Wednesday, September 30, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- Google 24 critical 144
- Mozilla 9 critical 77
- WordPress 30
- Eclipse Foundation 23
- HP 5 critical 21
- Apache 19
- Unknown 3 critical 19
- Wireshark Foundation 18
- Joomla! Project 16
- Microsoft 1 critical 15
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: Cyber Security News RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions
RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots. Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia. Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three…
Also in The Record Bleeping Computer CISA Alerts & Advisories +3
-
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that…
Also in SecurityWeek Palo Alto Unit 42 Rapid7 Blog +2
-
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
Also in Dark Reading CyberScoop The Hacker News +3
-
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the…
Also in Infosecurity Magazine Dark Reading CISA Alerts & Advisories +2
-
AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access
Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path, where a missing bounds check allows attacker-controlled data to be copied beyond an allocated kernel buffer. The vulnerability is notable not only for its impact, but for the weakness of the available exploit primitive. XBOW’s research showed that the bug could reliably produce only 16 zero…
Also in Bleeping Computer The Hacker News Bleeping Computer +3
-
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
Also in Bleeping Computer Bleeping Computer The Hacker News +3
-
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler
Also in CyberScoop Bleeping Computer The Register Security +1
-
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
Also in SecurityWeek Infosecurity Magazine Infosecurity Magazine
-
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Also in SecurityWeek Cyber Security News
-
Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software
A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information. The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory. The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task. The investigation did not establish how the altered software first reached the victim’s…
Also in Microsoft Security Microsoft Security Microsoft Security
CVE-2026-69288 ↗CVE-2026-69504 ↗CVE-2026-69712 ↗View on Security Feed
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-53988 | dockhandFinsys | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isDockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. A… Attack
Exploitation
|
|||||||||
| CVE-2026-96587 | Dashcam Android ApplicationGoogle | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isThe Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational… Attack
Exploitation
|
|||||||||
| CVE-2026-71379 | TMS7Toptech Systems | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isThe file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request. Attack
Exploitation
|
|||||||||
| CVE-2026-84154 | GEOVIA Geospatial Data ManagerDassault Systèmes | Critical | 9.9 | 0.4% | — | None linked | — | EPSS 0.4%CVSS 9.9No fix linked | |
What it isA Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. Attack
Exploitation
|
|||||||||
| CVE-2026-102911 | pi-llm-wikizosmaai | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isA flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection… Attack
Exploitation
|
|||||||||
| CVE-2023-54400 | Fumeng CloudMicrosoft | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isFumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authenticati… Attack
Exploitation
|
|||||||||
| CVE-2026-77177 | Unknown | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isOpen GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation … Attack
Exploitation
|
|||||||||
| CVE-2026-100291 | YSSD-RTMP-H5Anjvision | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIn Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations. Attack
Exploitation
|
|||||||||
| CVE-2026-39117 | Unknown | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isAn issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php Attack
Exploitation
|
|||||||||
| CVE-2026-76721 | Instant ONHP | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isBuffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to… Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Worth reading quieter, still worth your time
-
The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub
See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling
Also in Infosecurity Magazine
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.