{"date_iso":"2026-09-26","date_human":"Saturday, September 26, 2026","generated_utc":"2026-09-26 17:02 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild","link":"https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Huntress","Infosecurity Magazine","The Hacker News"],"coverage":7,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing\u2026","source":"The Hacker News","date_rel":"8h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHEPamtRBBEzltsUWnj-F8umrMf4eUUhTmGUJdhHlrvWZamHWpBtXcrpQKDArTziRiiIWv8psX4DTZyN9kLBtcAyLOPJma9_M7sYKgYz6WBISbOhJrRlfByfCKfTTMdBqaYUp-0nskrt2ndt3poUFLDGegEFJojS0EzEvwAqzaUNtvX26jZopYE4zA4S3K/s1600/share-kev.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint","related":[{"title":"Microsoft pauses KB5002907 update after Office license deactivations","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records","link":"https://cybersecuritynews.com/microsoft-auth-vulnerability-expose-records/","source":"Cyber Security News","date_rel":"13h ago"},{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 4","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"25 Sep"},{"title":"Podcast: OpenAI Admits AI is Killing the Internet","link":"https://www.404media.co/podcast-openai-admits-ai-is-killing-the-internet/","source":"404 Media","date_rel":"25 Sep"},{"title":"Microsoft plans to deprecate Windows Deployment Services","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/","source":"Bleeping Computer","date_rel":"25 Sep"},{"title":"Microsoft: Recent Windows updates cause desktop loading issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/","source":"Bleeping Computer","date_rel":"25 Sep"}]},{"title":"Crooks use fake desktop apps to fool HR staff into giving them remote access","link":"https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226","reason":"Windows","category":"News","sources":["Cyber Security News","Dark Reading","Malwarebytes Labs","Microsoft Security","SecurityWeek","The Hacker News","The Register Security"],"coverage":7,"cve_ids":["CVE-2026-85921"],"summary":"You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=262302&width=800","description":"You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it. Unfortunately, the app isn't what it claims to be. Instead, it silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to your PC. Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and\u2026","related":[{"title":"New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining","link":"https://www.securityweek.com/new-x47-c-windows-botnet-weaponizes-xai-grok-ai-api-draining/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Kothamine malware uses Tailscale\u2019s tailcat to evade network detection","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection","source":"Malwarebytes Labs","date_rel":"25 Sep"},{"title":"Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems","link":"https://cybersecuritynews.com/samsung-flaw/","source":"Cyber Security News","date_rel":"25 Sep"},{"title":"CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921","source":"Microsoft Security","date_rel":"25 Sep"},{"title":"TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace","link":"https://cybersecuritynews.com/tweakos-malware/","source":"Cyber Security News","date_rel":"25 Sep"},{"title":"Criminals turn placeholder domain into ClickFix trap","link":"https://www.malwarebytes.com/blog/news/2026/09/criminals-turn-placeholder-domain-into-clickfix-trap","source":"Malwarebytes Labs","date_rel":"25 Sep"}]},{"title":"Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells","link":"https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYN2VWIT2g8mQkV0GeZWzYErKcubb0-baI8J__2nmdElucECc7HrLkdPsR1dz93qjMBI5sr_dL8yPWHf2bwWCBXa3YfutHAeJ-70UCSMuJrHhyOB3RO4OkuDjuw7gxRLXUnK-CeK9jZO0uOJRy-N3w-rV7uZ4t1FnFIWNjEsKtSYQINUvPX31mKzV_5Ert/s1600/oracle-flaw.jpg","description":"Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day","related":[{"title":"Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script","link":"https://www.theregister.com/security/2026/09/25/fake-google-security-team-ad-says-no-script-reading-in-voice-phishing-then-prints-the-script/5299264","source":"The Register Security","date_rel":"21h ago"},{"title":"What We Missed: Google Gemini Joins the AI Escape Party","link":"https://www.darkreading.com/cyber-risk/what-we-missed-google-gemini-ai-escape-party","source":"Dark Reading","date_rel":"23h ago"},{"title":"Google to critical infra orgs: Our AI scanners won't be evil, promise","link":"https://www.theregister.com/security/2026/09/24/google-to-critical-infra-orgs-our-ai-scanners-wont-be-evil-promise/5298685","source":"The Register Security","date_rel":"24 Sep"},{"title":"Google\u2019s location data privacy failures draw a \u20ac403 million fine","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine","source":"Malwarebytes Labs","date_rel":"24 Sep"},{"title":"Google Chrome security advisory (AV26-955)","link":"https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-955","source":"CCCS Alerts & Advisories","date_rel":"23 Sep"}]},{"title":"OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services","link":"https://cybersecuritynews.com/oneplus-15-flaws-zero-permission-apps/","reason":"Android","category":"News","sources":["Cyber Security News","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services. The vulnerabilities are\u2026","source":"Cyber Security News","date_rel":"22h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/OnePlus-15-Flaws-Let-Zero-Permission-Apps-Gain-Root-Access-Through-OxygenOS-Services.webp","description":"Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services. The vulnerabilities are significant because Android permission prompts normally act as a barrier between