{"date_iso":"2026-09-23","date_human":"Wednesday, September 23, 2026","generated_utc":"2026-09-23 17:49 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"OAuth Token Theft Through Microsoft's Front Door | Huntress","link":"https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door","reason":"Microsoft","category":"Threat Intel","sources":["Any.Run Malware Analysis","Bleeping Computer","CyberScoop","Dark Reading","Google Project Zero","Huntress","SANS Internet Storm Center","SecurityWeek","The Hacker News","The Register Security"],"coverage":10,"cve_ids":["CVE-2026-50343","CVE-2026-66804"],"summary":"A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.","source":"Huntress","date_rel":"4h ago","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2F35b3adb09b9a44a1acdeffc954aee0aa","description":"","related":[{"title":"AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft","link":"https://www.securityweek.com/ai-powered-phishing-platform-eviltokens-disrupted-by-microsoft/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Microsoft: September Windows updates break Always On VPN connections","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/","source":"Bleeping Computer","date_rel":"6h ago"},{"title":"Microsoft Disrupts EvilTokens Device Code Phishing Service","link":"https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service","source":"Dark Reading","date_rel":"21h ago"},{"title":"Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises","link":"https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html","source":"The Hacker News","date_rel":"22 Sep"},{"title":"NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past","link":"https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320","source":"The Register Security","date_rel":"22 Sep"},{"title":"EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts","link":"https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/","source":"Bleeping Computer","date_rel":"22 Sep"}]},{"title":"Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign","link":"https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign","reason":"Google","category":"News","sources":["Bleeping Computer","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","Risky Business","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.","source":"Dark Reading","date_rel":"3h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdc4ade55d77fb4ff/6ab3b76557365fe244f410ae/chatbot_khunkornStudio_shutterstock.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"How One Kubernetes YAML Can Hand Over a GCP Organization","link":"https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Fake Claude Max giveaway hides a Google account phishing trap","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"Risky Business #854 -- We're Jevpilled","link":"https://risky.biz/RB854/","source":"Risky Business","date_rel":"11h ago"},{"title":"Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions","link":"https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435","source":"The Register Security","date_rel":"20h ago"},{"title":"New ClosedQuorum Windows malware uses AI for attack decisions","link":"https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Google Fined \u20ac403 Million Over GDPR Violations Tied to Location Data","link":"https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html","source":"The Hacker News","date_rel":"21 Sep"}]},{"title":"How dynamic application security testing validates risk at runtime","link":"https://www.rapid7.com/blog/post/em-dynamic-application-security-testing-dast-validates-risk-at-runtime-idc-marketscape","reason":"Teams","category":"Research","sources":["Bleeping Computer","Infosecurity Magazine","Microsoft Security Blog","Rapid7 Blog","SecurityWeek","The Hacker News"],"coverage":6,"cve_ids":[],"summary":"Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give\u2026","source":"Rapid7 Blog","date_rel":"3h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt6de5ce916fee1306/67e1ab62a352dfa88a696f5f/IDC-report.jpg","description":"Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader. We believe the result\u2026","related":[{"title":"Reimagining the SOC for the agentic era in Microsoft Defender","link":"https://www.microsoft.com/en-us/security/blog/2026/09/23/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender/","source":"Microsoft Security Blog","date_rel":"1h ago"},{"title":"Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare","link":"https://www.securityweek.com/honeywell-ot-security-teams-embrace-ai-but-autonomy-still-rare/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Reducing shadow IT visibility gaps with Wazuh","link":"https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/","source":"Bleeping Computer","date_rel":"22 Sep"},{"title":"AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds","link":"https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/","source":"Infosecurity Magazine","date_rel":"22 Sep"},{"title":"AI Agents Are Rewriting the Rules of