24h | 7d | 30d

Overview

  • N-able
  • N-central

06 Sep 2026
Published
09 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.41%

Description

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Statistics

  • 8 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

N-able releases N-central Hotfix 4 to address a critical zero-day vulnerability. Learn how to protect your server from remote code execution attacks today.

meterpreter.org/n-central-zero

  • 0
  • 0
  • 0
  • 1h ago

Bluesky

Profile picture fallback
N-able released an urgent hotfix for a zero-day RCE in N-central (CVE-2026-86218) and urges on-prem users to patch immediately and review logs.
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
@huntress.com Pre-auth RCE is actively exploited; patch N-central HF4 immediately. - IOCs: 23[.]234[.]100[.]105, 23[.]234[.]97[.]68 - #CVE2026-86218 #ThreatIntel
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
CISA added CVE-2026-86218 in N-able N-central to KEV, requiring FCEB agencies to patch by September 11, 2026.
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
Une faille critique RCE pré-auth dans #Nable N-central (CVE-2026-86218, score 10.0) est exploitée. #CISA exige un correctif avant le 11/09/2026 pour les agences fédérales US. 🚨 #CyberSecurity #Automatisation
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
CISA added CVE-2026-86218 to the KEV catalog after N-able said the N-central flaw was exploited in the wild. The pre-auth RCE issue is fixed in N-central 2026.3 Hotfix 4. #CVE202686218 #Nable #Ncentral
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
CISA added CVE-2026-86218, a maximum-severity static code injection vulnerability in N-able N-central, to its Known Exploited Vulnerabilities catalog. The flaw, […]
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
~Cybergcca~ N-able, MikroTik and Adobe report vulnerabilities exploited in the wild; patch affected systems. - IOCs: CVE-2026-86218, CVE-2026-67276, CVE-2026-75650 - #CVE #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Adobe
  • Adobe Commerce

07 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.68%

Description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Statistics

  • 9 Posts
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. thehackernews.com/2026/09/adob

  • 0
  • 0
  • 1
  • 20h ago

Bluesky

Profile picture fallback
Adobe Patches Critical Magento Flaw Exploited in the Wild Adobe has patched CVE-2026-75650, a critical Magento and Adobe Commerce flaw rated 10.0 that attackers are actively exploiting to execute code and deploy backdoors.
  • 1
  • 0
  • 0
  • 22h ago
Profile picture fallback
Adobe has patched CVE-2026-75650 in Commerce and Magento, scored 10.0 out of 10 and already exploited to plant backdoors on store servers. Anything running 2.4.4 through 2.4.9 needs the VULN-39341 hotfix and an encryption key rotation.
  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback
Adobe released security patches for CVE-2026-75650, a actively exploited Magento template injection flaw enabling arbitrary code execution.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day in Commerce and Magento Open Source exploited since September 4, 2026. The “StyleSmuggler” […]
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Adobe released patches for 170+ vulnerabilities, including exploited zero-day CVE-2026-75650 in Commerce/Magento and additional critical flaws requiring immediate remediation and key rotation.
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
~Cybergcca~ N-able, MikroTik and Adobe report vulnerabilities exploited in the wild; patch affected systems. - IOCs: CVE-2026-86218, CVE-2026-67276, CVE-2026-75650 - #CVE #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-75650, CVE-2026-81963, CVE-2026-85880 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Google
  • Chrome

09 Sep 2026
Published
09 Sep 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: Last hour

Fediverse

Profile picture fallback

Google Chrome 153 (153.0.8010.36/.37) korrigiert 230 Sicherheitslücken – CVE-2026-87491 in der freien Wildbahn

deskmodder.de/blog/2026/09/09/

  • 1
  • 0
  • 0
  • Last hour
Profile picture fallback

Google patched a Chrome zero-day, CVE-2026-87491, exploited in the wild. Chrome 153 fixes 230 flaws including critical WebGL bugs. Update now.

securityonline.info/chrome-zer

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
ゼロデイあり > "Google is aware that an exploit for CVE-2026-87491 exists in the wild."
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) 🔗 Read more: www.helpnetsecurity.com/2026/09/09/g... #Chrome #exploit #cybersecurity
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Microsoft
  • Windows 11 version 23H2

08 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
Pending

Description

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Statistics

  • 8 Posts
  • 3 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

securityonline.info/patch-tues

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

#Microsoft Plugs Nearly 1,000 #Security Holes

This month’s #patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security #vulnerabilities. September’s #PatchTuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.

There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on #Windows system.
#zeroday #exploit

Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user

krebsonsecurity.com/2026/09/mi

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Microsoft、2026年9月Patch Tuesdayでサイバー攻撃への悪用済み ゼロデイ 脆弱性 2件を修正 CVE-2026-81963・CVE-2026-85880 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Microsoft's Patch Tuesday disclosed 973 bugs, including two actively exploited flaws, CVE-2026-81963 and CVE-2026-85880. CISA says federal agencies must patch by Sept. 22. #Microsoft #Windows #CISA
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
「この内 CVE-2026-81963、CVE-2026-85880 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。」
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-75650, CVE-2026-81963, CVE-2026-85880 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
@talosintelligence.com 973 flaws, including 113 critical; CVE-2026-81963 and CVE-2026-85880 exploited in the wild. - IOCs: CVE-2026-81963, CVE-2026-85880, CVE-2026-69730 - #CVE #PatchTuesday #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

08 Sep 2026
Published
09 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
Pending

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Statistics

  • 8 Posts
  • 3 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild.

securityonline.info/patch-tues

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

#Microsoft Plugs Nearly 1,000 #Security Holes

This month’s #patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security #vulnerabilities. September’s #PatchTuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go.

