This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
Tag: Vulnerability
MSNightmare Releases New PoC for DoS Vulnerability in Windows Defender
Security researcher MSNightmare, also known as Nightmare-Eclipse, has released BigDiskBuster, a proof-of-concept denial-of-service technique designed to…
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security…
Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware
Hackers are exploiting a critical cPanel and WHM flaw to place Mirai malware on exposed servers, extending a botnet threat normally associated with…
MSNightmare has Released a Windows Defender Update DoS Vulnerability Called BigDiskBuster
Security researcher MSNightmare, also known as Nightmare-Eclipse, has released BigDiskBuster, a proof-of-concept denial-of-service technique designed to…
Gyazo Server Vulnerability Targeted to Steal Millions of User Records
Gyazo, an image-sharing platform, has confirmed a breach after attackers exploited a vulnerability in its upload server, gaining unauthorized access to…
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of…
Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file…
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the…
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications…
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
CISA Upgrades Vulnerability Reporting Platform
The US Cybersecurity and Infrastructure Security Agency (CISA) announced on September 17, 2025, the launch of VINCE-NT (Vulnerability Information and…
Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+
Cisco zero-day goes straight to root BambooToken branches into Linux CenterPoint breach claim hits 7M+ Get the show notes here:…
CISA Upgrades Vulnerability Reporting Platform with More Automation
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could…
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
Google says a Pixel modem zero-day was under targeted exploitation. CISA has added CVE-2026-58704 to KEV as users are urged to patch.
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.…
