Oracle Critical Security Patch Update, September 2026 Review

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, total 104 (15%) vulnerabilities … Continue reading “Oracle Critical Security Patch Update, September 2026 Review”

Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)

Cisco released a security advisory about a critical-severity vulnerability in Cisco Secure Email Gateway. Tracked as CVE-2026-76461, the vulnerability is being exploited in the wild. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary commands with root privileges on the underlying operating system. Cisco TAC team discovered the vulnerability. CISA acknowledged the … Continue reading “Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)”

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)

Google released security updates to address 230 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-87491, is being exploited in the wild. This is an out-of-bounds write vulnerability in the V8 JavaScript engine. The vulnerability was discovered and reported by Jihyeon Jeong (Compsec Lab, Seoul National University /Research Intern). CISA acknowledged the … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)”

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including … Continue reading “Microsoft Patch Tuesday, September 2026 Security Update Review”

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google released security updates to address 12 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-85046, is being exploited in the wild. CVE-2026-85046 is a type confusion vulnerability in the V8 JavaScript engine. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)”

Langflow Remote Code Execution Vulnerability Exploited in Attacks (CVE-2026-0768)

A vulnerability impacting Langflow is being exploited in the wild. Tracked as CVE-2026-0768, the vulnerability has a critical severity rating with a CVSS score of 9.8. Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code on affected installations of Langflow. Peter Girnus, William Gamazo Sanchez, and Alfredo Oliveira of Trend Research have discovered and reported the vulnerability to Langflow.

Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)

Veeam released a security advisory addressing a vulnerability affecting Veeam ONE. Tracked as CVE-2026-65641, the vulnerability has a critical severity rating with a CVSS score of 9.3. Successful exploitation of the vulnerability may allow an unauthenticated network attacker to coerce SMB authentication from the service account.

PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)

PaperCut released an Urgent Security Advisory to address two actively exploited vulnerabilities, tracked as CVE-2026-82078 & CVE-2026-81578, impacting all versions of PaperCut NG and PaperCut MF. When chained together, these vulnerabilities can enable pre-authentication remote code execution in the PaperCut Application Server. The flaw originates from a request-confusion/authorization gap. The vendor has mentioned in their … Continue reading “PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)”