📰 DAILY THREAT BRIEFING
Wednesday, September 16, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 16, 2026.

  1. Acronis warns of actively exploited flaw in its cPanel backup plugin
    — Bleeping Computer

    Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and…
  2. Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
    — Bleeping Computer

    Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor c…
  3. Microsoft Issues Emergency Fixes After Massive Patch Tuesday
    — Dark Reading

    You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
  4. Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
    — Dark Reading

    The 'Breaking' News: The OpenAI–Hugging Face Incident – A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 …
  5. KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
    — The Hacker News

    Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KR…
  6. VectraRAT Can Hack Windows Enterprises for $250 per Month
    — Dark Reading

    The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator pan…
  7. CenterPoint Energy confirms customer data stolen in cyberattack
    — Bleeping Computer

    CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from …
  8. Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
    — The Hacker News

    Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's in…
  9. MacOS 27 – First Boot, (Tue, Sep 15th)
    — SANS ISC

    I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick l…
  10. BambooToken Malware Uses MQTT to Control Windows and Linux Systems
    — The Hacker News

    Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) prot…
  11. ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Apple Updates Everything, (Mon, Sep 14th)
    — SANS ISC

    Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 2…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (14616 in last 30 days).
Critical: 2 · High: 8 · Medium: 10 · Low: 0. View full dashboard →

  1. CVE-2026-92184
    — CVSS 6.3 (MEDIUM)

    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Conten…
  2. CVE-2026-73460
    — CVSS 6.1 (MEDIUM)

    On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate premat…
  3. CVE-2026-73459
    — CVSS 7.4 (HIGH)

    On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-stat…
  4. CVE-2026-73446
    — CVSS 7.4 (HIGH)

    On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an establis…
  5. CVE-2026-85893
    — CVSS 8.8 (HIGH)

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
  6. CVE-2026-69486
    — CVSS 8.8 (HIGH)

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
  7. CVE-2025-11395
    — CVSS 5.5 (MEDIUM)

    A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
  8. CVE-2026-92259
    — CVSS 5.5 (MEDIUM)

    Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cac…
  9. CVE-2026-92257
    — CVSS 5.4 (MEDIUM)

    Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers …
  10. CVE-2026-92256
    — CVSS 6.5 (MEDIUM)

    NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to …
  11. CVE-2026-92255
    — CVSS 5.4 (MEDIUM)

    Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploi…
  12. CVE-2026-92248
    — CVSS 7.8 (HIGH)

    A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an emb…
  13. CVE-2026-92114
    — CVSS 5.3 (MEDIUM)

    A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipul…
  14. CVE-2026-83408
    — CVSS 8.1 (HIGH)

    Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23…
  15. CVE-2026-83368
    — CVSS 7.0 (HIGH)

    Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.…
  16. CVE-2026-83357
    — CVSS 8.1 (HIGH)

    Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23…
  17. CVE-2026-82567
    — CVSS 6.3 (MEDIUM)

    The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication bef…
  18. CVE-2026-81855
    — CVSS 9.1 (CRITICAL)

    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
  19. CVE-2026-78225
    — CVSS 9.0 (CRITICAL)

    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
  20. CVE-2026-76873
    — CVSS 5.2 (MEDIUM)

    Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. A LAN-based attacker can inject malici…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 16, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com