Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability News

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for Linux, with the update...

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The patches arrived on September 14, 2026, through iOS 27, iPadOS...

cPanel LiteSpeed Web Server Vulnerability Allows Shared Server Users to Gain Root-Level Access

cPanel has issued an urgent security advisory warning that a critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privileged shared-hosting user to gain root-level access to an affected server. Administrators are urged to upgrade LiteSpeed Enterprise to...

Cisco Secure Email Gateway 0-day Vulnerability Actively Exploited in the Wild to Run Malicious Code

Cisco has issued an urgent warning regarding an actively exploited zero-day vulnerability in its Secure Email Gateway appliances that allows remote, unauthenticated attackers to execute arbitrary commands with highest-level root privileges. Tracked as CVE-2026-76461, the flaw stems from a severe...

Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials

Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code secrets. F5 honeypot sensors recorded 807 session-grouped attacks and about 32,000 raw events in...

Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console

Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access information stored on the console. Tracked as CVE-2026-82079, the flaw affects firmware earlier than 23.0.0 and resides...

New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks

A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control. Tracked as CVE-2026-43502, the flaw was demonstrated through an exploit called ZcopyReaper by security researchers at NebuSec. This vulnerability affects the Reliable...

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the largest publicly disclosed payment made through GitHub’s...

NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected

The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near term. Organizations using affected Check Point gateways, management systems, or...

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations. The issue...

Latest News

Latest News