","CVE-2026-85880"],"summary":"Microsoft\u2019s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8. Administrators who can reproduce the failure\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Windows-11-Security-Update-KB5124008.webp","description":"Microsoft\u2019s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8. Administrators who can reproduce the failure say certificate-based tunnels that worked immediately before the patch stop connecting afterward, then recover as soon as the cumulative update is removed and the device is rebooted. The first detailed account appeared on Microsoft Q&A on September 9, 2026, from an administrator running Windows 11 24H2 and 25H2 clients with Always On VPN, certificate-based authentication\u2026","related":[{"title":"Hackers Favor US Eastern Business Hours in M365 Phishing Campaign","link":"https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/","source":"Bleeping Computer","date_rel":"7h ago"},{"title":"Most Organizations Skip Permissions Reviews Before Deploying AI Tools","link":"https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/","source":"Infosecurity Magazine","date_rel":"7h ago"},{"title":"Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data","link":"https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data","source":"Dark Reading","date_rel":"20h ago"},{"title":"Microsoft Excel KB5002914 update breaks copy and paste for some users","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit","link":"https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit","source":"Dark Reading","date_rel":"10 Sep"}]},{"title":"Metasploit Wrap Up: This One Goes to Sixteen!","link":"https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen","reason":"Cisco","category":"Research","sources":["Bleeping Computer","CCCS Alerts & Advisories","Rapid7 Blog","Sophos Threat Research","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit\u2026","source":"Rapid7 Blog","date_rel":"3h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0d50271a40a5f14f/6849ab419621d9f3824d5017/metasploit-sky.png","description":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516\u2026","related":[{"title":"Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware","link":"https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html","source":"The Hacker News","date_rel":"10h ago"},{"title":"\u201cEye\u201d spy: Cyclops Blink returns with extended capabilities","link":"https://www.sophos.com/en-us/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities","source":"Sophos Threat Research","date_rel":"16h ago"},{"title":"Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers","link":"https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/","source":"Bleeping Computer","date_rel":"10 Sep"},{"title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","link":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html","source":"The Hacker News","date_rel":"10 Sep"},{"title":"Cisco security advisory (AV26-197) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"}]},{"title":"New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims","link":"https://cybersecuritynews.com/new-android-ransomware/","reason":"Android","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the screen, intercept\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-Android-Ransomware-Records-Screens-Steals-OTPs-and-Secretly-Takes-Photos-of-Victims.webp","description":"A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone\u2019s cameras, making one infection both an extortion and privacy crisis. The campaign appears built around standalone Android app packages, or APKs, hosted on third-party file-sharing services. Victims can be led to them through shared links, messaging apps or phishing messages, then persuaded to install the app outside the official store. Its\u2026","related":[{"title":"Android malware creates a hidden copy of your banking app","link":"https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app","source":"Malwarebytes Labs","date_rel":"4h ago"},{"title":"Indonesia Hit by Android Banking App-Cloning Campaign","link":"https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign","source":"Dark Reading","date_rel":"15h ago"},{"title":"New Android malware encrypts files, steals data, and harasses victims","link":"https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories","link":"https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html","source":"The Hacker News","date_rel":"23h ago"},{"title":"Google Play Early Access Abused to Push Thousands of Deceptive Android Apps","link":"https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html","source":"The Hacker News","date_rel":"10 Sep"},{"title":"MantaxOtax Android Malware Combines Ransomware With Spyware","link":"https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/","source":"Infosecurity Magazine","date_rel":"10 Sep"}]},{"title":"Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits","link":"https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399","reason":"Chrome","category":"News","sources":["Ars Technica Security","Bleeping Computer","Malwarebytes Labs","Proofpoint Threat Insight","The Hacker News","The Register Security","Volexity"],"coverage":7,"cve_ids":["CVE-2026-87491"],"summary":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US\u2026","source":"The