{"date_iso":"2026-09-13","date_human":"Sunday, September 13, 2026","generated_utc":"2026-09-13 16:56 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","link":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html","reason":"Windows","category":"News","sources":["Bleeping Computer","Huntress","Microsoft Security","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-51990","CVE-2026-69461","CVE-2026-69468","CVE-2026-69732"],"summary":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital\u2026","source":"The Hacker News","date_rel":"11 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp8vDxYtUGwWuRZlSSBh2ghvSf6GTi_VlTQSQXTaIWSlQgHY_imEfl4hyAcrhPz9w3_ejmdAKK7ZeOt5gBsNZI7mhxJsnbyLT8Bo6O6HdM01yCNuDjuz-IU64LRuAuVDOzh2Z0vLhvzwP9PUUBKE_OLn0YD7m74-kZpo1dr5c0hzCMRHxrgfIzjk9MnR4/s1600/chinese.jpg","description":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns","related":[{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","source":"Huntress","date_rel":"just now"},{"title":"Hackers exploit Tencent app flaw to deploy GrayRabbit malware","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days","link":"https://www.securityweek.com/bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days/","source":"SecurityWeek","date_rel":"12 Sep"},{"title":"CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69461","source":"Microsoft Security","date_rel":"11 Sep"},{"title":"CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69468","source":"Microsoft Security","date_rel":"11 Sep"},{"title":"CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69732","source":"Microsoft Security","date_rel":"11 Sep"}]},{"title":"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data","link":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","The Hacker News","The Record"],"coverage":5,"cve_ids":[],"summary":"Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZ2E2hmYwxfZ25xw5iPhCHaSDENcuEyEIaha9e_rIJCf68srth31FtjIiIlnOcEiSQDDuk2Vg-dQdNLfR753ePSoDntP3BS-MGbEH2DS8Ch5ihzhpiDZZm5UIzKCbL1vNJSwSABCYst8oG6Oa-7iBWaSF6WSTEkCJBAi9YEEwAmVEdGYvu-JWZnxwEX9ni/s1600/ms-outlook.jpg","description":"Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers","related":[{"title":"Microsoft sees some new wrinkles in invoice-scam emails","link":"https://therecord.media/invoice-scam-emails-new-features-microsoft-researchers","source":"The Record","date_rel":"11 Sep"},{"title":"Passkey-themed phishing attacks lead to Microsoft 365 data theft","link":"https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/","source":"Bleeping Computer","date_rel":"11 Sep"},{"title":"Hackers Favor US Eastern Business Hours in M365 Phishing Campaign","link":"https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/","source":"Infosecurity Magazine","date_rel":"11 Sep"},{"title":"Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/","source":"Bleeping Computer","date_rel":"11 Sep"},{"title":"Most Organizations Skip Permissions Reviews Before Deploying AI Tools","link":"https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/","source":"Infosecurity Magazine","date_rel":"11 Sep"},{"title":"Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data","link":"https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data","source":"Dark Reading","date_rel":"10 Sep"}]},{"title":"Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers","link":"https://cybersecuritynews.com/plesk-backup-manager-flaw/","reason":"Linux","category":"News","sources":["Cyber Security News","Elastic Security Labs","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-68488","CVE-2026-76023"],"summary":"A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a\u2026","source":"Cyber Security News","date_rel":"11h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Plesk-Backup-Manager-Flaw-Lets-Low-Privileged-Users-Gain-Root-Access-to-Servers.webp","description":"A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations. The issue affects Plesk Obsidian installations running Plesk for Linux versions 18.0.80.6 and earlier, as well as 18.0.79.10 and earlier. Plesk for Windows is not affected. According to Plesk, the vulnerability exists in the Backup Manager workflow used to restore content belonging to a customer subscription. A\u2026","related":[{"title":"Chromium CVE-2026-76023: Improper resource control in Linux Toolkit Theming","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76023","source":"Microsoft Security","date_rel":"12 Sep"},{"title":"New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks","link":"https://cybersecuritynews.com/new-kataru-iot-malware/","source":"Cyber Security News","date_rel":"11 Sep"},{"title":"Linux Detection Engineering - Local Privilege Escalation","link":"https://www.elastic.co/security-labs/threat-command/linux-privilege-escalation-detection-framework","source":"Elastic Security Labs","date_rel":"11 Sep"}]},{"title":"GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure","link":"https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html","reason":"Gitlab","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is\u2026","source":"The