There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on #Windows system.
#zeroday #exploit

Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user

krebsonsecurity.com/2026/09/mi

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
Microsoft、2026年9月Patch Tuesdayでサイバー攻撃への悪用済み ゼロデイ 脆弱性 2件を修正 CVE-2026-81963・CVE-2026-85880 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
Microsoft's Patch Tuesday disclosed 973 bugs, including two actively exploited flaws, CVE-2026-81963 and CVE-2026-85880. CISA says federal agencies must patch by Sept. 22. #Microsoft #Windows #CISA
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
「この内 CVE-2026-81963、CVE-2026-85880 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。」
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities to its KEV Catalog; prioritize rapid remediation. - IOCs: CVE-2026-75650, CVE-2026-81963, CVE-2026-85880 - #CVE #KEV #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
@talosintelligence.com 973 flaws, including 113 critical; CVE-2026-81963 and CVE-2026-85880 exploited in the wild. - IOCs: CVE-2026-81963, CVE-2026-85880, CVE-2026-69730 - #CVE #PatchTuesday #ThreatIntel
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

14 Aug 2026
Published
08 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.56%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".

Statistics

  • 3 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.

securityonline.info/windows-de

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
Het lek, aangeduid als ShieldBreak (CVE-2026-69414), maakt het mogelijk voor een lokale aanvaller met beperkte rechten om via de Cloud Filter API volledige beheerdersrechten te verkrijgen.
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Microsoft Defenderの修正回避PoC「ShieldCrash」公開 ShieldBreak(CVE-2026-69414)対策後もSYSTEM権限で任意ファイル読み取りと研究者主張 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • SAP_SE
  • SAP Extended Passport (EPP) Processing

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

Statistics

  • 5 Posts
  • 9 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

OVERPASS: SAP-Kernel-Schwachstelle CVE-2026-44756 erfordert sofortiges Patchen

CVSS-Bewertung: 10,0 (höchste Stufe) | Handlungsbedarf: sofort

all-about-security.de/overpass

#sap #sapsecurity

  • 0
  • 0
  • 1
  • 19h ago
Profile picture fallback

OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).

Both have a very high CVSS and are likely to be exploited.

onapsis.com/blog/sap-overpass-

onapsis.com/blog/s4get-cve-202

  • 7
  • 2
  • 1
  • 18h ago

Bluesky

Profile picture fallback
SAP、CVSS 10.0の「OVERPASS」を修正 SAP KernelのCVE-2026-44756、未認証で複数経路から到達可能 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Fortinet
  • FortiSandbox PaaS

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
Pending

KEV

Description

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

‼️ FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Source: cybersecuritynews.com/fortisan

The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.

FortiSandbox is widely deployed across enterprise and government networks as an advanced threat detection appliance, using sandboxing techniques to analyze suspicious files and network traffic for zero-day malware and other advanced threats.

  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback

Fortinet fixed three critical Fortinet vulnerabilities. Attackers can exploit CVE-2026-84390 and CVE-2026-26084 to access corporate data.

securityonline.info/fortinet-v

  • 1
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Fortinet、FortiMonitor・FortiSandbox・FortiPAMの脆弱性を修正 認証回避など3件、CVSS最大9.6(FG-IR-26-170,FortiPAMFG-IR-26-168,CVE-2026-26084) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Proxmox Server Solutions GmbH
  • Proxmox Virtual Environment (VE)

01 Sep 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.75%

KEV

Description

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: 23 hours ago

Fediverse

Bluesky

Profile picture fallback
🚨 Kritische Proxmox-Lücke: CVE-2023-54391 ermöglicht in älteren Proxmox-VE-Versionen unter bestimmten Voraussetzungen einen Login ohne gültiges Passwort. CVSS: 9,8. Admins sollten Paketversion und Erreichbarkeit von Port 8006 jetzt prüfen. it-administrator.de #Proxmox #Cybersecurity #ITSecurity #CVE
  • 1
  • 1
  • 0
  • 23h ago

Overview

  • Fortinet
  • FortiSwitchManager

13 Jan 2026
Published
11 Aug 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
0.76%

KEV

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Statistics

  • 3 Posts

Last activity: 18 hours ago

Fediverse

Profile picture fallback

FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar

The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon....

itnerd.blog/2026/09/08/fortiga

  • 0
  • 0
  • 1
  • 18h ago

Bluesky

Profile picture fallback
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
  • 0
  • 0
  • 0
  • 22h ago
Showing 1 to 10 of 78 CVEs