● On the wire
Debian nginx Important Buffer Overflow Denial of Service 2026-6496-1//Cisco Secure Email Gateway SQL Injection Vulnerability//Ubuntu libEBML Critical Buffer Overflow Denial of Service USN-8746-1//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571-2//Ubuntu Konsole Important Remote Code Exec Risk USN-8752-1 CVE-2025-49091//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026//Ubuntu CivetWeb Important Denial Of Service Risks USN-8749-1//Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)//Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1//Ubuntu Urwid Important Denial of Service Local Access USN-8751-1//Ubuntu 26.04 LTS dracut Critical Command Injection Vulnerability USN-8758-1//Debian Network Manager L2TP Moderate Escalation Vulnerabilities DSA-6498-1//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//Debian nginx Important Buffer Overflow Denial of Service 2026-6496-1//Cisco Secure Email Gateway SQL Injection Vulnerability//Ubuntu libEBML Critical Buffer Overflow Denial of Service USN-8746-1//Debian xorg-server Important Privilege Escalation Fix DSA-6497-1//Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571-2//Ubuntu Konsole Important Remote Code Exec Risk USN-8752-1 CVE-2025-49091//Debian libevent Important HTTP Header Injection DoS Advisory CVE-2026-63379//Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026//Ubuntu CivetWeb Important Denial Of Service Risks USN-8749-1//Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)//Debian Stable ruby-rack Important Access Restriction Issues DSA-6492-1//Ubuntu Urwid Important Denial of Service Local Access USN-8751-1//Ubuntu 26.04 LTS dracut Critical Command Injection Vulnerability USN-8758-1//Debian Network Manager L2TP Moderate Escalation Vulnerabilities DSA-6498-1//CNAs — Call for Topics for “CVE Program Fall Technical Workshop: Advancing CVE Record Quality” on…//
Chrome/V8 zero-day attivamente sfruttato e inserito nel catalogo CISA KEV
Top story — News

Chrome/V8 zero-day actively exploited and added to the CISA KEV catalog

Google has released an urgent update for Chrome that fixes 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 engine already exploited in the wild. The flaw can allow a remote attacker to execute arbitrary code in the browser sandbox through a specially crafted HTML page. CISA has added the bug to the Known Exploited Vulnerabilities catalog, confirming…

Read the article →
From the newsroom
Zero-day SonicWall SMA 1000 sfruttati in rete
News

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers…

Read the article →
Spotlight
More news