{"date_iso":"2026-09-19","date_human":"Saturday, September 19, 2026","generated_utc":"2026-09-19 16:22 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall","link":"https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html","reason":"Android","category":"News","sources":["404 Media","Bleeping Computer","CCCS Alerts & Advisories","Hak5","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":7,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control\u2026","source":"The Hacker News","date_rel":"18 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5Psm8tS3JWb6ev7nZoz7YQDPIgoHj9gwbNjgjxbokxICdzRIUb5YJI-XfDx0NQgm8afhayc-Zd51hjuxqi7Sk_XxCNXoTNt7nIZWpxCBcDMLjSm3uW38HRciOu3WNtaUT0a-2NSsOX91GbXpCScryNirImMMC4lkuVysHku58maTbm9XvAwJ0-X6O_wDE/s1600/1000109602.jpg","description":"Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. \"Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses","related":[{"title":"New Android malware uses AI to steal bank logins and PINs","link":"https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins","source":"Malwarebytes Labs","date_rel":"18 Sep"},{"title":"New RatHat Android malware uses AI to automate device control","link":"https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/","source":"Bleeping Computer","date_rel":"17 Sep"},{"title":"A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire","link":"https://www.youtube.com/watch?v=fp959e8GFT4","source":"Hak5","date_rel":"17 Sep"},{"title":"University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It","link":"https://www.404media.co/university-rescinds-job-offer-to-activist-who-allegedly-wiped-phone-before-dhs-could-search-it/","source":"404 Media","date_rel":"17 Sep"},{"title":"New Chinese-Made \u2018RatHat\u2019 Android Malware Leverages AI to Steal Financial Data","link":"https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/","source":"Infosecurity Magazine","date_rel":"17 Sep"},{"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920","source":"CCCS Alerts & Advisories","date_rel":"16 Sep"}]},{"title":"Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test","link":"https://cybersecuritynews.com/google-gemini-ai-hacked-3-real-companies/","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News","The Register Security","Wired Security"],"coverage":5,"cve_ids":[],"summary":"Google has confirmed that its Gemini artificial intelligence model accessed protected systems belonging to three companies during a cybersecurity evaluation after a testing error exposed the agent to the public\u2026","source":"Cyber Security News","date_rel":"7h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Google-Gemini-AI-Hacked-3-Real-Companies.webp","description":"Google has confirmed that its Gemini artificial intelligence model accessed protected systems belonging to three companies during a cybersecurity evaluation after a testing error exposed the agent to the public internet. The incident shows how an autonomous AI system can move beyond a sandbox when controls, target definitions, and network isolation fail even without instructions to attack organizations. Irregular, a company that evaluates AI models for cybersecurity capabilities, conducted the exercise. Gemini was participating in a \u201ccapture the flag\u201d challenge, a security test in which an\u2026","related":[{"title":"Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up","link":"https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html","source":"The Hacker News","date_rel":"8h ago"},{"title":"An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang","link":"https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/","source":"Wired Security","date_rel":"18 Sep"},{"title":"Google security advisory (AV26-939)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-939","source":"CCCS Alerts & Advisories","date_rel":"18 Sep"},{"title":"CISO's Expert Guide to Agentic Pentesting for Websites","link":"https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html","source":"The Hacker News","date_rel":"17 Sep"},{"title":"Google Pixel phones pwned in zero-click attacks","link":"https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936","source":"The Register Security","date_rel":"16 Sep"},{"title":"Google security advisory (AV26-926)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-926","source":"CCCS Alerts & Advisories","date_rel":"16 Sep"}]},{"title":"CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild","link":"https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html","reason":"Linux","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","The Hacker News","Zero Day Initiative"],"coverage":4,"cve_ids":["CVE-2025-39682","CVE-2025-39964","CVE-2026-53266"],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcKuQ4GC9r1-4fQ3Ap_CQko0y3nMI0SnATF3WNSv48uFtNskrV4PqnyW4s0L7sXcojrHoJCEZRazGJNz5JhxrTTSYZSAQeD-xwdquE3X7pJ_ylBUerrybIiaE3V-i1vXdiLr_N1KCM9GTmeAKLlgySqEr0QeCB5ckvnppiEHSZhnEqv0IfUnqCKdA1kKsN/s1600/cisa-linux.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path","related":[{"title":"Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root","link":"https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html","source":"The Hacker News","date_rel":"22h ago"},{"title":"Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access","link":"https://cybersecuritynews.com/linux-kernel-privilege-escalation-flaws/","source":"Cyber Security News","date_rel":"18 Sep"},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"18 Sep"},{"title":"ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-715/","source":"Zero Day Initiative","date_rel":"18 Sep"}]},{"title":"Cisco drops another exploited zero-day, this time a perfect 10","link":"https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180","reason":"CVE-2026-76460","category":"News","sources":["CCCS Alerts & Advisories","CyberScoop","Dark Reading","The Hacker News","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-20192","CVE-2026-76423","CVE-2026-76460"],"summary":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication\u2026","source":"The Register Security","date_rel":"17 Sep","thumbnail":"https://image.theregister.com/?imageId=5249134&width=800","description":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its\u2026","related":[{"title":"Cisco Zero-Day Highlights API Endpoint Authentication