Register Security","date_rel":"9 Sep","thumbnail":"https://image.theregister.com/?imageId=5295408&width=800","description":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. \u201cIn terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted,\" he said. \"However, the true number is almost\u2026","related":[{"title":"BlueMoon exploit kit turns Chrome and Windows flaws into attacks","link":"https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks","source":"Malwarebytes Labs","date_rel":"10 Sep"},{"title":"New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws","link":"https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/","source":"Bleeping Computer","date_rel":"10 Sep"},{"title":"Update Chrome now to protect against an actively exploited vulnerability","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability","source":"Malwarebytes Labs","date_rel":"10 Sep"},{"title":"Four groups caught using the same Chrome and Windows exploit kit","link":"https://www.proofpoint.com/us/newsroom/news/four-groups-caught-using-same-chrome-and-windows-exploit-kit","source":"Proofpoint Threat Insight","date_rel":"9 Sep"},{"title":"Four groups caught using the same Chrome and Windows exploit kit","link":"https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/","source":"Ars Technica Security","date_rel":"9 Sep"},{"title":"Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows","link":"https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/","source":"Volexity","date_rel":"9 Sep"}]},{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","link":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html","reason":"Windows","category":"News","sources":["Bleeping Computer","Huntress","Microsoft Security","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-68877","CVE-2026-69508","CVE-2026-69777"],"summary":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp8vDxYtUGwWuRZlSSBh2ghvSf6GTi_VlTQSQXTaIWSlQgHY_imEfl4hyAcrhPz9w3_ejmdAKK7ZeOt5gBsNZI7mhxJsnbyLT8Bo6O6HdM01yCNuDjuz-IU64LRuAuVDOzh2Z0vLhvzwP9PUUBKE_OLn0YD7m74-kZpo1dr5c0hzCMRHxrgfIzjk9MnR4/s1600/chinese.jpg","description":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns","related":[{"title":"September Windows Server updates break Remote Desktop Services","link":"https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69777","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69508","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68877","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity","link":"https://www.huntress.com/blog/rogue-screenconnect-installations","source":"Huntress","date_rel":"9 Sep"}]},{"title":"Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html","reason":"Check Point","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-85102","CVE-2026-85103"],"summary":"Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only\u2026","source":"The Hacker News","date_rel":"10 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyc0Kqar7_6N4y9ymGxw8ukQCQbqQ_pGCfnoXYMBZoNZK1w3ljkO26S_rhVhJaIVcx8rcEK95njKyaYj5g63VByKh8ncf_s84nUBWoyEbWZH6uaLYjnu5fNt_TC9wz-r6P_RTJgZ83Z5wmurzSb9_lHVfV1t9STts4WCZr18AH-3XRHTn5pj15uURIM-0/s1600/checkpoint.jpg","description":"Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only \"under specific conditions\" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security","related":[{"title":"Check Point Patches Critical VPN Vulnerabilities","link":"https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Check Point security advisory (AV26-902)","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"}]},{"title":"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks","link":"https://cybersecuritynews.com/new-kataru-iot-malware/","reason":"Linux","category":"News","sources":["Cyber Security News","Elastic Security Labs"],"coverage":2,"cve_ids":[],"summary":"KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-KATARU-IoT-Malware-Packs-Linux-Privilege-Escalation-Exploits-and-Mirai-Style-DDoS-Attacks.webp","description":"KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then downloaded an ARM payload. It shows how old entry points still give attackers a foothold. The malware resembles the Mirai botnet family in its ability to flood targets with traffic, but carries wider tools. It can attempt to gain root access, stay active through reboots, hide command traffic, and run commands supplied by its operators. A compromised device can therefore be harder to\u2026","related":[{"title":"Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates","link":"https://cybersecuritynews.com/ubuntu-24-04-5-lts-linux-7/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Linux Detection Engineering - Local Privilege Escalation","link":"https://www.elastic.co/security-labs/threat-command/linux-privilege-escalation-detection-framework","source":"Elastic Security Labs","date_rel":"16h ago"}]},{"title":"Your Critical Vulnerabilities Might Not Be Your Biggest Risk","link":"https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html","reason":"Teams","category":"News","sources":["Recorded Future Intelligence","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Security teams have become exceptionally talented at finding