{"date_iso":"2026-09-15","date_human":"Tuesday, September 15, 2026","generated_utc":"2026-09-15 17:38 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Cisco email security boxes can be rooted by... an email","link":"https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604","reason":"CVE-2026-76461","category":"News","sources":["CISA Alerts & Advisories","CyberScoop","Rapid7 Blog","SecurityWeek","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":7,"cve_ids":["CVE-2026-76461"],"summary":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=260832&width=800","description":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly\u2026","related":[{"title":"Cisco warns customers of actively exploited zero-day in email gateways","link":"https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/","source":"CyberScoop","date_rel":"1h ago"},{"title":"CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"5h ago"},{"title":"Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution","link":"https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html","source":"The Hacker News","date_rel":"11h ago"},{"title":"Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation","link":"https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/","source":"SecurityWeek","date_rel":"12h ago"},{"title":"Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation","link":"https://www.sophos.com/en-us/blog/cisco-secure-email-gateway-vulnerability-cve-2026-76461-in-active-exploitation","source":"Sophos Threat Research","date_rel":"17h ago"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"14 Sep"}]},{"title":"CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments","link":"https://cybersecuritynews.com/cisa-active-directory-attack-techniques/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Infosecurity Magazine","Schneier on Security","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers use to compromise Microsoft Active Directory environments . The technical guide explains how\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CISA-Active-Directory-Attack-Techniques.webp","description":"CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers use to compromise Microsoft Active Directory environments . The technical guide explains how attackers exploit identity configurations, legacy protocols, certificate services, and privileged systems to escalate access, move laterally, and establish long-term persistence inside enterprise networks. Developed by the Australian Signals Directorate\u2019s Australian Cyber Security Center in cooperation with the US Cybersecurity and Infrastructure Security Agency and National\u2026","related":[{"title":"Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access","link":"https://cybersecuritynews.com/microsoft-ai-cyberattack-ban/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints","link":"https://www.securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"Microsoft confirms KB5002914 Excel update breaks copy and paste","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"Microsoft Releases Emergency Patch to Fix RDS Vulnerability","link":"https://www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/","source":"Infosecurity Magazine","date_rel":"8h ago"},{"title":"Microsoft releases emergency Windows updates to fix RDS failures","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"Microsoft\u2019s Patching","link":"https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html","source":"Schneier on Security","date_rel":"14 Sep"}]},{"title":"Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices","link":"https://cybersecuritynews.com/apple-security-update-273-vulnerabilities/","reason":"Apple","category":"News","sources":["Cyber Security News","Malwarebytes Labs","SANS Internet Storm Center","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The patches arrived\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Apple-Security-Update-1.webp","description":"Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The patches arrived on September 14, 2026, through iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27, alongside iOS and iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8. The 273 figure represents unique CVE identifiers across Apple\u2019s ten advisories, not the sum of every issue listed for each operating system. Many flaws affect shared frameworks\u2026","related":[{"title":"Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases","link":"https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Search results are sending people to fake Bitrefill checkouts","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts","source":"Malwarebytes Labs","date_rel":"8h ago"},{"title":"Apple Updates Everything, (Mon, Sep 14th)","link":"https://isc.sans.edu/diary/rss/33336","source":"SANS Internet Storm Center","date_rel":"23h ago"}]},{"title":"Google\u2019s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking","link":"https://cybersecuritynews.com/googles-new-search/","reason":"Google","category":"News","sources":["Cyber Security News","Huntress","Malwarebytes Labs","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser\u2019s link preview less useful as a quick safety\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Googles-New-Search-Redirects-Make-It-Harder-to-Check-Where-Links-Lead-Before-Clicking.webp","description":"Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser\u2019s link preview less useful as a quick safety check. The change comes as malicious advertising, search-result poisoning, and lookalike download pages keep turning ordinary searches into routes for scams and malware. Users may still see a familiar site name in the result, but their ability to compare that label with the actual link has