HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 10, 2026.
-
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
— Bleeping Computer
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management … -
AdaptHealth confirms 4.1 million people exposed in July cyberattack
— Bleeping Computer
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attrib… -
Mythos Vulnerability Firehose Hits a Human Bottleneck
— Dark Reading
An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed. -
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
— Bleeping Computer
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairin… -
US Government Accuses Chinese AI Firms of Distilling Frontier Models
— Dark Reading
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce… -
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
— The Hacker News
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarante… -
Scans for Proxmox Servers, (Wed, Sep 9th)
— SANS ISC
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment … -
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
— The Hacker News
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that c… -
Identity-Based AI Attack Threatens Security of Enterprise Data
— Dark Reading
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an … -
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
— The Hacker News
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illi… -
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
— Unit 42
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks… -
ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (14350 in last 30 days).
Critical: 1 · High: 9 · Medium: 10 · Low: 0. View full dashboard →
-
CVE-2026-87931
— CVSS 9.6 (CRITICAL)
A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The ⦠-
CVE-2026-87926
— CVSS 4.3 (MEDIUM)
A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a mani⦠-
CVE-2026-87925
— CVSS 7.3 (HIGH)
A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Perf⦠-
CVE-2026-87924
— CVSS 6.5 (MEDIUM)
A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoi⦠-
CVE-2026-87923
— CVSS 4.3 (MEDIUM)
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the comp⦠-
CVE-2026-15460
— CVSS 5.4 (MEDIUM)
The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target ⦠-
CVE-2026-88002
— CVSS 6.5 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history b⦠-
CVE-2026-88001
— CVSS 5.0 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect de⦠-
CVE-2026-88000
— CVSS 6.5 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/⦠-
CVE-2026-87999
— CVSS 7.1 (HIGH)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/⦠-
CVE-2026-87998
— CVSS 7.1 (HIGH)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against ⦠-
CVE-2026-87997
— CVSS 4.3 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-s⦠-
CVE-2026-87996
— CVSS 7.7 (HIGH)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in ⦠-
CVE-2026-87995
— CVSS 8.7 (HIGH)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox conta⦠-
CVE-2026-87994
— CVSS 4.3 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel ⦠-
CVE-2026-87922
— CVSS 7.3 (HIGH)
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/proc⦠-
CVE-2026-87921
— CVSS 7.3 (HIGH)
A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argum⦠-
CVE-2026-87017
— CVSS 4.3 (MEDIUM)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filt⦠-
CVE-2026-87016
— CVSS 8.1 (HIGH)
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON conta⦠-
CVE-2026-15913
— CVSS 7.7 (HIGH)
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxedâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment