Wednesday, October 7, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- Google 20 critical 253
- Linux 2 critical 194
- WordPress 4 critical 44
- HP 16 critical 37
- Gitea 30
- payloadcms 3 critical 29
- Microsoft 2 critical 26
- Arista Networks 2 critical 24
- IBM 2 critical 24
- Dell 7 critical 22
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: Ars Technica Security Hackers obtain counterfeit TLS certificates for Google and other large services
Attackers hijacked three top-level domains and used their control to mint counterfeit TLS certificates for Google and other large organizations, Google said Tuesday. The attackers launched a series of attacks on the .gh, .sl, and .as country code top-level domains (ccTLDs) and then modified authoritative DNS records for selected domains within those namespaces. By controlling those DNS records, the attackers were able to pass automated domain control validation checks and obtain unauthorized certificates for “several Google domains” and “several leading global brands and widely used online…
Also in The Hacker News Dark Reading Bleeping Computer +3
-
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
Also in SecurityWeek CCCS Alerts & Advisories The Hacker News +1
-
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
Also in The Register Security CCCS Alerts & Advisories The Hacker News +1
-
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
Also in Dark Reading Rapid7 Blog Wiz Research +2
-
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
-
Google Chrome Update Fixes Massive 247 Vulnerabilities, Including 4 Code Execution Flaws
Google released a major Chrome security update on October 6, 2026, fixing 247 vulnerabilities, including four critical memory-safety flaws , across Windows, Mac, and Linux. The patched versions are 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 for Linux. Although the critical bugs raise concerns about possible code execution, Google’s announcement identifies them as use-after-free vulnerabilities. It does not describe specific exploitation methods or confirm arbitrary code execution. The first critical vulnerability, CVE-2026-106382, affects Chromecast. Google reported the…
Also in SecurityWeek Malwarebytes Labs
-
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge
-
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Also in The Register Security CyberScoop
-
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may
Also in The Register Security Dark Reading The Register Security +1
-
Citrix NetScaler security snafus get even worse amid more 0-day reports
The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was…
Also in CyberScoop Infosecurity Magazine CCCS Alerts & Advisories
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-32579 | Kognetiks Chatbot for WordPressWordPress | Critical | 10.0 | 0.5% | — | None linked | — | EPSS 0.5%CVSS 10.0No fix linked | |
What it isUnauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-39770 | DoctreatAmentoTech | Critical | 10.0 | 0.4% | — | None linked | — | EPSS 0.4%CVSS 10.0No fix linked | |
What it isUnauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-39773 | Doctreat CoreAmentoTech | Critical | 10.0 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 10.0No fix linked | |
What it isUnauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-63688 | Dell Container Storage Modules (CSM)Dell | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isDell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploi… Attack
Exploitation
|
|||||||||
| CVE-2026-63692 | Container Storage ModulesDell | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isDell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Eleva… Attack
Exploitation
|
|||||||||
| CVE-2026-105857 | payloadpayloadcms | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isPayload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely … Attack
Exploitation
|
|||||||||
| CVE-2026-106102 | quasarquasarframework | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isQuasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into tit… Attack
Exploitation
|
|||||||||
| CVE-2026-32568 | WooCommerce Designer ProWordPress | Critical | 9.9 | 0.7% | — | None linked | — | EPSS 0.7%CVSS 9.9No fix linked | |
What it isSubscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-39755 | WP Duplicaterevmakx | Critical | 9.9 | 0.4% | — | None linked | — | EPSS 0.4%CVSS 9.9No fix linked | |
What it isSubscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-39757 | TaskbotAmentoTech | Critical | 9.9 | 0.5% | — | None linked | — | EPSS 0.5%CVSS 9.9No fix linked | |
Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.