untrusted apps and sensitive device functions. A user may reasonably assume that an app requesting no permissions has limited capabilities. However, the reported OxygenOS flaws could bypass that expectation by abusing system components already running with elevated privileges. Researcher Rasmus\u2026","related":[{"title":"Windows, Linux, Android File Notification Systems Leak User Activity","link":"https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/","source":"SecurityWeek","date_rel":"25 Sep"},{"title":"RemControl Banking Trojan Gives Attackers Remote Control of Android Devices","link":"https://www.infosecurity-magazine.com/news/banking-trojan-remote-control/","source":"Infosecurity Magazine","date_rel":"25 Sep"},{"title":"Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions","link":"https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html","source":"The Hacker News","date_rel":"24 Sep"},{"title":"Decades-old file security flaws found in Android, Linux, macOS, and Windows","link":"https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672","source":"The Register Security","date_rel":"24 Sep"},{"title":"Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls","link":"https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html","source":"The Hacker News","date_rel":"24 Sep"},{"title":"Update Chrome: 108 security fixes for desktop, new release for Android","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-108-security-fixes-for-desktop-new-release-for-android","source":"Malwarebytes Labs","date_rel":"24 Sep"}]},{"title":"Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware","link":"https://thehackernews.com/2026/09/compromised-github-actions-came-back.html","reason":"Github","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected\u2026","source":"The Hacker News","date_rel":"25 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJFMIQ6v0uJDRoxyIhqsoqsYoXN00dcDH4IvkdQAkRBRj6ha5LIu2-2yzzvQk1OZTc-7tK1fjeqyIh8xvRNvz_CotOtGNsYnejlbHED7cI-bmZFP80JIdxk_0D9I6Zo10-6b4x4euCTaRtz8c6ncYKykDsW7Bt4oFEVYWTe3AHJdiUxM32R6hGP9C0Y0Xf/s1600/github-shai.jpg","description":"Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: \"Access to this","related":[{"title":"GitHub Actions re-enabled with Mini Shai-Hulud payload still active","link":"https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"GitHub security advisory (AV26-956)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-956","source":"CCCS Alerts & Advisories","date_rel":"23 Sep"}]},{"title":"Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link","link":"https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoCsmpn_im_gimeko6yEdebgucFfzjRrTH0Hmvl1triNXT64w_JdoBIqCrFEApRZ9mmKBYfJQ1fqgfubPH3ZRaWW7SJ2HSr18mBsjSdFE6AwVl362SwcdzHp0EtlL2qoVuYARkSKmOqQaORUjjYVAM-PCT9Itvvkgb69lyVLttezAFtAuCw86RpPu3lAo4/s1600/wordpress-ele.jpg","description":"Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions","related":[{"title":"WordPress security advisory (AV26-952) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/wordpress-security-advisory-av26-952","source":"CCCS Alerts & Advisories","date_rel":"20h ago"},{"title":"Elementor WordPress flaw lets attackers create admin accounts","link":"https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/","source":"Bleeping Computer","date_rel":"22h ago"}]},{"title":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","link":"https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958","reason":"Salesforce","category":"News","sources":["Dark Reading","Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered\u2026","source":"The Register Security","date_rel":"24 Sep","thumbnail":"https://image.theregister.com/?imageId=5223048&width=800","description":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues. While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and\u2026","related":[{"title":"Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk","link":"https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/","source":"Infosecurity Magazine","date_rel":"25 Sep"},{"title":"\u2018SalesBleed\u2019 Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration","link":"https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/","source":"SecurityWeek","date_rel":"25 Sep"},{"title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","link":"https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing","source":"Dark Reading","date_rel":"24 Sep"}]},{"title":"Bitget blames North Korea for $387.5M crypto wallet raid","link":"https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218","reason":"Exchange","category":"News","sources":["Bleeping Computer","The Hacker News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange\u2019s\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=239887&width=800","description":"The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange\u2019s wallets. Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate. Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that\u2026","related":[{"title":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise","link":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html","source":"The Hacker News","date_rel":"25 Sep"},{"title":"Hackers steal $351.6 million in Bitget crypto exchange hack","link":"https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/","source":"Bleeping Computer","date_rel":"25 Sep"}]},{"title":"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/","reason":"CVE-2026-5430","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-5430","CVE-2026-71362"],"summary":"The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider\u2026","source":"Bleeping Computer","date_rel":"23h ago","thumbnail":"","description":"","related":[{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"24 Sep"}]},{"title":"GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks","link":"https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks","reason":"Gitlab","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading"],"coverage":2,"cve_ids":[],"summary":"Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.","source":"Dark Reading","date_rel":"23 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt60455cbfb6e49e3c/6ab3c1c302cf7035adb7a896/email-Bussarin_Rinchumrus-Getty-2157664756.