{"date_iso":"2026-09-12","date_human":"Saturday, September 12, 2026","generated_utc":"2026-09-12 16:10 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"US Government Accuses Chinese AI Firms of Distilling Frontier Models","link":"https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Huntress"],"coverage":3,"cve_ids":[],"summary":"US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.","source":"Dark Reading","date_rel":"9 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt33b13b556aa2e63e/6aa1a92888ea9adc3dabaf29/distillery-ArtistGNDphotography-GettyImages-2195175104.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","source":"Huntress","date_rel":"just now"},{"title":"Google security advisory (AV26-904)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-904","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"}]},{"title":"Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits","link":"https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399","reason":"Chrome","category":"News","sources":["Ars Technica Security","Malwarebytes Labs","Proofpoint Threat Insight","SecurityWeek","The Hacker News","The Register Security","Volexity"],"coverage":7,"cve_ids":[],"summary":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US\u2026","source":"The Register Security","date_rel":"9 Sep","thumbnail":"https://image.theregister.com/?imageId=5295408&width=800","description":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. \u201cIn terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted,\" he said. \"However, the true number is almost\u2026","related":[{"title":"BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days","link":"https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/","source":"SecurityWeek","date_rel":"4h ago"},{"title":"BlueMoon exploit kit turns Chrome and Windows flaws into attacks","link":"https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks","source":"Malwarebytes Labs","date_rel":"10 Sep"},{"title":"Update Chrome now to protect against an actively exploited vulnerability","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability","source":"Malwarebytes Labs","date_rel":"10 Sep"},{"title":"Four groups caught using the same Chrome and Windows exploit kit","link":"https://www.proofpoint.com/us/newsroom/news/four-groups-caught-using-same-chrome-and-windows-exploit-kit","source":"Proofpoint Threat Insight","date_rel":"9 Sep"},{"title":"Four groups caught using the same Chrome and Windows exploit kit","link":"https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/","source":"Ars Technica Security","date_rel":"9 Sep"},{"title":"Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows","link":"https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/","source":"Volexity","date_rel":"9 Sep"}]},{"title":"Microsoft sees some new wrinkles in invoice-scam emails","link":"https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Infosecurity Magazine","The Record","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.","source":"The Record","date_rel":"21h ago","thumbnail":"http://cms.therecord.media/uploads/email_icon_chuttersnap_unsplash_a8cc9cf839.jpg","description":"","related":[{"title":"Passkey-themed phishing attacks lead to Microsoft 365 data theft","link":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"Hackers Favor US Eastern Business Hours in M365 Phishing Campaign","link":"https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/","source":"Infosecurity Magazine","date_rel":"11 Sep"},{"title":"Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections","link":"https://cybersecuritynews.com/windows-11-security-update-kb5124008/","source":"Cyber Security News","date_rel":"11 Sep"},{"title":"Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/","source":"Bleeping Computer","date_rel":"11 Sep"},{"title":"Most Organizations Skip Permissions Reviews Before Deploying AI Tools","link":"https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/","source":"Infosecurity Magazine","date_rel":"11 Sep"},{"title":"Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data","link":"https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data","source":"Dark Reading","date_rel":"10 Sep"}]},{"title":"ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories","link":"https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"A lot of this week\u2019s security news has the same awkward answer to one question: \u201cWhy was that allowed to work?\u201d An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old\u2026","source":"The Hacker News","date_rel":"10 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFNPIVe_Yx__WtfjnMTnoJSKPMcGPiMCP5NxEyv1gRcGSlnozG41TeGldWhQi7Hsc0XgcmC9tfTEBS-CdLLAz8cOskVbBOsghdSM9kg_AhQmhfMada8rs4l7O7Py8YJErqK54BIt0r06Sm1l62fy8yv6H8PJrEXWxjnvyLkyFKzzXcGI_h00yeBqck5v9L/s1600/td-main.jpg","description":"A lot of this week\u2019s security news has the same awkward answer to one question: \u201cWhy was that allowed to work?