Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability News

Microsoft Teams for Android Vulnerability Exposes Sensitive Information

Microsoft has released a security update for CVE-2026-65812, a vulnerability in Microsoft Teams for Android that could allow an authorized attacker to disclose sensitive information, including user credentials. Microsoft published the flaw on September 8, 2026, and rates it as...

New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers. cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a...

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The update will reach users over the coming days and weeks and includes...

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product's web interface to siphon off sensitive information without ever needing valid credentials. The flaw, tracked as CVE-2026-26084, stems...

Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already exploited in attacks. This massive patch follows the recent Microsoft update on artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic...

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website. Tracked as CVE-2026-84393 and...

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used...

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems. The flaws affect Dell Secure Connect Gateway 5.0 Appliance...

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note. The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP...

Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials

A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud development environments. The attack involved unauthorized changes to Coder’s Cloudflare infrastructure, allowing an unidentified threat actor to redirect...

Latest News

Latest News