Daily Brief

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Link-following Update Stack EoP to SYSTEM — federal due today. Verify September cumulatives actually landed....

The 5-Minute Cyber Brief: September 22, 2026

The 5-Minute Cyber Brief: September 22, 2026

Zyxel GS1900 KEV due Thursday, Ivanti Neurons unauth RCE, Linux LPE quartet, Windows Update Stack due today....

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

CISA's three exploited Linux kernel bugs are due today. Patch, reboot, then triage....

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Pre-auth INLINE scripts escape GraalVM. Fortinet is blocking thousands of attempts — upgrade to 3.30.2+....

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

Hard-coded static key yields unauthenticated RCE on ARM ≤2026.2. Ship 2026.2.1....

CrowdSec: Departed Employee’s Live GitHub Access → ~170 Private Repos Cloned

CrowdSec: Departed Employee’s Live GitHub Access → ~170 Private Repos Cloned

TanStack credential theft plus retained ex-employee GitHub access cloned ~170 private repos....

The 5-Minute Cyber Brief: September 21, 2026

The 5-Minute Cyber Brief: September 21, 2026

Monday reboot-and-revoke brief: Linux kernel KEV trio due today, Orkes Conductor RCE, SolarWinds ARM, CrowdSec offboarding....

The 5-Minute Cyber Brief: September 15, 2026

The 5-Minute Cyber Brief: September 15, 2026

Cisco email gateway root RCE due Wednesday, Sogou one-click to GRAYRABBIT, Windows ALPC SYSTEM zero-day, and F5 PoisonedRefresh fileless webshell....

F5 BIG-IP APM PoisonedRefresh: Fileless PHP Web Shell After CVE-2025-53521 — Patch ≠ Clean

F5 BIG-IP APM PoisonedRefresh: Fileless PHP Web Shell After CVE-2025-53521 — Patch ≠ Clean

PoisonedRefresh injects a PHP webshell into BIG-IP APM memory after CVE-2025-53521. Patching alone does not remove the implant....

Windows ALPC Heap Overflow CVE-2026-85880: AppContainer to SYSTEM Zero-Day (Not the Update Stack Bug)

Windows ALPC Heap Overflow CVE-2026-85880: AppContainer to SYSTEM Zero-Day (Not the Update Stack Bug)

CVE-2026-85880 is an exploited Windows ALPC heap overflow to SYSTEM — separate from Update Stack CVE-2026-81963. KEV due September 22....

UNC3569 / Sogou Input Method CVE-2026-51990: One-Click RCE to GRAYRABBIT

UNC3569 / Sogou Input Method CVE-2026-51990: One-Click RCE to GRAYRABBIT

Gen Digital observed UNC3569 exploiting CVE-2026-51990 in Sogou Input Method to deploy GRAYRABBIT. Fix ≥ 16.3.0.3498....

Cisco Secure Email Gateway CVE-2026-76461: Unauth SQL Injection to Root — KEV Due Wednesday

Cisco Secure Email Gateway CVE-2026-76461: Unauth SQL Injection to Root — KEV Due Wednesday

CVE-2026-76461: unauthenticated SQL injection in Cisco AsyncOS email parsing escalates to root. CISA KEV due September 17, 2026. Fixed AsyncOS…

GitLab CVE-2026-85706: One Request, No Login, Your Secrets on Disk — Patch Deadline Is Today

GitLab CVE-2026-85706: One Request, No Login, Your Secrets on Disk — Patch Deadline Is Today

Self-hosted GitLab: one unauthenticated commits-API request can read secrets on disk. Federal due date is today....