Lateral Movement","link":"https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html","source":"The Hacker News","date_rel":"22 Sep"}]},{"title":"Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks","link":"https://thehackernews.com/2026/09/check-point-warns-of-management-server.html","reason":"Check Point","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","CISA Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-85102","CVE-2026-93616"],"summary":"Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipTjrp93lIMdPVKigtkoXjbsk75AIXEvqJuXoYMQLAmvzQfqSy3V1XhBTLXY1SAWp92vTbajtnxBgHYvDr2e3EZOi9Yf8KgT8EzQOp61PjmPsI55nERsYckaL-pfmQDDzRTiCWXegVWrJ0Fu_9I8GUi5O0M0103r218S3dC67Zmr9BZ3quLBRBm9T6Xqo/s1600/cp-upload.jpg","description":"Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point","related":[{"title":"Check Point Patches Exploited Management Server Zero-Day","link":"https://www.securityweek.com/check-point-patches-exploited-management-server-zero-day/","source":"SecurityWeek","date_rel":"11h ago"},{"title":"Check Point security advisory (AV26-902) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Check Point warns of Management Server zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"22 Sep"},{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/22/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"22 Sep"}]},{"title":"Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware","link":"https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html","reason":"Chrome","category":"News","sources":["CyberScoop","SecurityWeek","The Hacker News","Volexity"],"coverage":4,"cve_ids":["CVE-2026-85046","CVE-2026-85880","CVE-2026-87491"],"summary":"A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikVEmuPJKZAlboodZWejG4dGZXXejOLThyXPoOnycqTY8lznAewTW5ovv8XFJzhyjPRMXT-njudYOVWFEYCLvmEPDyUrfDTZzAmp1S4KE4DuzsDFxt8R-biL2puZZBWG36_dkhfzvpeigcPb9WJNy31oIXo6Oh3zMUzL3JG6MEr4OaGE4Yi_k5JCpohVrZ/s1600/windows-china.jpg","description":"A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break","related":[{"title":"Chrome 154 Patches 108 Vulnerabilities","link":"https://www.securityweek.com/chrome-154-patches-108-vulnerabilities/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects","link":"https://cyberscoop.com/volexity-uta0565-china-exploit-chain-chrome-microsoft/","source":"CyberScoop","date_rel":"23h ago"},{"title":"Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits","link":"https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/","source":"Volexity","date_rel":"21 Sep"}]},{"title":"This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move","link":"https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html","reason":"Cisco","category":"News","sources":["The Hacker News","Wired Security","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZdSpi6aqUlY2q-T-3eJ4YCn7G3jYa9Exo6BMffjdRLuqg9Gdn4ImZXKjcYX8s5Swz3W_WhxMZ_Z7qbu0Z60KrCk8EUhRV8bJ7l1mXOoDCo-XAXyq69_rtFDoVhvAiuJP1rCdSf9KixTqgAA52iwqWsqB5T0uJaRGFz1hpBcpfQuvPMYd17UcrfrnUV0c/s1600/closed.jpg","description":"A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.","related":[{"title":"A New Tool Found Malware That\u2019s Guided by an AI Hive Mind\u2014No Humans in Sight","link":"https://www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/","source":"Wired Security","date_rel":"22 Sep"},{"title":"ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-719/","source":"Zero Day Initiative","date_rel":"22 Sep"},{"title":"\u26a1 Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks","link":"https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html","source":"The Hacker News","date_rel":"21 Sep"}]},{"title":"WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers","link":"https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcFso-nJC2Re_gThOMTjPhyphenhyphenaOti1Mpn2_nb6NYGitzjVHTtvHN_q4oKg_FGa4IrTt81BAuA4qWzeJJZkxdV7F0-iSBR3ZwSUmqfBhvBX2ArxLTZqYjbtCPhu2Gw7PLSmOS5kOGQ9f0I46xPwhp5VCflFSN8YEm-z8VXdk1XRJwCvbqbljSZqorD4MpbQc/s1600/wp-update.jpg","description":"WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners","related":[{"title":"WordPress security advisory (AV26-952)","link":"https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952","source":"CCCS Alerts & Advisories","date_rel":"2h ago"},{"title":"Chinese hackers exploit WordPress, Zyxel flaws to steal govt data","link":"https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session","link":"https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html","source":"The Hacker News","date_rel":"22 Sep"}]},{"title":"CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM","link":"https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm","reason":"CVE-2026-94127","category":"Research","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-94127"],"summary":"Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS\u2026","source":"Rapid7 Blog","date_rel":"9h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic. BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML\u2026","related":[{"title":"F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers","link":"https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html","source":"The