\u201d An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn\u2019t. Different stories, same basic problem: the path in was often already","related":[{"title":"Hackers abused Claude to extract secrets from 1.8M Android apps","link":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"Android malware creates a hidden copy of your banking app","link":"https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app","source":"Malwarebytes Labs","date_rel":"11 Sep"},{"title":"Indonesia Hit by Android Banking App-Cloning Campaign","link":"https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign","source":"Dark Reading","date_rel":"11 Sep"},{"title":"New Android malware encrypts files, steals data, and harasses victims","link":"https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/","source":"Bleeping Computer","date_rel":"10 Sep"},{"title":"Google Play Early Access Abused to Push Thousands of Deceptive Android Apps","link":"https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html","source":"The Hacker News","date_rel":"10 Sep"},{"title":"MantaxOtax Android Malware Combines Ransomware With Spyware","link":"https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/","source":"Infosecurity Magazine","date_rel":"10 Sep"}]},{"title":"Metasploit Wrap Up: This One Goes to Sixteen!","link":"https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen","reason":"Cisco","category":"Research","sources":["CCCS Alerts & Advisories","Rapid7 Blog","Sophos Threat Research","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit\u2026","source":"Rapid7 Blog","date_rel":"11 Sep","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0d50271a40a5f14f/6849ab419621d9f3824d5017/metasploit-sky.png","description":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516\u2026","related":[{"title":"Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware","link":"https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html","source":"The Hacker News","date_rel":"11 Sep"},{"title":"\u201cEye\u201d spy: Cyclops Blink returns with extended capabilities","link":"https://www.sophos.com/en-us/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities","source":"Sophos Threat Research","date_rel":"11 Sep"},{"title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","link":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html","source":"The Hacker News","date_rel":"10 Sep"},{"title":"Cisco security advisory (AV26-197) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"}]},{"title":"GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure","link":"https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html","reason":"Gitlab","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioFH6aWhF9NgRW1O3yFExc7paTA9akN5-3IUQF8mvEiSTaFJjKvm6YQzFX6MP2uimYplHe1MJXz6eZtPtnxaLy25jJBhU6KuhsWFpIlnqhbn6OI6QTcfp6Olp1-VDUEF4KEYFF7hQDBdmgtxibsg9MkvbcOJIlR8Of2Flyw2m9zYfXC6gUm-TV8XA6vU43/s1600/gitlab-wild.jpg","description":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under","related":[{"title":"GitLab security advisory (AV26-917)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917","source":"CCCS Alerts & Advisories","date_rel":"19h ago"},{"title":"GitLab\u2019s critical flaw is already drawing internet-wide probes","link":"https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/","source":"CyberScoop","date_rel":"21h ago"},{"title":"GitLab Vulnerability Exploited One Day After Disclosure","link":"https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/","source":"SecurityWeek","date_rel":"23h ago"}]},{"title":"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks","link":"https://cybersecuritynews.com/new-kataru-iot-malware/","reason":"Linux","category":"News","sources":["Cyber Security News","Elastic Security Labs","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-76023"],"summary":"KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then\u2026","source":"Cyber Security News","date_rel":"11 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-KATARU-IoT-Malware-Packs-Linux-Privilege-Escalation-Exploits-and-Mirai-Style-DDoS-Attacks.webp","description":"KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then downloaded an ARM payload. It shows how old entry points still give attackers a foothold. The malware resembles the Mirai botnet family in its ability to flood targets with traffic, but carries wider tools. It can attempt to gain root access, stay active through reboots, hide command traffic, and run commands supplied by its operators. A compromised device can therefore be harder to\u2026","related":[{"title":"Chromium CVE-2026-76023: Improper resource control in Linux Toolkit Theming","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76023","source":"Microsoft Security","date_rel":"15h ago"},{"title":"Linux Detection Engineering - Local Privilege Escalation","link":"https://www.elastic.co/security-labs/threat-command/linux-privilege-escalation-detection-framework","source":"Elastic Security Labs","date_rel":"11 Sep"}]},{"title":"CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/cisa-gitlab-path-traversal/","reason":"CVE-2026-85706","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News"],"coverage":3,"cve_ids":["CVE-2026-85706"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively\u2026","source":"Cyber Security News","date_rel":"11h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CISA-GitLab-Path-Traversal.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal vulnerability in GitLab\u2019s repository commits API. GitLab said that, under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication\u2026","related":[{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"11 Sep"},{"title":"GitLab urges users to patch max severity path traversal flaw","link":"https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/","source":"Bleeping Computer","date_rel":"11 Sep"}]},{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","link":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html","reason":"Windows","category":"News","sources":["Bleeping Computer","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-69461","CVE-2026-69468","CVE-2026-69732"],"summary":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital\u2026","source":"The Hacker News","date_rel":"11 