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"GitLab security advisory (AV26-962)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-962","source":"CCCS Alerts & Advisories","date_rel":"25 Sep"}]}],"worth_reading":[{"title":"Wiz Named a Leader in The Forrester Wave\u2122: Proactive Security Platforms, Q3 2026","link":"https://www.wiz.io/blog/forrester-wave-for-proactive-security-2026","reason":"Forrester Proactive Platforms","category":"Research","sources":["CrowdStrike Blog","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"Forrester\u2019s Proactive Security Platforms evaluation rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era","source":"Wiz Research","date_rel":"24 Sep","thumbnail":"https://www.datocms-assets.com/75231/1790266246-blog-banner-image.png","description":"","related":[{"title":"CrowdStrike Named a Leader in The Forrester Wave\u2122: Proactive Security Platforms, Q3 2026","link":"https://www.crowdstrike.com/en-us/blog/crowdstrike-named-leader-forrester-wave-proactive-security-platforms-q3-2026/","source":"CrowdStrike Blog","date_rel":"24 Sep"}]},{"title":"Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)","link":"https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/","reason":"F5","category":"Research","sources":["The Register Security","watchTowr Labs"],"coverage":2,"cve_ids":["CVE-2026-94127"],"summary":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas\u2026","source":"watchTowr Labs","date_rel":"23 Sep","thumbnail":"https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/2026/09/1.png","description":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it\u2019s a free-for-all (unless you\u2019re trying to buy RAM). Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces\u2026 (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in\u2026","related":[{"title":"Someone's attacking a critical 0-day RCE in F5 BIG-IP APM","link":"https://www.theregister.com/security/2026/09/23/someones-attacking-a-critical-0-day-rce-in-f5-big-ip-apm/5298659","source":"The Register Security","date_rel":"23 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-100075","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters\n\nWhen srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect\ndescriptor, the unwind path destroys RDMA cont\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-100075"},{"id":"CVE-2026-93643","vendor":"Microsoft","product":"Zimbra Collaboration Suite (ZCS)","severity":"CRITICAL","score":9.8,"description":"When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned\u00a0save\u00a0fields to perform path-traversal writes and execute commands as\u00a0zimbra.","cwe":"CWE-22","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93643"},{"id":"CVE-2026-92161","vendor":"FriendsOfFlarum","product":"oauth","severity":"CRITICAL","score":9.8,"description":"FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before pas\u2026","cwe":"CWE-345","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92161"},{"id":"CVE-2026-18143","vendor":"WordPress","product":"Request a Quote for WooCommerce","severity":"CRITICAL","score":9.8,"description":"The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME ty\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18143"},{"id":"CVE-2026-93641","vendor":"Zimbra","product":"Zimbra Collaboration Suite (ZCS)","severity":"CRITICAL","score":9.3,"description":"An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93641"},{"id":"CVE-2026-93642","vendor":"Zimbra","product":"Zimbra Collaboration Suite (ZCS)","severity":"CRITICAL","score":9.3,"description":"An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93642"},{"id":"CVE-2026-93647","vendor":"Zimbra","product":"Zimbra Collaboration Suite (ZCS)","severity":"CRITICAL","score":9.3,"description":"An unauthenticated calendar sender can place active markup in a COUNTER message's RFC\u00a0From\u00a0address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93647"},{"id":"CVE-2026-39353","vendor":"InvoicePlane","product":"InvoicePlane","severity":"CRITICAL","score":9.1,"description":"InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an adm\u2026","cwe":"CWE-98","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-39353"},{"id":"CVE-2026-42322","vendor":"Piwigo","product":"Piwigo","severity":"CRITICAL","score":9.1,"description":"Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when c\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-42322"},{"id":"CVE-2026-62262","vendor":"Piwigo","product":"Piwigo","severity":"CRITICAL","score":9.1,"description":"Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-62262"}],"vendor_spikes":[{"vendor":"Linux","count":341,"critical_count":1},{"vendor":"OpenClaw","count":53,"critical_count":0},{"vendor":"Unknown","count":37,"critical_count":0},{"vendor":"Microsoft","count":30,"critical_count":1},{"vendor":"rabbitmq","count":28,"critical_count":0},{"vendor":"zammad","count":20,"critical_count":0},{"vendor":"WordPress","count":17,"critical_count":1},{"vendor":"Apple","count":15,"critical_count":0},{"vendor":"HashiCorp","count":13,"critical_count":0},{"vendor":"InvoicePlane","count":13,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":725,"has_news_data":true,"has_cve_data":true}