{"date_iso":"2026-09-24","date_human":"Thursday, September 24, 2026","generated_utc":"2026-09-24 17:50 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Managed or Modified: Choose How Huntress Hardens Microsoft 365","link":"https://www.huntress.com/blog/managed-or-modified-choose-how-huntress-hardens-microsoft-365","reason":"Microsoft","category":"Threat Intel","sources":["Any.Run Malware Analysis","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Dark Reading","Huntress","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":9,"cve_ids":["CVE-2026-65660"],"summary":"Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.","source":"Huntress","date_rel":"3h ago","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2Fbe73542cbcce49839e9e3b2c9d1f2720","description":"","related":[{"title":"AL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660","link":"https://cyber.gc.ca/en/alerts-advisories/al26-023-vulnerability-impacting-microsoft-sharepoint-server-cve-2026-65660","source":"CCCS Alerts & Advisories","date_rel":"36m ago"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"3h ago"},{"title":"Windows 11 KB5124010 update released with 46 changes and fixes","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Microsoft Rebuilds the SOC with AI Agents, SIEM Integration and Machine-Speed Defense","link":"https://cybersecuritynews.com/microsoft-rebuilds-the-soc/","source":"Cyber Security News","date_rel":"6h ago"},{"title":"Over 75% of Organizations Experience Microsoft 365 Governance Issues","link":"https://www.infosecurity-magazine.com/news/75-organizations-microsoft-365/","source":"Infosecurity Magazine","date_rel":"8h ago"},{"title":"Microsoft fixes bug that broke Windows File History backup feature","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/","source":"Bleeping Computer","date_rel":"9h ago"}]},{"title":"Google to critical infra orgs: Our AI scanners won't be evil, promise","link":"https://www.theregister.com/security/2026/09/24/google-to-critical-infra-orgs-our-ai-scanners-wont-be-evil-promise/5298685","reason":"Google","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Malwarebytes Labs","Risky Business","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a\u2026","source":"The Register Security","date_rel":"4h ago","thumbnail":"https://image.theregister.com/?imageId=5298699&width=800","description":"Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a municipality, a public rail operator, and major technology providers. So don't fear these bots. The initiative, announced on Thursday, uses Google\u2019s Gemini 3.8 Flash Cyber, a version of the model tuned for software bug hunting and remediation, and Wiz\u2019s Red Agent - this is the Google-owned cloud security shop\u2019s pentesting AI agent. The AI systems will uncover public exposures and\u2026","related":[{"title":"Google\u2019s location data privacy failures draw a \u20ac403 million fine","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine","source":"Malwarebytes Labs","date_rel":"9h ago"},{"title":"Malicious Firefox Extension Disguised as PDF Tool Steals Google Account Sessions","link":"https://cybersecuritynews.com/malicious-firefox-extension/","source":"Cyber Security News","date_rel":"10h ago"},{"title":"Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign","link":"https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign","source":"Dark Reading","date_rel":"23 Sep"},{"title":"How One Kubernetes YAML Can Hand Over a GCP Organization","link":"https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/","source":"Bleeping Computer","date_rel":"23 Sep"},{"title":"Fake Claude Max giveaway hides a Google account phishing trap","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap","source":"Malwarebytes Labs","date_rel":"23 Sep"},{"title":"Risky Business #854 -- We're Jevpilled","link":"https://risky.biz/RB854/","source":"Risky Business","date_rel":"23 Sep"}]},{"title":"Decades-old file security flaws found in Android, Linux, macOS, and Windows","link":"https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672","reason":"Android","category":"News","sources":["Bleeping Computer","Cyber Security News","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Security researchers affiliated with Austria's Graz University of Technology have found flaws in the implementation of file notification systems on Android, Linux, macOS, and Windows that leak potentially compromising\u2026","source":"The Register Security","date_rel":"49m ago","thumbnail":"https://image.theregister.com/?imageId=5298676&width=800","description":"Security researchers affiliated with Austria's Graz University of Technology have found flaws in the implementation of file notification systems on Android, Linux, macOS, and Windows that leak potentially compromising system information. \"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change,\" said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to The Register. Affected systems include inotify on Linux since 2005, FileObserver on Android since 2008\u2026","related":[{"title":"Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls","link":"https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"Update Chrome: 108 security fixes for desktop, new release for Android","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-108-security-fixes-for-desktop-new-release-for-android","source":"Malwarebytes Labs","date_rel":"6h ago"},{"title":"New Android Banking Trojan Uses AI-Built Overlays to Steal Users\u2019 Banking PINs","link":"https://cybersecuritynews.com/android-banking-trojan/","source":"Cyber Security News","date_rel":"7h ago"},{"title":"New RemControl Android banking malware targets users in Europe and Canada","link":"https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/","source":"Bleeping Computer","date_rel":"20h ago"}]},{"title":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content","link":"https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html","reason":"Windows","category":"News","sources":["Cyber Security News","Dark Reading","Infosecurity Magazine","Microsoft Security","The Hacker News"],"coverage":5,"cve_ids":["CVE-2026-69637","CVE-2026-69803","CVE-2026-71337"],"summary":"The \"third-party[.]com\" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. \"third-party[.]com has been a\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ/s1600/third.jpg","description":"The \"third-party[.]com\" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. \"third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\" Manifold Security's Head of Research, Ax Sharma, said. \"Unlike 'example[.]com,' third-party[.]com","related":[{"title":"CVE-2026-71337 Windows Storage Management Provider Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-69637 Windows DHCP Server Denial of Service Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69637","source":"Microsoft Security","date_rel":"3h ago"},{"title":"CVE-2026-69803 Windows DHCP Server Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69803","source":"Microsoft Security","date_rel":"3h ago"},{"title":"Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations","link":"https://cybersecuritynews.com/konni-malware-campaign/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"AvisLoader Windows Malware That Learned to Survive Even After Its Servers Are Taken Down","link":"https://cybersecuritynews.com/avisloader-windows-malware/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"EDR Evasion Stack Helps Process Injection Slip Past Defenses","link":"https://www.darkreading.com/endpoint-security/edr-evasion-stack-helps-process-injection-slip-past-defenses","source":"Dark Reading","date_rel":"20h ago"}]},{"title":"Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)","link":"https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/","reason":"CVE-2026-94127","category":"Research","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News","watchTowr Labs"],"coverage":4,"cve_ids":["CVE-2026-94127"],"summary":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas\u2026","source":"watchTowr Labs","date_rel":"18h ago","thumbnail":"https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/2026/09/1.png","description":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it\u2019s a free-for-all (unless you\u2019re trying to buy RAM). Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces\u2026 (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in\u2026","related":[{"title":"CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM","link":"https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm","source":"Rapid7 Blog","date_rel":"23 Sep"},{"title":"F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers","link":"https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html","source":"The Hacker News","date_rel":"23 Sep"},{"title":"AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) \u2013 CVE-2026-94127","link":"https://cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127","source":"CCCS Alerts & Advisories","date_rel":"22 Sep"}]},{"title":"How dynamic application security testing validates risk at runtime","link":"https://www.rapid7.com/blog/post/em-dynamic-application-security-testing-dast-validates-risk-at-runtime-idc-marketscape","reason":"Teams","category":"Research","sources":["Infosecurity Magazine","Microsoft Security Blog","Rapid7 Blog","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give\u2026","source":"Rapid7 Blog","date_rel":"23 Sep","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt6de5ce916fee1306/67e1ab62a352dfa88a696f5f/IDC-report.jpg","description":"Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, September 2026). The IDC MarketScape evaluated 16 vendors and named Rapid7 a Leader. We believe the result\u2026","related":[{"title":"Reimagining the SOC for the agentic era in Microsoft Defender","link":"https://www.microsoft.com/en-us/security/blog/2026/09/23/reimagining-the-soc-for-the-agentic-era-in-microsoft-defender/","source":"Microsoft Security Blog","date_rel":"23 Sep"},{"title":"AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds","link":"https://www.infosecurity-magazine.com/news/orgs-lack-ai-incident-response/","source":"Infosecurity Magazine","date_rel":"22 Sep"},{"title":"AI Agents Are Rewriting the Rules of Lateral Movement","link":"https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html","source":"The Hacker News","date_rel":"22 Sep"}]},{"title":"A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You","link":"https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html","reason":"Gitlab","category":"News","sources":["Bleeping Computer","Dark Reading","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start\u2026","source":"The Hacker News","date_rel":"23 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaHKzSxkk0R4wjlziQHsR5vS1s1mTJovZkES9XL9nn5VLYiM55XuJoiGP9cugwNUOBMEMG3NrW3iBL9cVOqfp0F-9roYS7K7R5w8t3_NJr61_2_XgRNltvjXBFoGLfQPQFhUk0ju_mMCRCqJHjr76BrbngafAtElKkD-LZWZ7uUcY82i8PAMKh0ljHJQI/s1600/gitlab-email.jpg","description":"The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled \"Email work item to this project.\" Mail sent to it opens an issue in that project, authored","related":[{"title":"Exposed GitLab project email addresses let attackers push code","link":"https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/","source":"Bleeping Computer","date_rel":"1m ago"},{"title":"GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks","link":"https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks","source":"Dark Reading","date_rel":"20h ago"}]},{"title":"Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates","link":"https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html","reason":"Github","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster\u2026","source":"The Hacker News","date_rel":"22 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf-fkqiHh6b0UEKMHUcsG54QVwJxghIbQLMNWeEG5LWKfUsicLMxisz4Mi8lXdfTdwVYDFpIrCFj5D7-JXXynq8lWhnNn1rJH2t8mgKUeZ4WMePwZktZRnIe2549JW3VXc2HYD9qpsvO8He0J0zCyAzsaRxWtiP46RSrd7jt4QnzKACJhfWnkmyWcFcQs/s1600/ms-def.jpg","description":"A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in","related":[{"title":"GitHub security advisory (AV26-956)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-956","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Hundreds of Leaked GitHub App Keys Still Authenticate","link":"https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/","source":"Infosecurity Magazine","date_rel":"23 Sep"},{"title":"Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data","link":"https://www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data","source":"Dark Reading","date_rel":"22 Sep"}]},{"title":"Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login","link":"https://cybersecuritynews.com/hackers-exploit-critical-check-point-vpn-flaws/","reason":"Check Point","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-93616"],"summary":"Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution. Both flaws carry\u2026","source":"Cyber Security News","date_rel":"10h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Exploit-Critical-Check-Point-VPN-Flaws-to-Gain-Remote-Access-Without-Login.webp","description":"Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution. Both flaws carry a CVSS severity score of 9.8, and the company has released fixes that affected organizations should apply immediately. The first issue, tracked as CVE-2026-85102, affects Check Point Security Gateway and Spark Firewall deployments that use Remote Access VPN or certificate-based Site-to-Site VPN authentication. The flaw stems from improper validation of certificate data during\u2026","related":[{"title":"Check Point security advisory (AV26-902) \u2013 Update 2","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902","source":"CCCS Alerts & Advisories","date_rel":"22 Sep"},{"title":"Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks","link":"https://thehackernews.com/2026/09/check-point-warns-of-management-server.html","source":"The Hacker News","date_rel":"22 Sep"}]},{"title":"Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure","link":"https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html","reason":"CVE-2026-87902","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-87902"],"summary":"Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an\u2026","source":"The Hacker News","date_rel":"12h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizoRcyQE1N3fGUKa2FY_q_T7EG_CyjTpMGGk1oFUF-XpBZa0zCA6V2yEuv3_Z1OrEjMmhbHdaVmo6NMrwb98U9VFGXDpRcItboVuZH7qc9QgPd5ZLDudfJPWoaSDbtkoXJeLTZw-6JDbq5F6YEp4AkeoJd10Nb_H9tuU0fYdgqkLrP6BTpAPOYwO6WdmkN/s1600/wordpress-exploits.jpg","description":"Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). \"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file","related":[{"title":"Critical WordPress Vulnerability Exploited Immediately After Disclosure","link":"https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/","source":"SecurityWeek","date_rel":"10h ago"},{"title":"Hackers start exploiting critical WordPress flaw for code execution","link":"https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/","source":"Bleeping Computer","date_rel":"23h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-59167","vendor":"JiHong88","product":"suneditor","severity":"CRITICAL","score":10.0,"description":"SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler at\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59167"},{"id":"CVE-2026-86708","vendor":"ManageEngine","product":"ManageEngine Applications Manager","severity":"CRITICAL","score":10.0,"description":"ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersona\u2026","cwe":"CWE-321","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86708"},{"id":"CVE-2026-19599","vendor":"ManageEngine","product":"ManageEngine OpManager","severity":"CRITICAL","score":9.9,"description":"ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19599"},{"id":"CVE-2026-77602","vendor":"OpenC3","product":"cosmos","severity":"CRITICAL","score":9.9,"description":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later ex\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-77602"},{"id":"CVE-2026-84474","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.4 for RHEL 8","severity":"CRITICAL","score":9.9,"description":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. The provisioning-callback secret (host_config_key) is exposed to\nusers holding only the read-level view_jobtemplate permission -- both in the\njob template API\u2026","cwe":"CWE-807","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84474"},{"id":"CVE-2026-84502","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.4 for RHEL 8","severity":"CRITICAL","score":9.9,"description":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. The Project scm_url field is not validated against values that\nbegin with a dash and is stored and passed verbatim to the git SCM module.\nBecause the module r\u2026","cwe":"CWE-88","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84502"},{"id":"CVE-2026-84719","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.4 for RHEL 8","severity":"CRITICAL","score":9.9,"description":"A flaw was found in the Ansible Automation Platform automation-controller. When a\nWorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,\nunified_job_template, and credentials of each cloned node and \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84719"},{"id":"CVE-2026-89078","vendor":"GitLab","product":"GitLab","severity":"CRITICAL","score":9.9,"description":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on th\u2026","cwe":"CWE-415","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89078"},{"id":"CVE-2026-93577","vendor":"GitLab","product":"GitLab","severity":"CRITICAL","score":9.9,"description":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on th\u2026","cwe":"CWE-190","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93577"},{"id":"CVE-2026-76183","vendor":"Apache","product":"Apache Tomcat","severity":"CRITICAL","score":9.8,"description":"Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 1\u2026","cwe":"CWE-289","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76183"}],"vendor_spikes":[{"vendor":"Red Hat","count":50,"critical_count":5},{"vendor":"WordPress","count":37,"critical_count":2},{"vendor":"IBM","count":30,"critical_count":4},{"vendor":"rabbitmq","count":24,"critical_count":0},{"vendor":"ManageEngine","count":18,"critical_count":2},{"vendor":"Apache","count":16,"critical_count":4},{"vendor":"Unknown","count":15,"critical_count":1},{"vendor":"Dell","count":8,"critical_count":0},{"vendor":"Microsoft","count":8,"critical_count":0},{"vendor":"joomshaper.com","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":421,"has_news_data":true,"has_cve_data":true}