FR
live
tag

#kev

ScreenConnect patches CVE-2026-84869, a missing-authorization flaw already exploited in live sessions

On September 8, 2026, ConnectWise shipped a fix for CVE-2026-84869, a missing authorization (CVSS 9.9) that lets an attacker push and run files on a machine during an active ScreenConnect session without host confirmation. Upgrade the client to version 26.6.5, then audit past sessions and file transfers before remote access becomes the entry point into your fleet.

Chrome 153 fixes CVE-2026-87491, the seventh exploited V8 zero-day of 2026

On September 8, 2026, Google ships Chrome 153, fixing 230 vulnerabilities including CVE-2026-87491, an out-of-bounds write in V8 already exploited in the wild. Update to 153.0.8010.36 or later before the CISA deadline of September 23, and check every Chromium browser in your fleet, Edge, Brave and Opera included.

GitLab patches a CVSS 10 arbitrary file-read flaw, exploited within 24 hours

On September 11, 2026, GitLab shipped an out-of-band release for CVE-2026-85706, a CVSS 10 path traversal that reads server files with no authentication via the commits API. The flaw is already being probed in the wild — patch self-managed instances before an attacker reads secrets.yml.

PivotC2 RAT exploits CVE-2025-25249, a Fortinet heap overflow patched since January

Patched in January 2026, the CVE-2025-25249 heap overflow in the FortiOS cw_acd daemon has resurfaced exploited in the wild: CISA added it to the KEV catalog on September 9, 2026, after SOCRadar observed the PivotC2 RAT deployed on 178 devices. Network teams must upgrade exposed FortiOS trains before September 12, then strip out unnecessary fabric access.

CVE-2026-8452, patched in June as a DoS, is an exploited pre-auth RCE on Citrix NetScaler

On 30 June 2026, Citrix rated CVE-2026-8452 as a memory overflow. On 14 August, WatchTowr showed it leads to pre-authentication code execution, and on 26 August CISA added it to the KEV catalog with a 29 August deadline. Appliances configured as VPN or AAA servers must be patched today, without waiting for official confirmation of exploitation.

A 2023 ownCloud flaw resurfaces and opens files with no credentials at all

CVE-2023-49105, a WebDAV authentication flaw rated CVSS 9.8 and fixed by ownCloud in late 2023, is now being actively exploited — CISA added it to the KEV catalog on 27 August 2026. Inventory your exposed ownCloud 10.x instances, move to 10.13.1 or later, and treat them as possible compromises.

A WebLogic proxy plug-in patched in January is now under active exploitation

CVE-2026-21962, a CVSS 10.0 access-control flaw in Oracle’s WebLogic Server proxy plug-in that was fixed in the January 2026 CPU, landed in CISA’s KEV catalog on August 24 with confirmed active exploitation. Apply the January patch before August 27 and inventory your middleware tier, which vulnerability scans too often miss.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss