Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of [β¦]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 [β¦]
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the productβs MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments [β¦]
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September [β¦]
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful [β¦]
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September [β¦]
Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities can lead to unauthorized access, root-level code execution, credential theft, network reconnaissance, and malware deployment. Critical Cisco FMC Flaws The most critical issue is identified as CVE-2026-20079, a critical authentication-bypass vulnerability with a [β¦]
Check Point has announced two critical vulnerabilities in its VPN technology that could allow unauthenticated remote attackers to execute arbitrary code on affected security gateways under certain conditions. These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, impact both Remote Access VPN and Site-to-Site VPN functionalities. Check Point said its internal research team discovered and resolved these [β¦]
A recently disclosed integer-underflow vulnerability in Appleβs modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Appleβs newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer [β¦]
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The [β¦]
A critical vulnerability has been identified in the Fortinet FortiPAM Chrome extension that could allow a malicious website to manipulate browser proxy settings, open tabs at the attackerβs discretion, and record activity within those tabs. This issue, tracked as CVE-2026-84388 and rated with a CVSS score of 9.1, impacts an extension that facilitates privileged access [β¦]
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in GitHub advisory GHSA-jrc7-96c5-q579. This vulnerability affects maplibre-gl versions 6.4.0 and earlier and is resolved in version 6.4.1. Critical MapLibre GL JS Flaw The issue lies in the DOM.sanitize() function in src/util/dom.ts, which [β¦]
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses [β¦]