Cyber News

//
HighSEP 20, 2026

Zimbra CVE-2026-73570: Exploited Unauth SNMP RCE

Zimbra CVE-2026-73570: an actively exploited unauth RCE (CVSS 8.9) in zimbra-snmp, in CISA KEV. Affected versions, fix, PoC status, and detection.

// AI · 4 MIN READ · READ →
// TRENDING
// 160 ENTRIES · PAGE 01/14
High
SEP 20, 2026

SolarWinds ARM CVE-2026-28326: Unauthenticated RCE

SolarWinds ARM CVE-2026-28326 is a CVSS 8.8 unauthenticated RCE via a hard-coded key. Affects Access Rights Manager 2026.2 and earlier; patch to 2026.2.1.

// Threat4 MIN READ
Critical
SEP 20, 2026

Linux Kernel CVE-2025-39682: 3 Flaws Exploited (CISA KEV)

Linux kernel CVE-2025-39682 and two more are in CISA KEV, exploited in the wild, plus 4 public local-root exploits. Which kernel flaws to patch now.

// OS4 MIN READ
Critical
SEP 20, 2026

Azure AI Foundry CVE-2026-85889: CVSS 10.0 Privesc

Azure AI Foundry CVE-2026-85889 is a CVSS 10.0 missing-authentication privilege-escalation flaw. Microsoft mitigated it server-side; no customer action.

// AI4 MIN READ
Notable
SEP 20, 2026

Claude Opus 5 Used to Breach OpenAI Staff Accounts

Hacktron researchers used Claude Opus 5 to chain libheif CVE-2026-32882 with an OpenAI SSO flaw and reach internal OpenAI code. What defenders should learn.

// AI5 MIN READ
Critical
SEP 16, 2026

VMware Workstation CVE-2026-59346: 9.3 VM-to-Host Escape

VMware Workstation and Fusion CVE-2026-59346 is a CVSS 9.3 VMXNET3 flaw letting a VM admin run code on the host. Affected versions and how to patch to 26H1u1.

// Enterprise4 MIN READ
Notable
SEP 16, 2026

OpenAI AI Agents Linked to RubyGems Supply-Chain Attack

Researchers link OpenAI AI agents to a RubyGems supply-chain attack: hundreds of malicious AI-generated packages and RCE on RubyDoc.info. What to know.

// AI5 MIN READ
Critical
SEP 16, 2026

Cisco Secure Email Gateway CVE-2026-76461 Exploited

CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway giving unauthenticated root RCE. Actively exploited, in CISA KEV. Patch AsyncOS now.

// AI4 MIN READ
Critical
SEP 16, 2026

WSO2 API Manager CVE-2026-5430: JWT Bypass Exploited

WSO2 API Manager CVE-2026-5430 is a critical JWT auth bypass (CVSS 10.0) accepting forged admin tokens. Actively exploited per watchTowr. Patch now.

// Threat4 MIN READ
High
SEP 16, 2026

Google Pixel CVE-2026-58704: Android Zero-Day Exploited

Google Pixel CVE-2026-58704 is an actively exploited Android modem zero-day (CVSS 8.0). Install the September 2026 update (2026-09-05 patch level).

// OS4 MIN READ
Critical
SEP 13, 2026

Check Point VPN CVE-2026-85102: RCE, Exploit Imminent

Check Point VPN CVE-2026-85102 and CVE-2026-85103 are two CVSS 9.8 remote code execution flaws in Security Gateways. The Dutch NCSC warns exploitation is imminent. Patch now.

// Edge4 MIN READ
Critical
SEP 13, 2026

GitLab CVE-2026-85706: CVSS 10 Path Traversal in KEV

GitLab CVE-2026-85706 is a CVSS 10.0 unauthenticated path traversal letting attackers read arbitrary files in one request. It is in CISA KEV with in-the-wild probes. Patch now.

// Enterprise4 MIN READ
High
SEP 13, 2026

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

The BlueMoon exploit kit chains two Chrome V8 zero-days and a Windows ALPC privilege-escalation bug into a browser-to-SYSTEM attack, and multiple China-linked APTs are using it.

// AI4 MIN READ
PAGE 01 / 14