vulnerabilities. Now, it\u2019s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPPe_ve3Cylrq2fJ8HTFPebWF7lR7tvzMvL3mwFcGZNF2KWesOGc66BfO7NbiPxmsiao8jcItyikguKNqsEGfpJEcAvacbP7rflAaAT-e0Y1IbsNCNvdqvXMbwERLlPpV0PMhk9c5esoEjCE97wglh8rU9xZ7eGz2N4BOpzFYTb9-Ln3FaBRQiscqzK7U/s1600/breachlock.jpg","description":"Security teams have become exceptionally talented at finding vulnerabilities. Now, it\u2019s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker","related":[{"title":"Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring","link":"https://www.recordedfuture.com/blog/unified-brand-identity-monitoring","source":"Recorded Future Intelligence","date_rel":"9 Sep"}]},{"title":"GitLab Vulnerability Exploited One Day After Disclosure","link":"https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/","reason":"Gitlab","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-85706"],"summary":"The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.","source":"SecurityWeek","date_rel":"48m ago","thumbnail":"","description":"","related":[{"title":"GitLab urges users to patch max severity path traversal flaw","link":"https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/","source":"Bleeping Computer","date_rel":"5h ago"}]}],"worth_reading":[{"title":"ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-679/","reason":"Adobe","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious\u2026","source":"Zero Day Initiative","date_rel":"10 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.","related":[{"title":"Adobe security advisory (AV26-808) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"10 Sep"},{"title":"ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-678/","source":"Zero Day Initiative","date_rel":"10 Sep"},{"title":"ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-677/","source":"Zero Day Initiative","date_rel":"10 Sep"},{"title":"Adobe security advisory (AV26-888) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888","source":"CCCS Alerts & Advisories","date_rel":"8 Sep"}]},{"title":"ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-645/","reason":"Fortinet","category":"Research","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","Zero Day Initiative"],"coverage":3,"cve_ids":["CVE-2025-25249"],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"9 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.","related":[{"title":"Fortinet security advisory (AV26-023) - Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"},{"title":"Fortinet security advisory (AV26-898)","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-898","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"9 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-68487","vendor":"WebPros","product":"Plesk","severity":"CRITICAL","score":9.9,"description":"Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.","cwe":"CWE-36","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68487"},{"id":"CVE-2026-68488","vendor":"WebPros","product":"Plesk","severity":"CRITICAL","score":9.9,"description":"A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.","cwe":"CWE-367","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-68488"},{"id":"CVE-2026-89049","vendor":"AWS","product":"Amazon SSM Agent","severity":"CRITICAL","score":9.9,"description":"A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms mig\u2026","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89049"},{"id":"CVE-2026-89094","vendor":"Forgejo","product":"Forgejo","severity":"CRITICAL","score":9.9,"description":"Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89094"},{"id":"CVE-2026-9163","vendor":"GIS Informatics","product":"GisLab Laboratory Management System","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection.\n\nThis issue affects GisLab Laboratory Management System: from 1.\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-9163"},{"id":"CVE-2026-88877","vendor":"Canonical","product":"traefik","severity":"CRITICAL","score":9.8,"description":"Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-88877"},{"id":"CVE-2026-81467","vendor":"Dell","product":"ThinOS 10","severity":"CRITICAL","score":9.8,"description":"Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit \u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81467"},{"id":"CVE-2026-88018","vendor":"rclone","product":"rclone","severity":"CRITICAL","score":9.8,"description":"rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any cli\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-88018"},{"id":"CVE-2026-88899","vendor":"knowns-dev","product":"knowns","severity":"CRITICAL","score":9.8,"description":"knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root o\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-88899"},{"id":"CVE-2026-52098","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-52098"}],"vendor_spikes":[{"vendor":"IBM","count":49,"critical_count":8},{"vendor":"WordPress","count":44,"critical_count":1},{"vendor":"Unknown","count":17,"critical_count":1},{"vendor":"OISF","count":15,"critical_count":1},{"vendor":"MongoDB","count":15,"critical_count":0},{"vendor":"WWBN","count":11,"critical_count":1},{"vendor":"strongSwan","count":9,"critical_count":0},{"vendor":"renovatebot","count":8,"critical_count":0},{"vendor":"Dell","count":7,"critical_count":4},{"vendor":"tesseract-ocr","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":373,"has_news_data":true,"has_cve_data":true}