2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.
P0
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.
P20
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-31583.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-53182.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-45930.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-46227.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74465.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 15:10 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74565.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-38416.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.
P20
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-72463.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.
P5
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-64265.
P15
2026-09-14 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-14 14:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-31719.
P15
2026-09-13 14:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-13 14:45 UTC
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
P15
2026-09-13 12:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-13 13:30 UTC
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]
P5
2026-09-12 15:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 17:30 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization
P80
2026-09-12 14:14 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-12 14:20 UTC
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
P15
2026-09-12 11:10 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-12 11:10 UTC
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
P25
2026-09-12 09:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-12 10:00 UTC
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the
P15
2026-09-11 19:08 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 19:15 UTC
Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which K…
P5
2026-09-11 18:27 UTC
Security Journalism
Dark Reading · Agam Shah · indexed 2026-09-14 13:20 UTC
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
P25
2026-09-11 17:09 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 17:20 UTC
Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < 2026-03-23 Please refer to the article below for the most u…
P5
2026-09-11 16:37 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 16:40 UTC
Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora failover, IAM authentication, and automated SQL query caching for applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB. We identified CVE-2026-18061, an improper restriction of XML external entity (XXE) refer…
P5
2026-09-11 16:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 17:25 UTC
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
P5
2026-09-11 16:11 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-11 16:30 UTC
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
P0