📰 DAILY THREAT BRIEFING
Thursday, September 10, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 10, 2026.

  1. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
    — Bleeping Computer

    Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management …
  2. AdaptHealth confirms 4.1 million people exposed in July cyberattack
    — Bleeping Computer

    Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attrib…
  3. Mythos Vulnerability Firehose Hits a Human Bottleneck
    — Dark Reading

    An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.
  4. Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
    — Bleeping Computer

    The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairin…
  5. US Government Accuses Chinese AI Firms of Distilling Frontier Models
    — Dark Reading

    US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce…
  6. U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
    — The Hacker News

    The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarante…
  7. Scans for Proxmox Servers, (Wed, Sep 9th)
    — SANS ISC

    About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment …
  8. Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
    — The Hacker News

    Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that c…
  9. Identity-Based AI Attack Threatens Security of Enterprise Data
    — Dark Reading

    "Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an …
  10. Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
    — The Hacker News

    Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illi…
  11. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
    — Unit 42

    An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks…
  12. ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (14350 in last 30 days).
Critical: 1 · High: 9 · Medium: 10 · Low: 0. View full dashboard →

  1. CVE-2026-87931
    — CVSS 9.6 (CRITICAL)

    A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The …
  2. CVE-2026-87926
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a mani…
  3. CVE-2026-87925
    — CVSS 7.3 (HIGH)

    A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Perf…
  4. CVE-2026-87924
    — CVSS 6.5 (MEDIUM)

    A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoi…
  5. CVE-2026-87923
    — CVSS 4.3 (MEDIUM)

    A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the comp…
  6. CVE-2026-15460
    — CVSS 5.4 (MEDIUM)

    The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target …
  7. CVE-2026-88002
    — CVSS 6.5 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history b…
  8. CVE-2026-88001
    — CVSS 5.0 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect de…
  9. CVE-2026-88000
    — CVSS 6.5 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/…
  10. CVE-2026-87999
    — CVSS 7.1 (HIGH)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/…
  11. CVE-2026-87998
    — CVSS 7.1 (HIGH)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against …
  12. CVE-2026-87997
    — CVSS 4.3 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-s…
  13. CVE-2026-87996
    — CVSS 7.7 (HIGH)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in …
  14. CVE-2026-87995
    — CVSS 8.7 (HIGH)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 until 0.11.1, src/lib/components/chat/FileNav/PortPreview.svelte rendered terminal port content in an iframe sandbox conta…
  15. CVE-2026-87994
    — CVSS 4.3 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel …
  16. CVE-2026-87922
    — CVSS 7.3 (HIGH)

    A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/proc…
  17. CVE-2026-87921
    — CVSS 7.3 (HIGH)

    A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argum…
  18. CVE-2026-87017
    — CVSS 4.3 (MEDIUM)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filt…
  19. CVE-2026-87016
    — CVSS 8.1 (HIGH)

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON conta…
  20. CVE-2026-15913
    — CVSS 7.7 (HIGH)

    In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com