weakened at the moment they decide whether to click. Analysts at Malwarebytes noted that the\u2026","related":[{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","source":"Huntress","date_rel":"4h ago"},{"title":"Investing Together: Wiz Defend and Google Security Operations","link":"https://www.wiz.io/blog/wiz-defend-and-google-security-operations","source":"Wiz Research","date_rel":"4h ago"},{"title":"Google\u2019s new search redirects make links harder to check before you click","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click","source":"Malwarebytes Labs","date_rel":"14 Sep"}]},{"title":"BambooToken Malware Uses MQTT to Control Windows and Linux Systems","link":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html","reason":"Linux","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News","Zero Day Initiative"],"coverage":4,"cve_ids":[],"summary":"Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7hFIl_GRAlPuegwLGZ2PzXVsPEUTEevpEYhkU2Va9isB7aC8a0jJCLVszVOUc_CAIb4IkIkmRjkvyaTIadUizNNEhHTxvzlPX0EUN6UQutjyrauyi35fzRtBjFudyOW4HlAnTRNC9XDj39uNBMKUWHUV2g0Rt8o3aSADZAeAIYgLN-dT0q8gIH9cWUDBF/s1600/windows-linux.jpg","description":"Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.","related":[{"title":"$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws","link":"https://www.securityweek.com/1-million-sandbox-challenge-uncovers-linux-kernel-flaws/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"BambooToken malware controls Windows and Linux systems via MQTT","link":"https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-702/","source":"Zero Day Initiative","date_rel":"14 Sep"},{"title":"ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-701/","source":"Zero Day Initiative","date_rel":"14 Sep"},{"title":"ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-700/","source":"Zero Day Initiative","date_rel":"14 Sep"}]},{"title":"HBO Max Reddit account compromised to serve ClickFix attacks","link":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408","reason":"Macos","category":"News","sources":["Bleeping Computer","SANS Internet Storm Center","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit\u2026","source":"The Register Security","date_rel":"18h ago","thumbnail":"https://image.theregister.com/?imageId=5296419&width=800","description":"Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author \u2014 this is the verified HBO Max account \u2014 and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a \u201csomewhat-legitimate\u201d looking landing page (hbomaxx[.]us) that includes\u2026","related":[{"title":"MacOS 27 - First Boot, (Tue, Sep 15th)","link":"https://isc.sans.edu/diary/rss/33340","source":"SANS Internet Storm Center","date_rel":"2h ago"},{"title":"Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack","link":"https://www.securityweek.com/hacked-hbo-reddit-account-used-for-malware-delivery-via-clickfix-attack/","source":"SecurityWeek","date_rel":"8h ago"},{"title":"Hackers hijack HBO Max Reddit account to push malware in ClickFix ads","link":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/","source":"Bleeping Computer","date_rel":"23h ago"}]},{"title":"CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks","link":"https://cybersecuritynews.com/cisco-secure-email-gateway-0-day-vulnerability-exploited/","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Dark Reading"],"coverage":4,"cve_ids":[],"summary":"CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks. The issue, tracked as\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CISA-Warns-of-Cisco-Secure-Email-Gateway-0-Day-Vulnerability-Actively-Exploited-in-Attacks-1.webp","description":"CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks. The issue, tracked as CVE-2026-76461, affects Cisco AsyncOS software used by Cisco Secure Email Gateway appliances. CVE-2026-76461 is an SQL injection vulnerability, categorized under CWE-89. It could allow an unauthenticated remote attacker to send specially crafted requests to a vulnerable Cisco Secure Email Gateway device and execute arbitrary commands on the underlying operating system. Successful\u2026","related":[{"title":"Cisco patches Secure Email Gateway zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/","source":"Bleeping Computer","date_rel":"10h ago"},{"title":"'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink","link":"https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink","source":"Dark Reading","date_rel":"20h ago"},{"title":"Cisco security advisory (AV26-921)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"A week in security (September 7 \u2013 September 13)","link":"https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-7-september-13","reason":"Android","category":"Threat Intel","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-65812","CVE-2026-69559"],"summary":"Here\u2019s what we\u2019ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your banking app BlueMoon\u2026","source":"Malwarebytes Labs","date_rel":"14 Sep","thumbnail":"","description":"Here\u2019s what we\u2019ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your banking app BlueMoon exploit kit turns Chrome and Windows flaws into attacks Will AI kill us all within the next decade? Update Chrome now to protect against an actively exploited vulnerability Copyright scammers get Instagram accounts suspended and demand payment More than 100,000 fake stores are out to steal your card details Microsoft fixes record 964 flaws, including 2 exploited zero-days The push\u2026","related":[{"title":"CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69559","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65812","source":"Microsoft Security","date_rel":"3h