Auto-updating • Public sources • Link-out only
Security Intel
Designed for engineers through CISOs: what is being exploited and what deserves attention. Always validate in your environment.
Feed status
CISA KEVOK
Wiz ResearchOK
AquaOK
Palo Alto Unit 42OK
SnykOK
Updated Sep 12, 2026 (auto-refresh ~15 min)
Unified feed
Take Reality Assessment →Showing 30 of 50
CISA KEVSep 11, 2026High
Open ↗CVE-2026-84869 — ConnectWise ScreenConnect
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
CISA KEVSep 11, 2026High
Open ↗CVE-2026-42016 — JFrog Artifactory
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CISA KEVSep 11, 2026High
Open ↗CVE-2026-42018 — JFrog Artifactory
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CISA KEVSep 11, 2026High
Open ↗CVE-2026-85706 — GitLab Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Wiz ResearchSep 10, 2026
Open ↗Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory (CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329). Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control.
Wiz ResearchSep 10, 2026
Open ↗Wiz achieves GovRAMP High Authorization
Delivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure.
Palo Alto Unit 42Sep 10, 2026
Open ↗The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.
SnykSep 10, 2026
Open ↗Is prevention essentially a solved problem?
Prevention in agent-generated code is architecturally solved—but choosing controls that protect security without slowing development remains the challenge.
CISA KEVSep 10, 2026High
Open ↗CVE-2026-86060 — MikroTik RouterOS
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
CISA KEVSep 10, 2026High
Open ↗CVE-2026-67277 — MikroTik RouterOS
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Wiz ResearchSep 09, 2026
Open ↗Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise
How default keys, unauthenticated MCP sessions, and custom code guardrails expose cloud AI infrastructure to root-level remote code execution and IAM theft.
Palo Alto Unit 42Sep 09, 2026
Open ↗Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.
CISA KEVSep 09, 2026High
Open ↗CVE-2026-19490 — Citrix NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
CISA KEVSep 09, 2026High
Open ↗CVE-2025-25249 — Fortinet Multiple Products
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CISA KEVSep 09, 2026High
Open ↗CVE-2026-87491 — Google Chromium V8
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEVSep 09, 2026High
Open ↗CVE-2026-20079 — Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
CISA KEVSep 08, 2026High
Open ↗CVE-2026-75650 — Adobe Commerce and Magento
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
CISA KEVSep 08, 2026High
Open ↗CVE-2026-81963 — Microsoft Windows
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
CISA KEVSep 08, 2026High
Open ↗CVE-2026-86218 — N-able N-central
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
CISA KEVSep 08, 2026High
Open ↗CVE-2026-85880 — Microsoft Windows
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
CISA KEVSep 04, 2026High
Open ↗CVE-2026-85046 — Google Chromium V8
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Palo Alto Unit 42Sep 03, 2026
Open ↗Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.
Wiz ResearchSep 03, 2026
Open ↗How Developers Prevent Production Risk at the Source
Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your software pipeline.
Palo Alto Unit 42Sep 02, 2026
Open ↗An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-59822 — BerriAI LiteLLM
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-48710 — Kludex Starlette
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-49869 — Kestra Kestra OSS
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-82329 — JFrog Artifactory
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-9586 — Sangoma Switchvox
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CISA KEVSep 02, 2026High
Open ↗CVE-2026-83548 — SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Notes
- • This page aggregates public feeds and links out; it does not scan your environment.
- • Treat items as signals: verify applicability, exposure, and exploitability before action.
- • For exec-ready prioritization, pair this with the Reality Assessment.