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp8vDxYtUGwWuRZlSSBh2ghvSf6GTi_VlTQSQXTaIWSlQgHY_imEfl4hyAcrhPz9w3_ejmdAKK7ZeOt5gBsNZI7mhxJsnbyLT8Bo6O6HdM01yCNuDjuz-IU64LRuAuVDOzh2Z0vLhvzwP9PUUBKE_OLn0YD7m74-kZpo1dr5c0hzCMRHxrgfIzjk9MnR4/s1600/chinese.jpg","description":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns","related":[{"title":"CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69461","source":"Microsoft Security","date_rel":"11 Sep"},{"title":"CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69468","source":"Microsoft Security","date_rel":"11 Sep"},{"title":"CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69732","source":"Microsoft Security","date_rel":"11 Sep"},{"title":"September Windows Server updates break Remote Desktop Services","link":"https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/","source":"Bleeping Computer","date_rel":"10 Sep"}]},{"title":"Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent","link":"https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/","reason":"CVE-2026-85102","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-85102","CVE-2026-85103"],"summary":"The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.","source":"Bleeping Computer","date_rel":"1h ago","thumbnail":"","description":"","related":[{"title":"Check Point Patches Critical VPN Vulnerabilities","link":"https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/","source":"SecurityWeek","date_rel":"11 Sep"}]}],"worth_reading":[{"title":"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329","link":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201","reason":"CVE-2026-42016","category":"Research","sources":["CISA Alerts & Advisories","Wiz Research"],"coverage":2,"cve_ids":["CVE-2026-42016","CVE-2026-42018","CVE-2026-82329"],"summary":"Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining\u2026","source":"Wiz Research","date_rel":"10 Sep","thumbnail":"https://www.datocms-assets.com/75231/1789064682-image-22.png","description":"Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.","related":[{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"11 Sep"}]},{"title":"ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-679/","reason":"Adobe","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious\u2026","source":"Zero Day Initiative","date_rel":"10 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.","related":[{"title":"Adobe security advisory (AV26-808) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"10 Sep"},{"title":"ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-678/","source":"Zero Day Initiative","date_rel":"10 Sep"},{"title":"ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-677/","source":"Zero Day Initiative","date_rel":"10 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-80462","vendor":"Progress","product":"Chef Automate","severity":"CRITICAL","score":10.0,"description":"A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-80462"},{"id":"CVE-2026-85706","vendor":"GitLab","product":"GitLab","severity":"CRITICAL","score":10.0,"description":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLa\u2026","cwe":"CWE-22","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-09-14","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85706"},{"id":"CVE-2026-87719","vendor":"GitLab","product":"GitLab","severity":"CRITICAL","score":9.9,"description":"GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced S\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-87719"},{"id":"CVE-2026-89259","vendor":"gohugoio","product":"hugo","severity":"CRITICAL","score":9.8,"description":"Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS \u2014 included in the default security.exec.allow list \u2014 requires a highly permissive configuration (--allow-addons, --allow\u2026","cwe":"CWE-250","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89259"},{"id":"CVE-2026-84390","vendor":"Fortinet","product":"FortiMonitorOnSight","severity":"CRITICAL","score":9.8,"description":"A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>","cwe":"CWE-540","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84390"},{"id":"CVE-2026-71644","vendor":"Unknown","product":"","severity":"CRITICAL","score":9.8,"description":"An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publ\u2026","cwe":"CWE-843","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71644"},{"id":"CVE-2026-89010","vendor":"WAVLINK Technology","product":"WN535M1","severity":"CRITICAL","score":9.8,"description":"WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89010"},{"id":"CVE-2026-72709","vendor":"SPIP","product":"SPIP","severity":"CRITICAL","score":9.8,"description":"SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72709"},{"id":"CVE-2026-72710","vendor":"SPIP","product":"SPIP","severity":"CRITICAL","score":9.8,"description":"SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject a\u2026","cwe":"CWE-915","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-72710"},{"id":"CVE-2026-62103","vendor":"wpeverest","product":"Everest Forms","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-62103"}],"vendor_spikes":[{"vendor":"Linux","count":387,"critical_count":0},{"vendor":"WordPress","count":53,"critical_count":2},{"vendor":"Apple","count":21,"critical_count":0},{"vendor":"WWBN","count":20,"critical_count":0},{"vendor":"CISA","count":15,"critical_count":0},{"vendor":"HashiCorp","count":14,"critical_count":0},{"vendor":"Concrete CMS","count":14,"critical_count":0},{"vendor":"Microsoft","count":13,"critical_count":0},{"vendor":"Unknown","count":12,"critical_count":2},{"vendor":"mistralai","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":676,"has_news_data":true,"has_cve_data":true}