FR
live
archive

All articles

CVE-2026-6471 lets a PostgreSQL replication account run code as the system user

Present since PostgreSQL 9.4 in 2014, CVE-2026-6471 (CVSS 7.2) lets an account holding the REPLICATION attribute load an arbitrary library through logical decoding and run code as the server’s operating-system user. Fixed on August 13, 2026 via the output_plugin_libraries parameter: update and make sure your output plugins are explicitly allowlisted.

A backdoor compiled into HAProxy intercepts traffic and vanishes from the load balancer’s counters

Rapid7 Labs documents “ted”, an implant compiled directly into HAProxy 2.8.12 at two South Korean companies that intercepts web traffic and erases its own connections from the load balancer’s counters. It requires a prior compromise of the host — verify the integrity of your edge binaries and watch connection counters instead of waiting for an HAProxy patch.

Claude Fable 5.1 cuts prices by a quarter and promises zero retention for enterprises

On September 1, 2026, Anthropic launched Claude Fable 5.1 and Claude Mythos 5.1 — the same model split into two safeguard levels — with an estimated 25% price cut and ’Enterprise Frontier Safeguards’ storage that keeps data on the customer side. For a CISO or CTO, it is the first model where compliance becomes the headline argument rather than the benchmark.

A CVSS 10 flaw turns Kestra into an unauthenticated root shell

On September 2, 2026, CISA added CVE-2026-49869 to its KEV catalog: a CVSS 10 command injection in the open-source orchestrator Kestra, caused by a path comparison that lets any endpoint ending in ’configs’ through. Move to 1.0.45 or 1.3.21 before the September 5 federal deadline, then check whether the instance was already used as an entry point.

Greg Kroah-Hartman sees a rough Linux 7.3 cycle under an AI patch flood

On September 2, 2026, Greg Kroah-Hartman warned that the Linux 7.3 cycle is shaping up to be ’rough’: his USB subsystem queue is overflowing with AI-generated patches, while the kernel approaches 2,000 CVEs per release. For distros and infrastructure teams, that means prioritizing real security fixes and bracing for a stable release around October 18.

Cisco ships seven IOS XR hardening CVEs, two reach CVSS 9.8

On September 2, 2026, Cisco bundled seven internally discovered IOS XR vulnerabilities into seven CVEs grouped by CWE class, including two at CVSS 9.8 that affect every release of the core-router operating system. Apply the SMUs in your maintenance windows rather than waiting for releases 26.2.2 and 26.3.1.

GitHub CLI’s signing key expires September 5, breaking Linux package installs

On Saturday, September 5, 2026, the PGP key that signs GitHub CLI’s APT and RPM repositories expires, and any gh install done before April 8 without a keyring update will start failing. Check your local keyring before the deadline and add the replacement key 7F38BBB59D064DBCB3D84D725612B36462313325.

Proxmox moves enterprise support to 24/7 and opens a North American subsidiary

On September 2, 2026, Proxmox announced around-the-clock enterprise support starting October 19 and the launch of Proxmox North America Inc. in Kingston, Ontario, on the back of a 2.3 million-server installed base. For organizations weighing a move off VMware after Broadcom’s price hikes, the support objection just fell away.

Chrome patches its sixth exploited zero-day of 2026, a V8 type confusion

On September 4, 2026, Google shipped an emergency Chrome update fixing CVE-2026-85046, a type confusion in the V8 engine already exploited in the wild and rated 8.8 on the CVSS scale. Update to Chrome 152.0.7977.82 or later and check every Chromium browser in your fleet, including Edge, Brave and Opera.

CloudFront flat-rate plans become manageable through the API and IaC

On September 3, 2026, AWS opened programmatic management of CloudFront flat-rate plans through the new PricingPlanManager API, the CLI, CloudFormation and the CDK. Teams can now codify subscribing, changing tiers and cancelling a no-overage monthly price, with a two-phase approval that prevents unintended billing.

Kubernetes 1.37 scales queue consumers to zero replicas with the HPA

On September 2, 2026, Kubernetes 1.37 enabled horizontal scaling to zero replicas by default (Beta) whenever an object or external metric, such as a queue length, allows it. Queue consumers and batch processors can release reserved CPU and GPU while idle, provided they accept the cold-start latency.

Type at least two characters.

navigate open esc dismiss