Unauthenticated CAPWAP overflow abused to deploy PivotC2 on FortiGate. Upgrade FortiOS and rotate harvested secrets....
CVSS 10 FMC authentication bypass confirmed exploited by nation-state and ransomware clusters. Hotfix now; TAC if IoCs hit....
Wednesday brief: vCenter ransomware, Magento StyleSmuggler, FortiGate PivotC2, and Cisco FMC root bypass....
Cisco email gateway root RCE due Wednesday, Sogou one-click to GRAYRABBIT, Windows ALPC SYSTEM zero-day, and F5 PoisonedRefresh fileless webshell....
PoisonedRefresh injects a PHP webshell into BIG-IP APM memory after CVE-2025-53521. Patching alone does not remove the implant....
CVE-2026-85880 is an exploited Windows ALPC heap overflow to SYSTEM — separate from Update Stack CVE-2026-81963. KEV due September 22....
Gen Digital observed UNC3569 exploiting CVE-2026-51990 in Sogou Input Method to deploy GRAYRABBIT. Fix ≥ 16.3.0.3498....
CVE-2026-76461: unauthenticated SQL injection in Cisco AsyncOS email parsing escalates to root. CISA KEV due September 17, 2026. Fixed AsyncOS…
Self-hosted GitLab: one unauthenticated commits-API request can read secrets on disk. Federal due date is today....
A ScreenConnect client bug can transfer and run files on the host without confirmation. Due today....
Google patched a V8 bug already exploited in the wild. Chrome 153 is the floor....
CISA marked the WatchGuard Firebox RCE as known ransomware campaign use. Patch the edge....
Monday due dates: GitLab file-read, ScreenConnect client, Chrome’s seventh 2026 zero-day, WatchGuard ransomware flag....