3 September 2026
CVE-2026-83548 (CVSS score: 10.0) & CVE-2026-83549 (CVSS score: 7.8) released by SonicWall that impact its Secure Mobile Access 1000 series VPN.
CVE-2026-83548 (CVSS score: 10.0) & CVE-2026-83549 (CVSS score: 7.8) released by SonicWall that impact its Secure Mobile Access 1000 series VPN.
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident; ShinyHunters extortion group claiming it stole 284 million patient data records.
28,000 publicly reachable .git repositories containing credentials, financial information and internal employee records that could give criminals a direct route into cloud accounts and business systems.
Added to the KEV catalog- CVE-2026-65400 (CVSS score: 9.8) Apple macOS, CVE-2026-55040 (CVSS score: 9.1) Microsoft SharePoint, CVE-2026-59310 (CVSS score: 9.8) Broadcom VMware vCenter, CVE-2026-33824 (CVSS score: 9.8) IKE.
Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. CVE-2026-15748, is rated 9.8 out of 10.0.
1,449 security patches were released as part of the company’s quarterly security fixes may partly reflect Oracle’s internal push to harness AI for vulnerability detection.
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
7-Zip version 26.02 was released to fix a remote code execution vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip’s processing of XZ-compressed data.
CVE-2026-63030 and CVE-2026-60137 chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
CVE-2026-40639 (DSA-2026-197), stems from a broken XOR encryption scheme rather than a proper cryptographic hash.
A server-side request forgery (SSRF) vulnerability in PAN-OS security risk is minimized when management interface is restricted to only trusted internal IP addresses.
CVE-2026-4020 – Threat actors active on 100,000 sites, affects all versions of the plugin from 2.1.4 and older and has been addressed in version 2.1.5, released on March 17.
Palo Alto Networks CVE-2026-0274, CommvaultSecurityIQ integration; patches for PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App. Splunk published a dozen advisories.
Oracle has released CVE-2026-35273, a critical unauthenticated remote code execution vulnerability impacting PeopleSoft Enterprise PeopleTools v8.61 and 8.62 and PeopleSoft Enterprise Applications.
CVE-2026-45447, a heap user-after-free bug used for PKCS#7 (Public-Key Cryptography Standard #7) verification; patches 18 vulnerabilities including a high-severity issue that could allow remote code execution.
CVE-2026-44963 allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. It impacts Veeam Backup & Replication 12.3.2.4465 and all earlier versions of 12 builds.
CVE-2026-4480 allowing unauthenticated attackers to achieve remote code execution (RCE) on affected systems; carries CVSS v3.1 score of 10.0, highlighting its severe impact and ease of exploitation.
“PinTheft,” was publicly disclosed on May 19, 2026. The vulnerability was fixed in the mainline Linux kernel tree. A proof-of-concept exploit was published along with public disclosure.
Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip, the vulnerability affects both NGINX Plus and NGINX Open Source, and can be triggered by a remote, unauthenticated attacker over plain HTTP.
CVE-2026-41091, MS Defender local privilege escalation (LPE) flaw known as RedSun, and CVE-2026-45498 is known as UnDefend, a security flaw according to a security researcher known as “Nightmare Eclipse”.