search
CVE
Trends
- 1Study: High-Mileage Electric Cars More Reliable Than PetrolβΌ"High-mileage electric cars are more reliable than petrol ones, study finds" # Cars # Vehicles # EV # ElectricVehicles h
A study reported by The Guardian has found that used, high-mileage electric vehicles are more reliable than equivalent petrol cars, challenging a common assumption that EV durability drops sharply with age and mileage. The finding is being shared widely among drivers and environmental commentators, with many pointing to it as further evidence that electric cars are a dependable long-term alternative to combustion engines.
- 2Bitget reportedly loses $350M in Bitcoin to North Korean hackersβSeverity: CRITICAL β Bitget exchange lost $350M+ in Bitcoin to a suspected North Korean breach. No CVE or technical deta
Crypto exchange Bitget is reported to have lost more than $350 million in Bitcoin in a breach attributed to North Korean hackers. No technical details or CVE have been released about how the attack was carried out. The exchange has reportedly resumed withdrawals, but security watchers are urging caution while the full picture remains unclear.
- 3Apple patches CoreGraphics flaw exploited in targeted attacksβπ€ Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics affecting older iOS/iPadOS/macOS versions. Proces
Apple has released patches for CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting older versions of iOS, iPadOS and macOS. Processing a maliciously crafted file could allow arbitrary code execution. Apple says the flaw may already have been exploited in targeted attacks, prompting users of older devices to update promptly.
- 4Citrix confirms two actively exploited NetScaler zero-day flawsβTwo Citrix NetScaler zero-day RCE flaws are under active exploitation. Citrix confirmed CVE-2026-88771 and CVE-2026-8877
Citrix has confirmed two zero-day remote code execution vulnerabilities in its NetScaler application delivery products, tracked as CVE-2026-88771 and CVE-2026-88772, both under active exploitation. The company has released patches, and security researchers are urging administrators to update internet-facing NetScaler and VPN appliances immediately, warning that unpatched systems could allow attackers to run code remotely.
- 5Check Point VPN flaw under active attack days after patchβCheck Point confirms active attacks on CVE-2026-85102 began three days after patches dropped. CISA sets federal deadline
Check Point has confirmed that attackers began exploiting CVE-2026-85102, a vulnerability in its VPN products, just three days after patches were released. CISA has added the flaw to its exploited-vulnerabilities catalog and given federal agencies a September 25 deadline to apply the fix. Security teams are urged to patch immediately as exploitation continues.
- 6Citrix NetScaler zero-days under active exploitationβTwo Citrix NetScaler zero-day flaws enabling remote code execution are reportedly under active exploitation. No CVE or p
Two zero-day vulnerabilities in Citrix NetScaler appliances, both allowing remote code execution, are reportedly being actively exploited by attackers. No CVE identifiers or official patches have been released yet. Administrators running NetScaler as VPN or application delivery controllers are urged to apply interim mitigation steps and watch for an official Citrix advisory.
- 7Citrix NetScaler flaws actively exploited, thousands exposedβπ€ Citrix NetScaler ADC/Gateway: CVE-2026-88771 + CVE-2026-88772 (unauth RCE) exploited in the wild. The first hits defau
Two unauthenticated remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in the wild against Citrix NetScaler ADC and Gateway appliances. The first affects default configurations, while the second requires DTLS, which is enabled by default on VPN virtual servers. Patches are available, the flaws have been added to CISA's Known Exploited Vulnerabilities catalog with a federal patching deadline of September 30, and Shadowserver reports over 23,000 exposed instances online.
- 8Oracle PeopleSoft flaw mass-exploited by ShinyHuntersβπ€ Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. Attack
Attackers are mass-exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, rated CVSS 9.8 as an unauthenticated remote code execution flaw. The ShinyHunters group is reportedly using URL-encoding tricks to bypass WAF rules before deploying web shells. Google has warned of global targeting across multiple sectors, and renewed exploitation waves are drawing fresh attention from security teams.
- 9CISA adds two actively exploited Citrix NetScaler flaws to catalogβΌβ οΈ CRITICAL: CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA added CVE-2026-88771 and CVE-2026-88772 affec
CISA has added CVE-2026-88771 and CVE-2026-88772, two vulnerabilities affecting Citrix NetScaler, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Both flaws are described as remote code execution vectors, meaning attackers can potentially run malicious code on affected appliances. Security teams are urged to check whether they run NetScaler and apply patches immediately, as exploited edge devices are a common entry point for intrusions.
- 10Citrix patches two actively exploited NetScaler zero-daysβπ¨ CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37
Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.
- 11Critical Zero-Day Exploited in Arista VeloCloud Orchestratorβ(diesec.com) Critical Zero-Day Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation In brief - This
Security researchers report a critical zero-day vulnerability, tracked as CVE-2026-93952, in the Arista VeloCloud Orchestrator. The flaw allows unauthenticated attackers to access privileged functions, and it is reportedly being actively exploited in the wild. Defenders are being urged to review exposure of VeloCloud Orchestrator deployments and apply mitigations as details emerge.
- 12CISA Flags Critical WSO2 and Adobe Commerce Flaws Under Active Exploitationβπ΅ THREAT INTELLIGENCE WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Vulnerability | CRITICAL CVE
The US Cybersecurity and Infrastructure Security Agency has added two critical vulnerabilities, affecting WSO2 and Adobe Commerce, to its Known Exploited Vulnerabilities catalog after both flaws were observed being used in real-world attacks. The inclusion signals that organizations running the affected software should treat patching as urgent, as the catalog formally requires federal agencies to remediate listed flaws within set deadlines.
- 13Exploited WordPress vulnerability affects all versions since 4.7.0βπ΄ EXPLOITED WordPress core CVE-2026-87902 is being exploited to run code on sites, and it affects every release back to
A WordPress core vulnerability tracked as CVE-2026-87902 is being actively exploited to run code on websites without requiring login. The flaw reportedly affects every release going back to version 4.7.0. CISA has added it to its catalog and is requiring federal agencies to patch by September 28. Administrators are being urged to update to WordPress 7.1.2 immediately.
- 14Hackers exploit Citrix NetScaler zero-day to deploy web shellsβ"Hackers exploit Citrix NetScaler zero-day to deploy web shells" "[...] Cybersecurity firms say attackers exploited the
Cybersecurity firms report attackers are exploiting a previously unknown vulnerability in Citrix NetScaler, tracked as CVE-2026-88772, to deploy custom web shells and tunneling malware. The attackers reportedly gain root access, steal credentials, and move into victims' internal networks. Security teams are urged to check exposed NetScaler appliances for signs of compromise and apply patches as they become available.
- 15EU Reporting Rules Put Linux Vulnerability Management Under PressureβThe # EU Is About to Make # Linux 's # Vulnerability Management Problem Harder to Ignore More # CVE , sprawling deployme
The EU's upcoming cybersecurity reporting requirements are set to expose long-standing weaknesses in how Linux vulnerabilities are tracked and patched. The number of published CVEs has grown sharply, and sprawling deployments make it harder for organisations to prove which systems are affected. Under the new rules, patching alone may not suffice: teams will need documented evidence of their vulnerability handling, turning compliance into a pressing operational challenge for Linux users across Europe.
- 16D-Link DIR-895L routers hit by unpatched critical flawβΌD-Link DIR-895L routers hit by CVE-2026-100740, a CVSS 9.9 vulnerability. No patch coming: the series reached end-of-lif
A critical vulnerability, CVE-2026-100740 with a CVSS score of 9.9, has been reported in D-Link DIR-895L routers. The company will not release a fix because the product line reached end-of-life in 2019. Security watchers are warning that affected devices remain exposed, with no vendor support available, and are urging users of the model to consider replacement or mitigation.
- 17Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3βCritical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a pa
A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.
- 18Critical flaw in Apache OpenOffice lets documents run codeβΌCVE-2026-59265: A critical flaw in Apache OpenOffice's Java integration lets a crafted untrusted document execute arbitr
A critical vulnerability, tracked as CVE-2026-59265, has been found in Apache OpenOffice's Java integration. Opening a crafted untrusted document can allow arbitrary code execution on the affected machine. Versions 4.1.16 and earlier are affected, and no exploitation has been confirmed so far. A fix is expected in version 4.1.17; users are advised to disable the Java runtime as an interim measure.
- 19SourceHut account takeover flaw found in build log renderingβSourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 https:// reddthat.com/post/74210240
A security vulnerability in SourceHut, tracked as CVE-2026-92973, reportedly allowed account takeover through malicious build logs. The flaw involved cross-site scripting in the ansi2html.py script used to render logs, letting attackers inject code that could hijack sessions. Developers and security researchers are discussing the disclosure and how the issue was handled.
- 20Microsoft tracks unauthenticated command injection flaw in mail serversβΌUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft is tracking CVE-2026-73570, a newly disclosed vulnerability that allows unauthenticated command injection on internet-facing mail servers. Because the flaw can be exploited without credentials and targets exposed systems, security teams are watching for signs of exploitation and awaiting patch guidance. Admins of mail infrastructure are being urged to assess exposure while details and fixes are confirmed.
- 21Citrix NetScaler flaw CVE-2026-88771 draws security attentionβCVE-2026-88771: Citrix NetScaler ADC & Citrix NetScaler Gateway Vulnerability
A vulnerability tracked as CVE-2026-88771 has been reported affecting Citrix NetScaler ADC and Citrix NetScaler Gateway, the widely used application delivery and remote access products. Security researchers are flagging the flaw, and organisations running NetScaler appliances are likely to face questions about exposure and patching. Details on severity and exploitation have not been confirmed, so administrators should follow official Citrix advisories.
- 22Cenovus Energy stock outpaces broader market gainsβΌCenovus Energy (CVE) Beats Stock Market Upswing: What Investors Need to Know
Cenovus Energy shares have risen faster than the wider stock market, drawing attention from investors watching the Canadian oil and gas producer. The move comes amid broader strength in the market, with commentary focused on what the outperformance means for investors, including the company's position in the energy sector and its outlook going forward.
- 23Citrix issues security bulletin for eight NetScaler vulnerabilitiesβCitrix has finally spoken. Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2
Citrix has released a long-awaited security bulletin for its NetScaler ADC and NetScaler Gateway products, covering eight vulnerabilities tracked as CVE-2026-88771 through CVE-2026-88778. Administrators of the widely used application delivery and remote access products are being urged to review the advisory and apply the relevant patches, as NetScaler flaws have historically been heavily exploited.
- 24Three unpatched critical flaws disclosed in LightLLMβΌπ¨ LightLLM Mass Disclosure β 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) β unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
- 25GitLab Rushes Emergency Fixes for Exploited AI Gateway FlawsβGitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws GitLab released emer
GitLab has released emergency security patches addressing two critical vulnerabilities: a remote code execution flaw in its AI Gateway, tracked as CVE-2026-90970, and a maximum-severity path traversal issue. Both flaws are reportedly being actively exploited, prompting the unusually urgent rollout. Security teams are being urged to apply the updates immediately, with the disclosures fueling renewed discussion about securing AI infrastructure.
- 26GitLab patches critical AI Gateway flaw allowing command executionβπ€ GitLab patches CVE-2026-90970 (CVSS 9.9, critical) in the AI Gateway: a logged-in user with Duo Agent Platform access
GitLab has released fixes for CVE-2026-90970, a critical vulnerability (CVSS 9.9) in its AI Gateway. An authenticated user with access to the Duo Agent Platform can run commands on the gateway. Only self-hosted gateway deployments are affected. Patches are available in versions 19.2.4, 19.3.2 and 19.4.1, and administrators are urged to update immediately.
- 27Critical CVE-2026-71885 flagged in Bouncy Castle BC-JavaβCRITICAL CVE-2026-71885 in Bouncy Castle BC-JAVA ( https:// radar.offseq.com/threat/cve-20 26-71885-cwe-295-improper-cer
Security teams are being alerted to CVE-2026-71885, a critical vulnerability in Legion of the Bouncy Castle's BC-Java cryptography library. The flaw involves improper certificate validation (CWE-295), meaning affected Java applications could trust forged or invalid certificates, opening the door to man-in-the-middle attacks. Given how widely BC-Java is embedded in Java infrastructure, administrators are advised to track for patches and assess exposure.
- 28Cisco SD-WAN Manager flaw actively exploited, admins urged to patchβAttackers exploit CVE-2026-76504, a 9.8 authentication bypass in Cisco SD-WAN Manager that grants admin API access. Patc
Attackers are exploiting CVE-2026-76504, a critical authentication bypass vulnerability in Cisco SD-WAN Manager with a severity score of 9.8. The flaw allows unauthenticated access to the administrative API, potentially handing attackers full control of affected systems. Security sources say it is being actively exploited and are urging organisations to apply Cisco's patch immediately.
- 29Bouncy Castle Java library hit by new signature verification flawβCVE-2026-71887 | Legion of the Bouncy Castle BC-JAVA https:// radar.offseq.com/threat/cve-20 26-71887-cwe-347-improper-v
A new vulnerability, CVE-2026-71887, has been disclosed affecting the Legion of the Bouncy Castle cryptography library for Java. The flaw is classed as CWE-347, improper verification of cryptographic signature, meaning the library may accept signatures it should reject. Security researchers are sharing the advisory and tracking potential impact on Java applications relying on the widely used library.
- 30Op-Ed Critiques Jane Schoenbrun's 'Eroticverse' as Self-IndulgentβΌOp-Ed: Jane Schoenbrunβs Self-Indulgent Movie Eroticverse
InSession Film has published an opinion piece criticizing filmmaker Jane Schoenbrun, describing her body of work as a 'self-indulgent movie Eroticverse.' The essay takes issue with what it portrays as self-absorbed storytelling in Schoenbrun's films, adding to ongoing debate about her distinctive, internet-inflected style. Reaction so far appears limited, and the piece's specific arguments are not detailed beyond the headline.
- 31WordPress plugin Jeg Kit vulnerable to stored XSS flawβJeg Kit for Elementor, a WordPress add-on on 300,000+ sites, has an unauthenticated stored XSS: a stranger can plant Jav
Jeg Kit for Elementor, a WordPress add-on installed on more than 300,000 sites, contains an unauthenticated stored cross-site scripting vulnerability, tracked as CVE-2026-100180. An attacker can inject JavaScript through a blog comment, which then runs in visitors' browsers. All versions up to 3.2.19 are affected, and site owners are urged to update to version 3.2.20 immediately.
- 32Critical Stirling PDF flaw with public exploit demands urgent patchβDetails and a PoC are public for CVE-2026-85714, a 9.1 Stirling PDF RCE via crafted SQL import. Upgrade to version 2.13.
A critical remote code execution vulnerability in Stirling PDF, tracked as CVE-2026-85714 and rated 9.1, has full technical details and a proof-of-concept exploit publicly available. The flaw stems from a crafted SQL import affecting the bundled H2 database. Administrators are urged to upgrade to version 2.13.2 immediately, as the public exploit makes attacks likely.
- 33New analysis warns of economic doom approaching for RussiaβNew Video: Economic Doom Approaching for Russia | Ukraine War Poltical News Update https://www.youtube.com/watch?v=CVev9
A new geopolitical news update argues that Russia's economy is heading toward serious trouble as the war in Ukraine continues. The piece points to Western sanctions and the strain of a war economy under Vladimir Putin as key pressures, framing the country's economic outlook as increasingly bleak.
- 34Zoho's poor trust score raises patching concernsβZoho holds a D trust score with 38 CVEs, 2 in CISA KEV, and 100% unpatched. SQLi and XSS dominate. Patch or pivot. https
A cybersecurity assessment gives Zoho a D trust score, citing 38 known vulnerabilities, two of which are listed in CISA's Known Exploited Vulnerabilities catalog, with none of the flaws patched. SQL injection and cross-site scripting account for most of the reported issues. Security commentators are urging organizations using Zoho products to either apply fixes promptly or reconsider the vendor.
- 35Critical Zammad vulnerability CVE-2026-102490 allows remote code executionβπ΄ New security advisory: CVE-2026-102490 affects Zammad. β’ Impact: Remote code execution or complete system compromise p
A new security advisory reports that CVE-2026-102490 affects Zammad, the open-source helpdesk and customer support platform. According to the advisory, the flaw could allow remote code execution and full system compromise, letting attackers gain complete control of affected servers. Administrators are urged to patch immediately or isolate exposed systems until updated.
- 36Infosec community shares joke artwork 'Several vulnerabilities'βI call this piece "Several vulnerabilities". # infosec # CVE
A member of the Australian information security community posted a piece titled 'Several vulnerabilities', tagged with infosec and CVE. The post is a light-hearted commentary circulating among cybersecurity practitioners, who often swap jokes about the steady stream of published vulnerabilities and advisories in their field.
- 37Critical LightLLM flaw exposes AI servers to remote code executionβπ¨ CVE-2026-103041 β CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 38Apple zero-day exploited in targeted attacksβΌπ΄ Apple CVE-2026-86950 β zero-day exploited in targeted attacks A CoreGraphics out-of-bounds write can lead to arbitrary
Apple is dealing with a newly disclosed zero-day vulnerability, CVE-2026-86950, affecting CoreGraphics on iPhone, iPad and Mac. The out-of-bounds write flaw can allow arbitrary code execution, and Apple has confirmed it was exploited in what the company describes as 'extremely sophisticated' targeted attacks. Security updates are rolling out, and users are advised to install them promptly.
- 39GitLab AI Gateway flaw CVE-2026-90970 enables remote code executionβGitLab AI Gateway flaw CVE-2026-90970 enables RCE https:// fawkes.rocks/2026/10/02/gitlab -ai-gateway-flaw-cve-2026-9097
A security vulnerability tracked as CVE-2026-90970 has been disclosed in GitLab's AI Gateway, reportedly allowing remote code execution on affected systems. GitLab's AI Gateway sits in front of the company's AI-powered features, so a flaw there could expose organizations using the platform's AI tooling. Administrators are being urged to check their deployments and apply patches. Details on affected versions and exploitation are still limited.
- 40Apple Patches Actively Exploited Zero-Day in iOS and macOSβΌApple Patches Actively Exploited Zero-Day in iOS 26, iPadOS 26 and macOS Apple patched a zero-click vulnerability (CVE-2
Apple has released emergency security updates for iOS 26, iPadOS 26 and macOS 26 to fix a zero-click vulnerability, tracked as CVE-2026-86950, that was already being exploited in the wild. The flaw allows remote code execution and theft of user data without any interaction from the victim, and security experts are urging all iPhone, iPad and Mac users to install the patches immediately.