{"date_iso":"2026-09-22","date_human":"Tuesday, September 22, 2026","generated_utc":"2026-09-22 17:37 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past","link":"https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320","reason":"Microsoft","category":"News","sources":["Any.Run Malware Analysis","Bleeping Computer","Cyber Security News","CyberScoop","Google Project Zero","SANS Internet Storm Center","SecurityWeek","The Hacker News","The Record","The Register Security"],"coverage":10,"cve_ids":["CVE-2026-32996","CVE-2026-50343","CVE-2026-66804"],"summary":"Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri\u2026","source":"The Register Security","date_rel":"1h ago","thumbnail":"https://image.theregister.com/?imageId=5295963&width=800","description":"Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri, released a proof-of-concept dubbed \u201cBigDiskBuster\u201d that is designed to prevent Microsoft Defender Antivirus from installing platform and security intelligence updates. \u201cMade a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background,\u201d NightmareEclipse said. The researcher describes BigDiskBuster as\u2026","related":[{"title":"Two arrested in UK after Microsoft takedown of \u2018Eviltokens\u2019 AI-chatbot for cybercriminals","link":"https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens","source":"The Record","date_rel":"1h ago"},{"title":"UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites","link":"https://www.theregister.com/security/2026/09/22/uk-cops-arrest-2-eviltokens-suspects-microsoft-seizes-50-phishing-kit-websites/5298317","source":"The Register Security","date_rel":"2h ago"},{"title":"EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts","link":"https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud","link":"https://cyberscoop.com/microsoft-eviltokens-cybercrime-service-takedown/","source":"CyberScoop","date_rel":"2h ago"},{"title":"Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges","link":"https://cybersecuritynews.com/microsoft-sharepoint-rce-flaw/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity","link":"https://www.securityweek.com/nightmare-eclipse-drops-new-microsoft-defender-exploit-after-revealing-identity/","source":"SecurityWeek","date_rel":"4h ago"}]},{"title":"EU data regulator fines Google more than $460 million for location data violations","link":"https://therecord.media/google-europe-location-data-fine","reason":"Google","category":"News","sources":["Ars Technica Security","Bleeping Computer","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Record"],"coverage":7,"cve_ids":[],"summary":"Ireland\u2019s Data Protection Commission will fine Google more than \u20ac403 million ($462 million) over the tech giant\u2019s processing of location data, concluding an inquiry into the company that began in early 2020.","source":"The Record","date_rel":"22h ago","thumbnail":"http://cms.therecord.media/uploads/Google_HQ_8fcdbb2613.jpg","description":"","related":[{"title":"Google Hit With $463 Million Fine for EU Location Data Rule Breach","link":"https://www.securityweek.com/google-hit-with-463-million-fine-for-eu-location-data-rule-breach/","source":"SecurityWeek","date_rel":"21 Sep"},{"title":"Google Fined \u20ac403 Million Over GDPR Violations Tied to Location Data","link":"https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html","source":"The Hacker News","date_rel":"21 Sep"},{"title":"Google fined \u20ac403 million over location data privacy violations","link":"https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/","source":"Bleeping Computer","date_rel":"21 Sep"},{"title":"Google Hit with \u20ac403m GDPR Fine Over Location Data Practices","link":"https://www.infosecurity-magazine.com/news/google-hit-with-403m-gdpr-fine/","source":"Infosecurity Magazine","date_rel":"21 Sep"},{"title":"Gemini\u2019s breach of real companies exposes an AI guardrail problem","link":"https://www.malwarebytes.com/blog/ai/2026/09/geminis-breach-of-real-companies-exposes-an-ai-guardrail-problem","source":"Malwarebytes Labs","date_rel":"21 Sep"},{"title":"An undercover Google analyst infiltrated a notorious supply-chain hacking gang","link":"https://arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/","source":"Ars Technica Security","date_rel":"20 Sep"}]},{"title":"CAIRN \u2013 A New Tool to Track AI Malware That Operates Without Human Control","link":"https://cybersecuritynews.com/cairn-tool-for-tracking-ai-malware/","reason":"Cisco","category":"News","sources":["Cyber Security News","The Hacker News","Wired Security"],"coverage":3,"cve_ids":[],"summary":"Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CAIRN-Tool-for-Tracking-AI-Malware.webp","description":"Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research Network searches for prompt templates, provider endpoints, API-key prefixes, jailbreak terms, and orchestration logic without downloading or executing binaries. The launch also revealed CLOSEDQUORUM, which Talos describes as the first publicly documented Windows implant to delegate tactical command-and-control decisions to artificial intelligence. Instead of awaiting\u2026","related":[{"title":"A New Tool Found Malware That\u2019s Guided by an AI Hive Mind\u2014No Humans in Sight","link":"https://www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/","source":"Wired Security","date_rel":"7h ago"},{"title":"\u26a1 Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks","link":"https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html","source":"The Hacker News","date_rel":"21 Sep"}]},{"title":"AI Agents Are Rewriting the Rules of Lateral Movement","link":"https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html","reason":"Teams","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9ivhHLwWwT7Ptbr537Fd2CV3d_maDSNRmH0up0x67UPpc5x45Uuz0Bg8EnLkjrtB3DYXldW7aKbzx5uljQSF7IhQlzHHA1HR0F16Eaxs8Y3tgURkizSrA79L3EqyD5RDlqPGljbXCTQj0tFFG2EOVueksvhyrmdmC-v6VFjs76KdzZlCg1juWiVOPDnU/s1600/token.jpg","description":"Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May","related":[{"title":"Reducing shadow IT visibility gaps with Wazuh","link":"https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/","source":"Bleeping Computer","date_rel":"18m ago"},{"title":"AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds","link":"https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/","source":"Infosecurity Magazine","date_rel":"4h ago"},{"title":"FBI's CJIS v6.1: What Security Teams Need to Know","link":"https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/","source":"Bleeping Computer","date_rel":"21 Sep"}]},{"title":"Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access","link":"https://cybersecuritynews.com/linux-kvm-arm64-vulnerability/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-89775"],"summary":"A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Linux-KVMarm64-Vulnerability-Lets-Attackers-Escape-Virtual-Machines-and-Gain-Host-Access.webp","description":"A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested virtualization is enabled, creating a serious risk for multi-tenant cloud infrastructure and systems that allow untrusted users to create virtual machines. Security researcher Hyunwoo Kim reported that the flaw stems from a type truncation issue in the KVM/arm64 stage-1 page-table walk process. The bug affects how the kernel calculates the size of a memory region it must\u2026","related":[{"title":"BambooToken Linux Backdoor Uses MQTT C2 to Execute Shell Commands and Exfiltrate Files","link":"https://cybersecuritynews.com/bambootoken-linux-backdoor/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory","link":"https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"CISA alerts of active exploitation of three Linux kernel flaws","link":"https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/","source":"Bleeping Computer","date_rel":"21h ago"}]},{"title":"WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session","link":"https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server\u2026","source":"The Hacker News","date_rel":"11h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPBWV1XNsTGB5ImLNRGJTygk0-82k7xTHmuOr7lTivRRDcF83ddu4jLOpdkQYMq7VB3j5SMpA9zBRvM3-SUkDLBhN5-j-Z6UltcTnVfXOxHDzfBYWiw_fRiRefAYa1XSiFu5JMzb06dwqV4PhKaZkPt3vKZFHQjdVFUgbr2B3nOEoFs_qHe6zwGayHM2I/s1600/wordpress-comment.jpg","description":"A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and called \"Comment2Shell,\" on September 17 in version 7.1.1 and told site owners to update right away. There is","related":[{"title":"WordPress Patches \u2018Click2Shell\u2019 Vulnerability","link":"https://www.securityweek.com/wordpress-patches-click2shell-vulnerability/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"WordPress Click2Shell flaw lets hackers execute PHP on the server","link":"https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/","source":"Bleeping Computer","date_rel":"23h ago"}]},{"title":"Check Point warns of Management Server zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/","reason":"Check Point","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":[],"summary":"Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.","source":"Bleeping Computer","date_rel":"1h ago","thumbnail":"","description":"","related":[{"title":"Check Point security advisory (AV26-902) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902","source":"CCCS Alerts & Advisories","date_rel":"2h ago"}]},{"title":"New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords","link":"https://cybersecuritynews.com/new-taskstomp-backdoor/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-40400","CVE-2026-68825","CVE-2026-83498"],"summary":"TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-TASK-STOMP-Backdoor-Uses-PowerShell-to-Steal-Documents-and-Wi-Fi-Passwords.webp","description":"TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code compilation to collect business documents, saved Wi-Fi passwords, clipboard data, and screenshots from compromised machines. The observed infection begins with a randomly named VBS file in a user-accessible location. Its delivery route remains unconfirmed: the available evidence cannot distinguish phishing, a browser download, removable media, remote access, or an extracted archive\u2026","related":[{"title":"CVE-2026-68825 Windows Bind Filter Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68825","source":"Microsoft Security","date_rel":"21 Sep"},{"title":"CVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83498","source":"Microsoft Security","date_rel":"21 Sep"},{"title":"CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400","source":"Microsoft Security","date_rel":"21 Sep"}]},{"title":"Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits","link":"https://cybersecuritynews.com/hackers-clone-legitimate-websites/","reason":"Chrome","category":"News","sources":["Cyber Security News","Volexity"],"coverage":2,"cve_ids":["CVE-2026-85046","CVE-2026-85880","CVE-2026-87491"],"summary":"Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Clone-Legitimate-Websites-to-Silently-Trigger-Chrome-and-Windows-Zero-Day-Exploits.webp","description":"Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in Google Chrome and Microsoft Windows, giving attackers a quiet path from a fake page to malware on a victim\u2019s device. The activity was recorded on September 3 and 4, before the affected flaws were patched. It targeted Asian government entities with a Chinese-language message about jailed Hong Kong activist Chow Hang-tung, while another lure impersonated the Center for American\u2026","related":[{"title":"Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits","link":"https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/","source":"Volexity","date_rel":"20h ago"}]},{"title":"Siemens Industrial Edge Management","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06","reason":"Siemens","category":"Advisory","sources":["CISA Alerts & Advisories","CISA ICS Advisories"],"coverage":2,"cve_ids":[],"summary":"View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without\u2026","source":"CISA Alerts & Advisories","date_rel":"5h ago","thumbnail":"","description":"View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Industrial Edge Management are affected: Industrial Edge Management Cloud vers:all/* (CVE-2026-18963) Industrial Edge Management Pro V1 vers:intdot/>=1.14.9|<1.15.20 (CVE-2026-18963) Industrial Edge Management\u2026","related":[{"title":"Siemens WTV676 and WTV776","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"Siemens SIPLUS and SIMATIC Products","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-04","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"Siemens WTV676 and WTV776","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-08","source":"CISA ICS Advisories","date_rel":"5h ago"},{"title":"Siemens SIMOVE Fleetmanager and SIPLANT","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-07","source":"CISA ICS Advisories","date_rel":"5h ago"},{"title":"Siemens Industrial Edge Management","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-06","source":"CISA ICS Advisories","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-77521","vendor":"1Panel-dev","product":"MaxKB","severity":"CRITICAL","score":10.0,"description":"MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execut\u2026","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77521"},{"id":"CVE-2026-94493","vendor":"Gigatech","product":"PDV5701","severity":"CRITICAL","score":10.0,"description":"A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94493"},{"id":"CVE-2026-93952","vendor":"Arista Networks","product":"VeloCloud Orchestrator (VCO) On-Prem","severity":"CRITICAL","score":10.0,"description":"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit\u2026","cwe":"CWE-20","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93952"},{"id":"CVE-2026-79920","vendor":"ajenti","product":"ajenti","severity":"CRITICAL","score":9.9,"description":"Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-managem\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-79920"},{"id":"CVE-2026-94301","vendor":"Apache","product":"Apache MINA","severity":"CRITICAL","score":9.8,"description":"The fix for CVE-2026-47065/ZDRES-232 (\"resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\"), released on 2026-06-02 and announced as \"Fully addressed\" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed \u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94301"},{"id":"CVE-2026-85751","vendor":"F5","product":"Mailu","severity":"CRITICAL","score":9.8,"description":"Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forw\u2026","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85751"},{"id":"CVE-2026-13355","vendor":"WordPress","product":"Meta Box Frontend Submission","severity":"CRITICAL","score":9.8,"description":"The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission com\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-13355"},{"id":"CVE-2026-19658","vendor":"WordPress","product":"Give Tributes","severity":"CRITICAL","score":9.8,"description":"The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. N\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19658"},{"id":"CVE-2026-25254","vendor":"Qualcomm","product":"Snapdragon","severity":"CRITICAL","score":9.8,"description":"Improper authorization leads to Remote Code Execution via SocketIO interface.","cwe":"CWE-285","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-25254"},{"id":"CVE-2026-58491","vendor":"Oracle","product":"warpgate","severity":"CRITICAL","score":9.3,"description":"Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inse\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58491"}],"vendor_spikes":[{"vendor":"Unknown","count":43,"critical_count":0},{"vendor":"WordPress","count":33,"critical_count":2},{"vendor":"Microsoft","count":30,"critical_count":0},{"vendor":"Red Hat","count":12,"critical_count":0},{"vendor":"MISP","count":10,"critical_count":0},{"vendor":"1Panel-dev","count":10,"critical_count":2},{"vendor":"Oracle","count":9,"critical_count":1},{"vendor":"Apache","count":9,"critical_count":2},{"vendor":"jishenghua","count":9,"critical_count":0},{"vendor":"laurent22","count":9,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":313,"has_news_data":true,"has_cve_data":true}