P.01CVE-2026-87491: Chrome's Second Zero-Day in a Week
Chrome patched a second actively exploited V8 zero-day in five days. Here is what CVE-2026-87491 affects, the fixed version, and how to check your fleet.
Tag
68 articles tagged #CVE.
P.01Chrome patched a second actively exploited V8 zero-day in five days. Here is what CVE-2026-87491 affects, the fixed version, and how to check your fleet.
P.02CVE-2026-44477 lets any database owner escalate to postgres superuser and run OS commands in CloudNativePG. Here is who is affected and how to patch.
P.03CVE-2026-83548 (SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection) hit SMA1000 appliances again, seven weeks after the last chain. Affected models and the fix.
P.04CISA gave federal agencies until Sept 12 to patch a Citrix NetScaler auth bypass and a critical FortiOS RCE tied to a live PivotC2 malware campaign.
P.05A single unauthenticated request can run code inside OmniRoute, the 58k-star AI gateway. Patch status is contested, so verify your build yourself.
P.06MikroTik patched three RouterOS bugs after CISA confirmed active exploitation of two: which CVEs to prioritize and how to check your router for compromise.
P.07Microsoft's September 8, 2026 update fixes 964 CVEs (104 Critical), the largest Patch Tuesday yet, including two exploited local-privilege zero-days.
P.08N-able's third N-central patch cycle in six weeks fixes CVE-2026-86218, a CVSS 10.0 pre-auth RCE already exploited in the wild and KEV-listed.
P.09CVE-2026-75650 lets anyone run code on unpatched Magento and Adobe Commerce stores. Sansec found it deploying a Rust backdoor before Adobe even patched.
P.10CVE-2026-49869 lets unauthenticated attackers hit any Kestra path ending in /configs, skip login, then run shell commands as root via script plugins.
P.11CVE-2026-9586 is an unauthenticated SQL injection in Sangoma Switchvox's /pa endpoint that leads to RCE. Active exploitation, KEV status, and the fix.
P.12A phantom join key in JFrog Artifactory's auth service let attackers forge admin tokens days after disclosure. Affected versions, what to check, and the patch.
P.13BadHost sat quietly patched since May. In September, CISA flagged active exploitation. If you run FastAPI, vLLM, or any Starlette app, here's what to check.
P.14CVE-2026-85046 is a Chrome V8 type confusion bug already exploited in the wild. Here's who's affected, what version fixes it, and how fast to move.
P.15CVE-2026-59822 lets an attacker fake a Bearer token and skip LiteLLM's MCP auth entirely. Different bug from June's RCE chain, same exposed surface.
P.16CVE-2026-81934 is a use-after-free in Redis's TLS pending-data handling, with a public PoC. If you don't terminate TLS inside Redis, it mostly passes you by.
P.17A public proof-of-concept for a Windows Defender privilege-escalation flaw has circulated since August 12 with no fix shipped. What to do about it now.
P.18Two chained PaperCut NG/MF flaws let an attacker with no credentials run code on your print server. PaperCut needed two emergency patches to close it.
P.19A capture-replay flaw in Tomcat's DIGEST authenticator lets an intercepted request be replayed once inside the nonce window. Critical, but narrow.
P.20Chrome 152 landed 327 security fixes, 10 of them critical use-after-free bugs in ANGLE, Views, and Safe Browsing. Why not-exploited isn't the same as safe.
P.21One unauthenticated RCE in PTC Windchill and FlexPLM let Cl0p quietly take data from Shell, Philips, and GE. How CVE-2026-12569 works, and what to check.
P.22Citrix shipped CVE-2026-8452 as a routine DoS fix in June. watchTowr showed it's a pre-auth heap overflow with a path to RCE. CISA's deadline was August 29.
P.23A flaw in Gitea's diffpatch API turns a crafted merge conflict into an executable Git hook. CISA added it after miner payloads showed up. What to patch.
P.24A Secure Remote Password bug let attackers into macOS Screen Sharing without credentials and reach root. Apple patched August 6; CISA listed it August 18.
P.25PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 fixed 28 CVEs on August 13, 17 of them CVSS 8.0 or higher. Which matter, and who's actually exposed.
P.26CISA added two TrueConf Server flaws to its KEV catalog in one week, and a hacktivist group has been swapping client installers for backdoors since July.
P.27A double-free in Windows IKE Service Extensions gives remote code execution from one crafted UDP packet, no auth. CISA confirmed exploitation, deadline Aug 21.
P.28A CVSS 9.1 flaw in SharePoint's JWT validation lets an unauthenticated attacker impersonate any user. CISA confirmed exploitation, with an August 21 deadline.
P.29An unauthenticated attacker can inject through a GitLab GraphQL directive and delete public projects and user data. CVSS 9.4, patched in 19.2.4.
P.30Two critical unauthenticated vCenter flaws let attackers skip login and run code on the management plane. What's affected, and how to check for compromise.
P.31A stack overflow in Windows DNS Server runs code from one crafted packet, no auth, no clicks. Not seen exploited yet, but shaped like a bug that will be.
P.32A use-after-free in Windows' AFD.sys networking driver is on CISA's KEV list with an August 25 deadline. Lazarus has used it on defense targets since July.
P.33One unauthenticated HTTP request reloads Cisco ASA and FTD devices with remote-access VPN on. CISA's deadline was August 14. What's affected, and the fix.
P.34An unauthenticated attacker can inject SQL through Metabase's password-reset flow and gain full admin. CVSS 10.0, on CISA's KEV list since August 11.
P.35A heap-buffer bug in Progress Kemp LoadMaster's escape_quotes() lets an unauthenticated attacker run commands on the load balancer. CISA confirmed Aug 7.
P.36A deserialization flaw in TeamCity's agent polling protocol lets an attacker with no credentials run commands as the build server. CISA confirmed August 5.
P.37Researchers showed an untrusted GitHub issue reaching CI runner secrets in Claude Code, Gemini CLI, and Codex. Gemini CLI's flaw scored a perfect 10.0.
P.38A one-line control-flow change meant to patch CVE-2026-29146 quietly broke Tomcat's cluster encryption. CISA confirmed exploitation on August 4. The fix.
P.39CISA added CVE-2026-9198 to its KEV catalog on August 4. Unlike July's Langflow flaw, this one needs no credentials at all. The chain, and what to patch.
P.40N-able's first N-central auth bypass fix was incomplete. The leftover gap is now exploited, pivoting from one RMM server into every managed endpoint.
P.41CVE-2026-20079 is a 10.0 CVSS Cisco Secure FMC authentication bypass disclosed before the hardcoded-password bug. Why it matters, and what to patch.
P.42CISA flagged two FortiSandbox command injection bugs as exploited on July 16. Chained with a third, they reach root with no credentials. What to patch.
P.43A static credential baked into on-prem Cisco Secure FMC is being exploited. Who's affected, why a 5.3 CVSS undersells it, and what to check right now.
P.44Two CVSS 10.0 zero-days in Joomla page builder plugins are being exploited to plant webshells and create rogue admins. What's affected, and what to patch.
P.45CISA added CVE-2025-68686, a FortiOS SSL-VPN symlink persistence bypass, on July 27. It only bites devices compromised earlier and never forensically cleaned.
P.46CISA added CVE-2026-16812, an unauthenticated command injection in Arista VeloCloud Orchestrator scored 10.0, on July 27. Who's affected, and what's patched.
P.47CVE-2026-20262 lets an authenticated attacker write files on Catalyst SD-WAN Manager and escalate to root. It's on CISA's KEV list, deadline already passed.
P.48pnpm before 10.34.0 and 11.4.0 could send your unscoped npm token to whatever registry a repo's .npmrc named. How it works, and how to check and fix.
P.49A default WordPress install can be taken over by one anonymous HTTP request. wp2shell chains two core flaws into pre-auth RCE. What's affected, and the fix.
P.50A CVSS 9.8 unauthenticated flaw in Oracle E-Business Suite Payments has been exploited since late June, with roughly 950 instances still exposed.
P.51CVE-2026-35273 was exploited as a zero-day for two weeks before patching. Nissan, Kubota, Aflac Japan, and dozens of universities are still disclosing.
P.52Two chained SMA1000 flaws, an unauthenticated CVSS 10.0 SSRF and a post-auth code injection, are under active attack. Affected firmware and the fix.
P.53Microsoft fixed 622 CVEs on July 14, its largest ever, including exploited zero-days in SharePoint and AD FS, plus the RC4 Kerberos rollback switch removal.
P.54A critical authorization bypass in n8n-MCP let one tenant read, delete, or destroy another tenant's workflow backups. Who's affected, and what to patch.
P.55A forged OIDC token in SimpleHelp RMM lets an unauthenticated attacker create an admin and reach every managed endpoint. CISA added it on June 29.
P.56CISA added Langflow's authorization bypass to its KEV catalog on July 7 with a July 10 deadline. How it works, who's affected, and why rotating keys matters.
P.57An unauthenticated SSRF in Cisco Unified CM is being exploited to write files, plant a webshell, and reach root. The chain, and how to patch or work around.
P.58A race in the Linux kernel's epoll subsystem lets any local user reach root, with an exploit that works 99% of the time. Who's affected, and what to patch.
P.59Auth bypass, account takeover, and RCE across JetBrains Hub, IntelliJ IDEA, and Code With Me are now patched. What each CVE does and which build fixes it.
P.60A use-after-free in Linux KVM, present since 2010, lets an untrusted guest crash or compromise its host. Fixed kernels shipped July 4. Who's exposed.
P.61Adobe disclosed nine ColdFusion and Campaign Classic flaws on July 1, seven scoring CVSS 10.0. One path traversal was exploited within hours. What to patch.
P.62CISA added the SharePoint deserialization bug CVE-2026-45659 to its KEV catalog on July 1, with a July 4 deadline. Who's affected, and what to patch now.
P.63Three 10.0-severity UniFi OS flaws chain into unauthenticated root, and a Mirai botnet is already using them. What's affected, and how to patch today.
P.64Node.js patched 12 CVEs across v22, v24, and v26 on June 18. Two are auth bypasses, and undici's queue poisoning can hand back the wrong response.
P.65A CVSS 9.3 stored XSS lets a malicious PostgreSQL server inject JavaScript into your pgAdmin tab. Versions 6.0 to 9.15 are affected; v9.16 is the fix.
P.66June 2026 Patch Tuesday is the year's largest: 206 CVEs, 37 Critical, three zero-days, and a Splunk RCE already under attack. What to patch first.
A comprehensive security briefing covering February 2026's most critical vulnerabilities including OpenSSL RCE, Foxit PDF Reader zero-days, Chrome V8 exploits, and Linux kernel privilege escalation.
A CVSS 10.0 pre-auth RCE in React Server Components was exploited within two days of disclosure. Here's the patch guidance and what changed.