Hacker News","date_rel":"9h ago"},{"title":"AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) \u2013 CVE-2026-94127","link":"https://cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates","link":"https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html","reason":"Github","category":"News","sources":["Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster\u2026","source":"The Hacker News","date_rel":"22 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf-fkqiHh6b0UEKMHUcsG54QVwJxghIbQLMNWeEG5LWKfUsicLMxisz4Mi8lXdfTdwVYDFpIrCFj5D7-JXXynq8lWhnNn1rJH2t8mgKUeZ4WMePwZktZRnIe2549JW3VXc2HYD9qpsvO8He0J0zCyAzsaRxWtiP46RSrd7jt4QnzKACJhfWnkmyWcFcQs/s1600/ms-def.jpg","description":"A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in","related":[{"title":"Hundreds of Leaked GitHub App Keys Still Authenticate","link":"https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data","link":"https://www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data","source":"Dark Reading","date_rel":"22 Sep"},{"title":"Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR","link":"https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html","source":"The Hacker News","date_rel":"21 Sep"}]},{"title":"Critical F5 BIG-IP Vulnerability Exploited as Zero-Day","link":"https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/","reason":"F5","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","SecurityWeek"],"coverage":3,"cve_ids":[],"summary":"Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.","source":"SecurityWeek","date_rel":"10h ago","thumbnail":"","description":"","related":[{"title":"F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks","link":"https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"10h ago"},{"title":"F5 security advisory (AV26-949) - Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-949","source":"CCCS Alerts & Advisories","date_rel":"21h ago"}]}],"worth_reading":[{"title":"Meta\u2019s Muse AI Assistant Rolled Out With a Serious Security Flaw","link":"https://www.wired.com/story/metas-muse-ai-agent-zero-day/","reason":"Assistant Serious Metas","category":"Media","sources":["Ars Technica Security","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do \u201cwhatever\u201d they wanted on a victim\u2019s Mac, highlighting the inherent dangers of AI helpers.","source":"Wired Security","date_rel":"4h ago","thumbnail":"https://media.wired.com/photos/6ab2cd9fca426ab5b46f084b/master/pass/Security_Meta%E2%80%99s%20Muse%20AI%20Agent%20Has%20a%20Serious%20Security%20Flaw_v1.jpg","description":"","related":[{"title":"Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day","link":"https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/","source":"Ars Technica Security","date_rel":"21 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-80155","vendor":"LANTRONIX","product":"SLC8000","severity":"CRITICAL","score":10.0,"description":"Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allow\u2026","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-80155"},{"id":"CVE-2026-73369","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73369"},{"id":"CVE-2026-75699","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75699"},{"id":"CVE-2026-75703","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75703"},{"id":"CVE-2026-75721","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75721"},{"id":"CVE-2026-75723","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. E\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75723"},{"id":"CVE-2026-77244","vendor":"Atlassian","product":"mcp-atlassian","severity":"CRITICAL","score":10.0,"description":"MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77244"},{"id":"CVE-2026-84412","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84412"},{"id":"CVE-2026-89275","vendor":"Adobe","product":"Adobe Campaign Classic","severity":"CRITICAL","score":10.0,"description":"Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerab\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89275"},{"id":"CVE-2026-75745","vendor":"Adobe","product":"AEM 6.5 Forms JEE","severity":"CRITICAL","score":10.0,"description":"Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary c\u2026","cwe":"CWE-863","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75745"}],"vendor_spikes":[{"vendor":"Adobe","count":54,"critical_count":25},{"vendor":"WordPress","count":53,"critical_count":0},{"vendor":"IBM","count":44,"critical_count":7},{"vendor":"Atlassian","count":30,"critical_count":3},{"vendor":"Foxit Software Inc.","count":29,"critical_count":0},{"vendor":"Unknown","count":24,"critical_count":1},{"vendor":"Microsoft","count":19,"critical_count":1},{"vendor":"NVIDIA","count":19,"critical_count":1},{"vendor":"MISP","count":17,"critical_count":0},{"vendor":"Apache","count":13,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":18,"new_cve_count":516,"has_news_data":true,"has_cve_data":true}