Hacker News","date_rel":"11 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioFH6aWhF9NgRW1O3yFExc7paTA9akN5-3IUQF8mvEiSTaFJjKvm6YQzFX6MP2uimYplHe1MJXz6eZtPtnxaLy25jJBhU6KuhsWFpIlnqhbn6OI6QTcfp6Olp1-VDUEF4KEYFF7hQDBdmgtxibsg9MkvbcOJIlR8Of2Flyw2m9zYfXC6gUm-TV8XA6vU43/s1600/gitlab-wild.jpg","description":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under","related":[{"title":"GitLab security advisory (AV26-917)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917","source":"CCCS Alerts & Advisories","date_rel":"11 Sep"},{"title":"GitLab\u2019s critical flaw is already drawing internet-wide probes","link":"https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/","source":"CyberScoop","date_rel":"11 Sep"},{"title":"GitLab Vulnerability Exploited One Day After Disclosure","link":"https://www.securityweek.com/gitlab-vulnerability-exploited-one-day-after-disclosure/","source":"SecurityWeek","date_rel":"11 Sep"}]},{"title":"ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories","link":"https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html","reason":"Android","category":"News","sources":["Bleeping Computer","Dark Reading","Malwarebytes Labs","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A lot of this week\u2019s security news has the same awkward answer to one question: \u201cWhy was that allowed to work?\u201d An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old\u2026","source":"The Hacker News","date_rel":"10 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFNPIVe_Yx__WtfjnMTnoJSKPMcGPiMCP5NxEyv1gRcGSlnozG41TeGldWhQi7Hsc0XgcmC9tfTEBS-CdLLAz8cOskVbBOsghdSM9kg_AhQmhfMada8rs4l7O7Py8YJErqK54BIt0r06Sm1l62fy8yv6H8PJrEXWxjnvyLkyFKzzXcGI_h00yeBqck5v9L/s1600/td-main.jpg","description":"A lot of this week\u2019s security news has the same awkward answer to one question: \u201cWhy was that allowed to work?\u201d An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn\u2019t. Different stories, same basic problem: the path in was often already","related":[{"title":"Hackers abused Claude to extract secrets from 1.8M Android apps","link":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/","source":"Bleeping Computer","date_rel":"11 Sep"},{"title":"Android malware creates a hidden copy of your banking app","link":"https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app","source":"Malwarebytes Labs","date_rel":"11 Sep"},{"title":"Indonesia Hit by Android Banking App-Cloning Campaign","link":"https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign","source":"Dark Reading","date_rel":"11 Sep"},{"title":"New Android malware encrypts files, steals data, and harasses victims","link":"https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/","source":"Bleeping Computer","date_rel":"10 Sep"}]},{"title":"CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/cisa-gitlab-path-traversal/","reason":"CVE-2026-85706","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cyber Security News"],"coverage":3,"cve_ids":["CVE-2026-85706"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively\u2026","source":"Cyber Security News","date_rel":"12 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CISA-GitLab-Path-Traversal.webp","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal vulnerability in GitLab\u2019s repository commits API. GitLab said that, under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication\u2026","related":[{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"11 Sep"},{"title":"GitLab urges users to patch max severity path traversal flaw","link":"https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/","source":"Bleeping Computer","date_rel":"11 Sep"}]},{"title":"Metasploit Wrap Up: This One Goes to Sixteen!","link":"https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen","reason":"Cisco","category":"Research","sources":["Rapid7 Blog","Sophos Threat Research","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit\u2026","source":"Rapid7 Blog","date_rel":"11 Sep","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt0d50271a40a5f14f/6849ab419621d9f3824d5017/metasploit-sky.png","description":"This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516\u2026","related":[{"title":"Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware","link":"https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html","source":"The Hacker News","date_rel":"11 Sep"},{"title":"\u201cEye\u201d spy: Cyclops Blink returns with extended capabilities","link":"https://www.sophos.com/en-us/blog/-eye-spy-cyclops-blink-returns-with-extended-capabilities","source":"Sophos Threat Research","date_rel":"11 Sep"}]},{"title":"Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent","link":"https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/","reason":"CVE-2026-85102","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-85102","CVE-2026-85103"],"summary":"The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.","source":"Bleeping