HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 9, 2026.
-
Microsoft Plugs Nearly 1,000 Security Holes
— Krebs on Security
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its big… -
Patch Tuesday Sets Another Record With 974 CVEs
— Dark Reading
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft. -
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
— Dark Reading
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote … -
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
— Dark Reading
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose. -
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
— Bleeping Computer
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [..… -
The EU CRA's Real Question: What Shipped, and When Did You Know?
— Bleeping Computer
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours t… -
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
— Bleeping Computer
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into… -
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
— SANS ISC
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Pat… -
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
— The Hacker News
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at … -
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
— The Hacker News
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public reco… -
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
— The Hacker News
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to q… -
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (14411 in last 30 days).
Critical: 2 · High: 8 · Medium: 9 · Low: 1. View full dashboard →
-
CVE-2026-86564
— CVSS 3.3 (LOW)
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash. -
CVE-2026-53638
— CVSS 4.3 (MEDIUM)
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/⦠-
CVE-2026-53637
— CVSS 6.5 (MEDIUM)
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. Wh⦠-
CVE-2026-53581
— CVSS 9.0 (CRITICAL)
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attack⦠-
CVE-2026-18090
— CVSS 6.1 (MEDIUM)
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-⦠-
CVE-2026-86819
— CVSS 7.1 (HIGH)
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its ⦠-
CVE-2026-85983
— CVSS 7.8 (HIGH)
The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the ⦠-
CVE-2026-85982
— CVSS 9.0 (CRITICAL)
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user wi⦠-
CVE-2026-85981
— CVSS 6.7 (MEDIUM)
The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the ho⦠-
CVE-2026-84685
— CVSS 6.5 (MEDIUM)
The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across⦠-
CVE-2026-82001
— CVSS 5.5 (MEDIUM)
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an⦠-
CVE-2026-81997
— CVSS 6.3 (MEDIUM)
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write⦠-
CVE-2026-81996
— CVSS 8.8 (HIGH)
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this i⦠-
CVE-2026-81994
— CVSS 8.2 (HIGH)
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulne⦠-
CVE-2026-81993
— CVSS 5.5 (MEDIUM)
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of⦠-
CVE-2026-81992
— CVSS 7.8 (HIGH)
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi⦠-
CVE-2026-81991
— CVSS 5.5 (MEDIUM)
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this i⦠-
CVE-2026-81990
— CVSS 7.8 (HIGH)
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op⦠-
CVE-2026-81989
— CVSS 7.8 (HIGH)
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op⦠-
CVE-2026-81988
— CVSS 7.8 (HIGH)
Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must opâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 9, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment