{"date_iso":"2026-09-17","date_human":"Thursday, September 17, 2026","generated_utc":"2026-09-17 17:35 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino","link":"https://cybersecuritynews.com/hacked-thai-college-website-abused-to-redirect-google-searchers-to-illegal-online-casino/","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Huntress","Malwarebytes Labs","The Hacker News","The Register Security","Wiz Research"],"coverage":7,"cve_ids":[],"summary":"A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform ADEX, which says the campaign achieved full ad cloaking without\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hacked-Thai-College-Website-Abused-to-Redirect-Google-Searchers-to-Illegal-Online-Casino.webp","description":"A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform ADEX, which says the campaign achieved full ad cloaking without deploying a single line of cloaking code, mirroring evasion tactics seen in campaigns designed to bypass Google Ads screening . The scheme, uncovered by ADEX\u2019s traffic-monitoring team, abused the genuine domain km.chpc.ac.th, which sits in Thailand\u2019s .ac.th zone reserved for educational institutions. Attackers planted a casino-themed page on the hacked site, which Google indexed\u2026","related":[{"title":"CISO's Expert Guide to Agentic Pentesting for Websites","link":"https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html","source":"The Hacker News","date_rel":"6h ago"},{"title":"Google Pixel phones pwned in zero-click attacks","link":"https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936","source":"The Register Security","date_rel":"23h ago"},{"title":"Google security advisory (AV26-926)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-926","source":"CCCS Alerts & Advisories","date_rel":"16 Sep"},{"title":"Google Pixel owners urged to patch actively exploited modem flaw","link":"https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw","source":"Malwarebytes Labs","date_rel":"16 Sep"},{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","source":"Huntress","date_rel":"15 Sep"},{"title":"Investing Together: Wiz Defend and Google Security Operations","link":"https://www.wiz.io/blog/wiz-defend-and-google-security-operations","source":"Wiz Research","date_rel":"15 Sep"}]},{"title":"Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware","link":"https://cybersecuritynews.com/heavygram-surveillance-malware/","reason":"Windows","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Microsoft Security","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":7,"cve_ids":["CVE-2026-33835","CVE-2026-50311","CVE-2026-62819"],"summary":"HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Turn-Telegram-Into-a-Command-Center-for-HEAVYGRAM-Surveillance-Malware.webp","description":"HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accounts and groups to receive instructions, move stolen data and keep infected devices under control. The malware has been used since fall 2023 against journalists, Iranian dissidents and people whose views oppose Iran\u2019s government. Victims were approached through messaging apps by people posing as familiar contacts or technical support, then sent files disguised as applications or services. The campaign also relies on\u2026","related":[{"title":"CVE-2026-50311 Windows Server Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50311","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33835","source":"Microsoft Security","date_rel":"3h ago"},{"title":"Iranian hackers use CHOSEN BRICK Windows malware to spy on targets","link":"https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"September Patch Tuesday haul includes 973 CVEs","link":"https://www.sophos.com/en-us/blog/september-2026-patch-tuesday","source":"Sophos Threat Research","date_rel":"16 Sep"},{"title":"Iranian spies hit Windows machines with Chosen Brick data-stealing malware","link":"https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646","source":"The Register Security","date_rel":"15 Sep"}]},{"title":"'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink","link":"https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","SecurityWeek","Zero Day Initiative"],"coverage":6,"cve_ids":[],"summary":"The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.","source":"Dark Reading","date_rel":"14 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc3c48d3f94f040d1/6aa866a635d26cae06cd28c4/cyclops-ratpack223-Getty-2194261969.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Cisco security advisory (AV26-932)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-932","source":"CCCS Alerts & Advisories","date_rel":"2h ago"},{"title":"Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard","link":"https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Cisco Warns of Active Exploitation of Critical ISE Flaw","link":"https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/","source":"Infosecurity Magazine","date_rel":"6h ago"},{"title":"Cisco warns of max severity ISE zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"10h ago"},{"title":"ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-709/","source":"Zero Day Initiative","date_rel":"16 Sep"},{"title":"Cisco security advisory (AV26-921)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921","source":"CCCS Alerts & Advisories","date_rel":"14 Sep"}]},{"title":"A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire","link":"https://www.youtube.com/watch?v=fp959e8GFT4","reason":"Android","category":"Podcast","sources":["404 Media","CCCS Alerts & Advisories","Hak5","Infosecurity Magazine","Microsoft Security"],"coverage":5,"cve_ids":["CVE-2026-65812","CVE-2026-69559"],"summary":"What if a phone call could spread a zero-click worm without you answering, tapping a link, or doing anything at all? Security researchers built WeWorm, a proof-of-concept that exploited WeChat calls on iOS and Android\u2026","source":"Hak5","date_rel":"1h ago","thumbnail":"https://i3.ytimg.com/vi/fp959e8GFT4/hqdefault.jpg","description":"What if a phone call could spread a zero-click worm without you answering, tapping a link, or doing anything at all? Security researchers built WeWorm, a proof-of-concept that exploited WeChat calls on iOS and Android, revealing how a zero-click vulnerability could turn a messaging app into a self-spreading