CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)

Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to bypass authentication. Cisco mentioned in their advisory that they are aware of active exploitation of this vulnerability. CISA acknowledged the active exploitation of the vulnerability by adding to its … Continue reading “CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)”

Oracle Critical Security Patch Update, September 2026 Review

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, total 104 (15%) vulnerabilities … Continue reading “Oracle Critical Security Patch Update, September 2026 Review”

Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)

Cisco released a security advisory about a critical-severity vulnerability in Cisco Secure Email Gateway. Tracked as CVE-2026-76461, the vulnerability is being exploited in the wild. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary commands with root privileges on the underlying operating system. Cisco TAC team discovered the vulnerability. CISA acknowledged the … Continue reading “Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)”

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)

Google released security updates to address 230 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-87491, is being exploited in the wild. This is an out-of-bounds write vulnerability in the V8 JavaScript engine. The vulnerability was discovered and reported by Jihyeon Jeong (Compsec Lab, Seoul National University /Research Intern). CISA acknowledged the … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)”

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including … Continue reading “Microsoft Patch Tuesday, September 2026 Security Update Review”

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google released security updates to address 12 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-85046, is being exploited in the wild. CVE-2026-85046 is a type confusion vulnerability in the V8 JavaScript engine. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)”

Langflow Remote Code Execution Vulnerability Exploited in Attacks (CVE-2026-0768)

A vulnerability impacting Langflow is being exploited in the wild. Tracked as CVE-2026-0768, the vulnerability has a critical severity rating with a CVSS score of 9.8. Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code on affected installations of Langflow. Peter Girnus, William Gamazo Sanchez, and Alfredo Oliveira of Trend Research have discovered and reported the vulnerability to Langflow.