Issues","link":"https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues","source":"Dark Reading","date_rel":"20h ago"},{"title":"Cisco alerts customers to second actively exploited zero-day in as many days","link":"https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/","source":"CyberScoop","date_rel":"17 Sep"},{"title":"AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460","link":"https://cyber.gc.ca/en/alerts-advisories/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"},{"title":"Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks","link":"https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html","source":"The Hacker News","date_rel":"17 Sep"}]},{"title":"TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories","link":"https://cybersecuritynews.com/tanstack-supply-chain-attack/","reason":"Github","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee\u2019s account was compromised through May\u2019s TanStack npm supply chain attack. The May 22 theft remained undetected\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/TanStack-Supply-Chain-Attack.webp","description":"CrowdSec has disclosed that attackers copied about 170 private GitHub repositories after a former employee\u2019s account was compromised through May\u2019s TanStack npm supply chain attack. The May 22 theft remained undetected until stolen source code appeared on a cybercrime forum on September 16, showing how a poisoned dependency can outlive its infection window and undermine developer identities. Data Leak Claim The incident traces to CVE-2026-45321 , the compromise of TanStack\u2019s Router and Start ecosystem. On May 11, the threat actor chained an unsafe pull_request_target workflow, GitHub Actions\u2026","related":[{"title":"CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories","link":"https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html","source":"The Hacker News","date_rel":"9h ago"},{"title":"Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2","link":"https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer","link":"https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/","source":"Bleeping Computer","date_rel":"18 Sep"},{"title":"AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom","link":"https://www.theregister.com/security/2026/09/17/ai-coding-agents-0-click-rce-flaw-could-hand-attackers-keys-to-the-kingdom/5297335","source":"The Register Security","date_rel":"17 Sep"}]},{"title":"BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers","link":"https://cybersecuritynews.com/bragjack-ai-agent-hijacking/","reason":"Chrome","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A new attack technique dubbed \u201cBragJack\u201d allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing\u2026","source":"Cyber Security News","date_rel":"13h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/BragJack-Attack.webp","description":"A new attack technique dubbed \u201cBragJack\u201d allows a malicious browser extension to seize trusted communication channels used by AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. Rather than bypassing model guardrails or hiding instructions inside web content, the proof-of-concept attacks directly supplied commands to privileged browser components, turning an assistant into a tool for theft and unauthorized actions. Forever Security researcher Gal Weizman demonstrated the technique across all five Chromium-based environments using one extension with browser-specific rules\u2026","related":[{"title":"BragJack attacks hijack AI browser agents through malicious extensions","link":"https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage","link":"https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html","source":"The Hacker News","date_rel":"18 Sep"}]},{"title":"Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges","link":"https://cybersecuritynews.com/microsoft-azure-ai-foundry-vulnerability/","reason":"Azure","category":"News","sources":["Cyber Security News","Microsoft Security","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-68791","CVE-2026-69399","CVE-2026-70009"],"summary":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to\u2026","source":"Cyber Security News","date_rel":"18 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Azure-AI-Foundry-Vulnerability.webp","description":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to escalate privileges over the network without any user interaction. Tracked as CVE-2026-85889 , the vulnerability carries the highest possible CVSS score of 10.0, placing it among the most severe cloud security issues disclosed this year. According to Microsoft\u2019s advisory, published on September 17, 2026, the root cause is a missing authentication check for a critical function\u2026","related":[{"title":"Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation","link":"https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html","source":"The Hacker News","date_rel":"18 Sep"},{"title":"Microsoft Patches 18 Vulnerabilities in AI, Cloud Products","link":"https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/","source":"SecurityWeek","date_rel":"18 Sep"},{"title":"CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009","source":"Microsoft Security","date_rel":"17 Sep"},{"title":"CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69399","source":"Microsoft Security","date_rel":"17 Sep"},{"title":"CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791","source":"Microsoft Security","date_rel":"17 Sep"}]},{"title":"Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root","link":"https://thehackernews.com/2026/09/critical-check-point-management-server.html","reason":"Check Point","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is\u2026","source":"The Hacker News","date_rel":"17 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuFSb4LQQ7e_Iz1RS0JfQEDY9G9LcQZ23RM0h6ladr56GJ6nN3kPwVoZPpNVJUyJEBmLVEyMaIxytF2XqyQs8fGjIdd_ymPjwaZA8Q8R7JiXC-srMFj0_YBd-a94juv46HZm4ie72j7PTj45veyTgOBaeuN53HvktSH3JTgasvV_Mo-RwjsTPnRLlHFVk/s1600/cp-main.jpg","description":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw","related":[{"title":"New Check Point flaw lets hackers execute code with root privileges","link":"https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/","source":"Bleeping Computer","date_rel":"18 Sep"},{"title":"Check Point, Kaspersky, Tanium Patch Product Vulnerabilities","link":"https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/","source":"SecurityWeek","date_rel":"18 Sep"},{"title":"Check Point security advisory (AV26-933)","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-933","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"}]},{"title":"Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link","link":"https://cybersecuritynews.com/click2shell-wordpress-vulnerability/","reason":"Wordpress","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins\u2026","source":"Cyber Security News","date_rel":"11h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Click2Shell-WordPress-Vulnerability.webp","description":"WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into remote code execution (RCE) on a vulnerable website. The issue begins with a WordPress Core theme-preview weakness that silently installs an attacker-selected theme from the official directory, then becomes a server compromise when chained with insecure pre-activation code in a theme. WordPress addressed the Core flaw in version 7.1.1 , released September 17, 2026, as part of an update containing 11 security fixes, 17 Core bug fixes, and 19 Block\u2026","related":[{"title":"New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution","link":"https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html","source":"The Hacker News","date_rel":"23h ago"},{"title":"In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw","link":"https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/","source":"SecurityWeek","date_rel":"18 Sep"}]},{"title":"SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html","reason":"Solarwinds","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXW-SaTg898BaxxlrDjSCrcm6ZYDgxoeuYCBY4QNWs6Nt5RhyphenhyphenCf4iSIyodz-7jk8rTqUT8hjlMT74dIf6ZjL_pD5NmiNbAHhsZwzw2rakJUDaU1tVeEvKw7Az3tMf34Xwh3ffToJeI1tpTQ8rAR8AvVn2XTupFgfhehb9sHClHDDGeDd4Y9z4oUf5CYPoS/s1600/solar.jpg","description":"SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. \"SolarWinds","related":[{"title":"SolarWinds security advisory (AV26-941)","link":"https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-941","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]}],"worth_reading":[{"title":"ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-718/","reason":"Cisco","category":"Research","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a\u2026","source":"Zero Day Initiative","date_rel":"18 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.","related":[{"title":"ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-717/","source":"Zero Day Initiative","date_rel":"18 Sep"},{"title":"ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-716/","source":"Zero Day Initiative","date_rel":"18 Sep"},{"title":"Cisco security advisory (AV26-932)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-932","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"},{"title":"Cisco Warns of Active Exploitation of Critical ISE Flaw","link":"https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/","source":"Infosecurity Magazine","date_rel":"17 Sep"}]},{"title":"Exploring the new AWS Sign Up experience","link":"https://www.wiz.io/blog/exploring-the-new-aws-sign-up-experience","reason":"Aws","category":"Research","sources":["Palo Alto Unit 42","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.","source":"Wiz Research","date_rel":"17 Sep","thumbnail":"https://www.datocms-assets.com/75231/1789596868-starter-home-2x.png","description":"","related":[{"title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","link":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","source":"Palo Alto Unit 42","date_rel":"18 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-93603","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver \u2014 e.g. \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93603"},{"id":"CVE-2026-93605","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary comma\u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93605"},{"id":"CVE-2026-93606","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCa\u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93606"},{"id":"CVE-2025-15399","vendor":"IBM","product":"Common Licensing","severity":"CRITICAL","score":10.0,"description":"IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a u\u2026","cwe":"CWE-352","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-15399"},{"id":"CVE-2026-10747","vendor":"IBM","product":"MQ Appliance","severity":"CRITICAL","score":10.0,"description":"IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-10747"},{"id":"CVE-2026-93740","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":10.0,"description":"A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93740"},{"id":"CVE-2026-93741","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":10.0,"description":"A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buffer overflow. It is\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93741"},{"id":"CVE-2025-53837","vendor":"xwiki","product":"xwiki-rendering","severity":"CRITICAL","score":9.9,"description":"XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or a\u2026","cwe":"CWE-95","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2025-53837"},{"id":"CVE-2026-10858","vendor":"IBM","product":"MQ for HPE NonStop","severity":"CRITICAL","score":9.9,"description":"IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-10858"},{"id":"CVE-2026-61682","vendor":"Kubernetes","product":"kcp","severity":"CRITICAL","score":9.9,"description":"kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* iden\u2026","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-61682"}],"vendor_spikes":[{"vendor":"IBM","count":90,"critical_count":16},{"vendor":"WordPress","count":77,"critical_count":3},{"vendor":"Red Hat","count":39,"critical_count":1},{"vendor":"OISF","count":16,"critical_count":0},{"vendor":"Unknown","count":10,"critical_count":1},{"vendor":"Microsoft","count":10,"critical_count":1},{"vendor":"AcademySoftwareFoundation","count":10,"critical_count":0},{"vendor":"strukturag","count":8,"critical_count":1},{"vendor":"MongoDB Inc.","count":8,"critical_count":2},{"vendor":"HashiCorp","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":461,"has_news_data":true,"has_cve_data":true}