Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability News

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0 through 3.0.23 and require a...

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the "Noble Numbat" long-term support release, delivering a fresh installation image packed with the latest security patches, bug fixes, and an upgraded hardware enablement stack built...

GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution

GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that could enable arbitrary file reads and credential theft. A separate high-severity issue in GitLab Enterprise Edition could allow authenticated attackers...

Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection

Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored cross-site scripting, authorization bypass, and SQL injection in certain configurations. The vulnerabilities were disclosed on September 8, 2026....

CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026. CVE-2026-19490 affects Citrix NetScaler ADC and...

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor...

Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48...

MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks

A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to zero-click attacks. The flaw, tracked as CVE-2026-85061 and GitHub Security Advisory GHSA-jrc7-96c5-q579, affects maplibre-gl versions 6.4.0 and...

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code remotely on affected devices. The update, published on September 8, includes security patch levels dated 2026-09-01 and 2026-09-05. Android users should...

CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild

The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able's N-central remote monitoring and management platform to its Known Exploited Vulnerabilities catalog, confirming that attackers are actively abusing the bug against real-world targets. The vulnerability, tracked as...

Latest News

Latest News