ago"},{"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920)","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920","source":"CCCS Alerts & Advisories","date_rel":"14 Sep"}]},{"title":"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE","link":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html","reason":"Chrome","category":"News","sources":["Bleeping Computer","Elastic Security Labs","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE\u2026","source":"The Hacker News","date_rel":"12h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5aJxmkQeaEoRUyxjlnH4uMELX24ICkHN1UpJaF3kM181M-V32GMskTo1YCRAf-8m4rsHw0nEYM53AC1CAZekv6yOEfBkj1ZNxL3lWatq_F5Bpuwsvw7snHIiIz62EA1pX-bPaawFgIwbvtUH020WdVwEupWi_CkYJVDog_w0LVEnMMvRYo0D7giAdtuGK/s1600/chrome-windows.jpg","description":"A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. \"The","related":[{"title":"Twitch extension with 30K installs exposes users\u2019 OAuth tokens","link":"https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions","link":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware","source":"Elastic Security Labs","date_rel":"14 Sep"}]},{"title":"VectraRAT Can Hack Windows Enterprises for $250 per Month","link":"https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises","reason":"Windows","category":"News","sources":["Dark Reading","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-68841","CVE-2026-69406","CVE-2026-69608"],"summary":"The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.","source":"Dark Reading","date_rel":"52m ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdd19a1ede5fda05d/6aa9273ab525586149ce55e2/rat-David_Chapman-Alamy.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68841","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69406","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69608","source":"Microsoft Security","date_rel":"3h ago"}]}],"worth_reading":[{"title":"On the NSA\u2019s Supercomputer from the 1960s","link":"https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html","reason":"Ibm","category":"Media","sources":["CCCS Alerts & Advisories","Schneier on Security"],"coverage":2,"cve_ids":[],"summary":"Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.","source":"Schneier on Security","date_rel":"7h ago","thumbnail":"","description":"","related":[{"title":"IBM security advisory (AV26-922)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-922","source":"CCCS Alerts & Advisories","date_rel":"3h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-90937","vendor":"F5","product":"froxlor","severity":"CRITICAL","score":9.9,"description":"froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlin\u2026","cwe":"CWE-93","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90937"},{"id":"CVE-2026-16338","vendor":"IBM","product":"DataStage on Cloud Pak for Data","severity":"CRITICAL","score":9.9,"description":"IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16338"},{"id":"CVE-2026-91001","vendor":"D-Link","product":"DI-8400","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results \u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-91001"},{"id":"CVE-2026-82232","vendor":"Apache","product":"Apache Syncope","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope.\n\n\n\nAn administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsa\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82232"},{"id":"CVE-2026-86460","vendor":"Apache","product":"Apache Syncope","severity":"CRITICAL","score":9.8,"description":"Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search\u00a0conditions.\n\n\n\nThis issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2.\n\n\n\nUser\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86460"},{"id":"CVE-2026-90898","vendor":"maximhq","product":"Bifrost","severity":"CRITICAL","score":9.8,"description":"Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.\n\n\n\nThe default is governance.auth_config.\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90898"},{"id":"CVE-2026-90919","vendor":"ModelTC","product":"LightLLM","severity":"CRITICAL","score":9.8,"description":"LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config S\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90919"},{"id":"CVE-2026-73470","vendor":"Apache","product":"Apache Syncope","severity":"CRITICAL","score":9.8,"description":"Improper Privilege Management vulnerability in Apache Syncope.\n\n\n\n\n\nDelegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for.\n\n\n\nThi\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73470"},{"id":"CVE-2026-73579","vendor":"Apache","product":"Apache Syncope","severity":"CRITICAL","score":9.8,"description":"Incorrect Authorization vulnerability in Apache Syncope.\n\n\n\nAny search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration.\nAn important component of such transfor\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73579"},{"id":"CVE-2026-73668","vendor":"Apache","product":"Apache Syncope","severity":"CRITICAL","score":9.8,"description":"Incorrect Authorization vulnerability in Apache Syncope.\n\n\n\n\n\nAn administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Re\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73668"}],"vendor_spikes":[{"vendor":"Apple","count":252,"critical_count":3},{"vendor":"IBM","count":61,"critical_count":2},{"vendor":"Apache","count":37,"critical_count":16},{"vendor":"Microsoft","count":30,"critical_count":6},{"vendor":"Unknown","count":20,"critical_count":0},{"vendor":"OpenIdentityPlatform","count":17,"critical_count":1},{"vendor":"Mattermost","count":14,"critical_count":0},{"vendor":"GNU","count":12,"critical_count":0},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"Kubernetes","count":11,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":726,"has_news_data":true,"has_cve_data":true}