Computer","date_rel":"12 Sep","thumbnail":"","description":"","related":[{"title":"Check Point Patches Critical VPN Vulnerabilities","link":"https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/","source":"SecurityWeek","date_rel":"11 Sep"}]},{"title":"Containing Machine Speed Cyber Attacks Inside AI Infrastructure","link":"https://cybersecuritynews.com/containing-machine-speed-cyber-attacks-inside-ai-infrastructure/","reason":"Teams","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents\u2026","source":"Cyber Security News","date_rel":"12 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/agnidiptas.webp","description":"A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents operated at a human pace. Our defenses have relied on human error, human speed, and human limitations. That era is over. AI-driven adversaries have fundamentally changed the pace of cyber conflict. They act without delay and do not follow the timelines our processes were designed for. This mismatch is most evident and most dangerous within AI infrastructure. Cybersecurity is\u2026","related":[{"title":"Your Critical Vulnerabilities Might Not Be Your Biggest Risk","link":"https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html","source":"The Hacker News","date_rel":"11 Sep"}]},{"title":"Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329","link":"https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201","reason":"CVE-2026-42016","category":"Research","sources":["CISA Alerts & Advisories","Wiz Research"],"coverage":2,"cve_ids":["CVE-2026-42016","CVE-2026-42018","CVE-2026-82329"],"summary":"Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining\u2026","source":"Wiz Research","date_rel":"10 Sep","thumbnail":"https://www.datocms-assets.com/75231/1789064682-image-22.png","description":"Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.","related":[{"title":"CISA Adds Three Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-three-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"11 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-90558","vendor":"irontec","product":"sngrep","severity":"CRITICAL","score":9.8,"description":"sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or ot\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90558"},{"id":"CVE-2026-15451","vendor":"WordPress","product":"MemberPress Corporate Accounts","severity":"HIGH","score":8.8,"description":"The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the ra\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-15451"},{"id":"CVE-2026-90493","vendor":"Microsoft","product":"Internet Download Manager","severity":"HIGH","score":8.8,"description":"A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access c\u2026","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90493"},{"id":"CVE-2026-90537","vendor":"WWBN","product":"AVideo","severity":"HIGH","score":8.2,"description":"WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a si\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90537"},{"id":"CVE-2026-90560","vendor":"luben","product":"zstd-jni","severity":"HIGH","score":8.2,"description":"zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arb\u2026","cwe":"CWE-125","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90560"},{"id":"CVE-2026-90651","vendor":"F5","product":"Socket Firewall","severity":"HIGH","score":8.1,"description":"Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the gen\u2026","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90651"},{"id":"CVE-2026-90553","vendor":"vllm-project","product":"vLLM","severity":"HIGH","score":7.8,"description":"vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitra\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90553"},{"id":"CVE-2026-90556","vendor":"freeciv","product":"freeciv","severity":"HIGH","score":7.8,"description":"Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that \u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90556"},{"id":"CVE-2026-90559","vendor":"xerial","product":"snappy-java","severity":"HIGH","score":7.5,"description":"snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed \u2026","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90559"},{"id":"CVE-2026-90668","vendor":"UnrealIRCd","product":"UnrealIRCd","severity":"HIGH","score":7.5,"description":"The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with\u2026","cwe":"CWE-770","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90668"}],"vendor_spikes":[{"vendor":"WWBN","count":16,"critical_count":0},{"vendor":"WordPress","count":11,"critical_count":0},{"vendor":"Microsoft","count":6,"critical_count":0},{"vendor":"lenve","count":5,"critical_count":0},{"vendor":"vvbbnn00","count":4,"critical_count":0},{"vendor":"FlowiseAI","count":3,"critical_count":0},{"vendor":"vllm-project","count":3,"critical_count":0},{"vendor":"Xuxueli","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":75,"has_news_data":true,"has_cve_data":true}