attack. \u2b07\ufe0f OPEN FOR LINKS TO ARTICLES TO LEARN MORE \u2b07\ufe0f @endingwithali \u2192 Twitch: https://twitch.tv/endingwithali Twitter: https://twitter.com/endingwithali YouTube: https://youtube.com/@endingwithali Everywhere else: https://links.ali.dev Want to work with Ali? hak5@endingwithali.com [\u2757]\u2026","related":[{"title":"University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It","link":"https://www.404media.co/university-rescinds-job-offer-to-activist-who-allegedly-wiped-phone-before-dhs-could-search-it/","source":"404 Media","date_rel":"2h ago"},{"title":"New Chinese-Made \u2018RatHat\u2019 Android Malware Leverages AI to Steal Financial Data","link":"https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/","source":"Infosecurity Magazine","date_rel":"4h ago"},{"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920","source":"CCCS Alerts & Advisories","date_rel":"16 Sep"},{"title":"CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69559","source":"Microsoft Security","date_rel":"15 Sep"},{"title":"CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65812","source":"Microsoft Security","date_rel":"15 Sep"}]},{"title":"Mythos has made 2026 patching hell. It might make 2027 a breeze","link":"https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","The Register Security","Zero Day Initiative"],"coverage":5,"cve_ids":[],"summary":"When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their\u2026","source":"The Register Security","date_rel":"16 Sep","thumbnail":"https://image.theregister.com/?imageId=4093186&width=800","description":"When Microsoft delivered over 970 patches last week, many saw a nightmare for beleaguered security staff. Gartner research vice president Craig Lawson thinks infosec workers might soon see sunlit uplands as their workloads ease. Lawson outlined that scenario at Gartner\u2019s IT Symposium in Australia today and explained it by theorising that the increased volume of vulnerability discoveries made possible by Anthropic\u2019s Mythos and other bug-hunting AI might be getting close to finding most of the flaws in established codebases. \u201cWe've never had a situation where massive codebases have been audited\u2026","related":[{"title":"Windows 11 24H2 Home and Pro reach end of support in October","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-october/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Microsoft shares workaround for Windows domain login issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-workaround-for-windows-domain-login-authentication-issues/","source":"Bleeping Computer","date_rel":"9h ago"},{"title":"Windows 11 KB5124008 update breaks domain trust for some users","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/","source":"Bleeping Computer","date_rel":"20h ago"},{"title":"ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-708/","source":"Zero Day Initiative","date_rel":"16 Sep"},{"title":"Microsoft Issues Emergency Fixes After Massive Patch Tuesday","link":"https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday","source":"Dark Reading","date_rel":"15 Sep"},{"title":"Microsoft Releases Emergency Patch to Fix RDS Vulnerability","link":"https://www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/","source":"Infosecurity Magazine","date_rel":"15 Sep"}]},{"title":"Cisco drops another exploited zero-day, this time a perfect 10","link":"https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180","reason":"CVE-2026-76460","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-76460"],"summary":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication\u2026","source":"The Register Security","date_rel":"4h ago","thumbnail":"https://image.theregister.com/?imageId=5249134&width=800","description":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its\u2026","related":[{"title":"Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks","link":"https://cybersecuritynews.com/cisco-warns-of-critical-ise-0-day-vulnerability-exploited/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks","link":"https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html","source":"The Hacker News","date_rel":"10h ago"},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"16 Sep"}]},{"title":"FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor","link":"https://cybersecuritynews.com/famoussparrow-exploits/","reason":"Exchange","category":"News","sources":["Cisco Security Advisories","Cyber Security News","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-50696"],"summary":"FamousSparrow has introduced a new backdoor called SparroWocky after breaking into public-facing Microsoft Exchange servers. The campaign shows how a known espionage group can turn an exposed email system into a quiet\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/FamousSparrow-Exploits-Public-Facing-Exchange-Servers-to-Deploy-SparroWocky-Backdoor.webp","description":"FamousSparrow has introduced a new backdoor called SparroWocky after breaking into public-facing Microsoft Exchange servers. The campaign shows how a known espionage group can turn an exposed email system into a quiet, long-term entry point inside a government network. The impact extends beyond the first host, because email servers commonly hold sensitive messages and trusted network connections. The activity has concentrated on Latin America since mid-2025, with governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela among the observed targets\u2026","related":[{"title":"Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20IKEv2%20Certificate%20Authentication%20Denial%20of%20Service%20Vulnerability%26vs_k=1","source":"Cisco Security Advisories","date_rel":"16 Sep"},{"title":"CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50696","source":"Microsoft Security","date_rel":"15 Sep"}]},{"title":"The vulnpocalypse rains iBugs down on Apple with record-setting number of patches","link":"https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679","reason":"Apple","category":"News","sources":["CCCS Alerts & Advisories","SANS Internet Storm Center","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history. While this CVE count is hardly notable\u2026","source":"The Register Security","date_rel":"15 Sep","thumbnail":"https://image.theregister.com/?imageId=5296699&width=800","description":"Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino's history. While this CVE count is hardly notable compared to some vendors - hello, Microsoft\u2019s record-breaking 974 bugs disclosed earlier this month - it does set a company record for Apple. It also reflects the new reality of AI-driven bug hunting, as models become exponentially better and faster at finding security vulnerabilities. However, the flip side of the AI coin we were promised - that models would also excel at\u2026","related":[{"title":"Apple security advisory (AV26-930)","link":"https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-930","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Apple Updates Everything, (Mon, Sep 14th)","link":"https://isc.sans.edu/diary/rss/33336","source":"SANS Internet Storm Center","date_rel":"14 Sep"}]},{"title":"Cisco email security boxes can be rooted by... an email","link":"https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604","reason":"CVE-2026-76461","category":"News","sources":["CyberScoop","Rapid7 Blog","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-76461"],"summary":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and\u2026","source":"The Register Security","date_rel":"15 Sep","thumbnail":"https://image.theregister.com/?imageId=260832&width=800","description":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly\u2026","related":[{"title":"Cisco warns customers of actively exploited zero-day in email gateways","link":"https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/","source":"CyberScoop","date_rel":"15 Sep"},{"title":"CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"15 Sep"},{"title":"Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution","link":"https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html","source":"The Hacker News","date_rel":"15 Sep"},{"title":"Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation","link":"https://www.sophos.com/en-us/blog/cisco-secure-email-gateway-vulnerability-cve-2026-76461-in-active-exploitation","source":"Sophos Threat Research","date_rel":"15 Sep"}]},{"title":"ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-703/","reason":"Sharepoint","category":"Research","sources":["Microsoft Security","Zero Day Initiative"],"coverage":2,"cve_ids":["CVE-2026-69724"],"summary":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"16 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.","related":[{"title":"CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69724","source":"Microsoft Security","date_rel":"3h ago"}]}],"worth_reading":[{"title":"Oracle September 2026 Critical Security Patch Update addresses 672 CVEs","link":"https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves","reason":"Oracle","category":"Research","sources":["CCCS Alerts & Advisories","Tenable Blog"],"coverage":2,"cve_ids":[],"summary":"Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for\u2026","source":"Tenable Blog","date_rel":"15 Sep","thumbnail":"","description":"Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches Background On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026 . Beginning in May 2026, Oracle introduced CSPUs as a\u2026","related":[{"title":"Oracle Corporation security advisory (AV26-929)","link":"https://cyber.gc.ca/en/alerts-advisories/oracle-corporation-security-advisory-av26-929","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-70416","vendor":"Dell","product":"ObjectScale","severity":"CRITICAL","score":10.0,"description":"Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-70416"},{"id":"CVE-2026-73456","vendor":"Arista Networks","product":"EOS","severity":"CRITICAL","score":10.0,"description":"Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an a\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73456"},{"id":"CVE-2026-20130","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20130"},{"id":"CVE-2026-20192","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security \u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20192"},{"id":"CVE-2026-76423","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":10.0,"description":"A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device.\r\n\r\nThis vulnerability is due to the REST API web service being exposed with \u2026","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76423"},{"id":"CVE-2026-76460","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":10.0,"description":"A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.\r\n\r\nThis vulnerability is due to insufficient authentication control on an API endpoint. An attacker \u2026","cwe":"CWE-648","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-09-19","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76460"},{"id":"CVE-2026-20234","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":9.9,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security \u2026","cwe":"CWE-522","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20234"},{"id":"CVE-2026-20307","vendor":"Cisco","product":"Cisco Identity Services Engine Software","severity":"CRITICAL","score":9.9,"description":"A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the atta\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20307"},{"id":"CVE-2026-20322","vendor":"Cisco","product":"Cisco Nexus Dashboard","severity":"CRITICAL","score":9.9,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release th\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20322"},{"id":"CVE-2026-20324","vendor":"Cisco","product":"Cisco Secure Firewall Management Center (FMC)","severity":"CRITICAL","score":9.9,"description":"A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.\r\n\r\nThis vulnerability exists \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20324"}],"vendor_spikes":[{"vendor":"Linux","count":232,"critical_count":20},{"vendor":"Cisco","count":79,"critical_count":24},{"vendor":"WordPress","count":35,"critical_count":1},{"vendor":"Microsoft","count":22,"critical_count":1},{"vendor":"Jenkins","count":20,"critical_count":0},{"vendor":"Unknown","count":20,"critical_count":0},{"vendor":"Advantech","count":15,"critical_count":0},{"vendor":"Qualcomm","count":15,"critical_count":0},{"vendor":"ISC","count":14,"critical_count":0},{"vendor":"HP","count":13,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":764,"has_news_data":true,"has_cve_data":true}