> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
CVE-2026-75754: Chained Flaw in ASUS Control Center Enterprise Gives Unauthenticated Root
CVE-2026-75754 (CVSS 10.0) chains a missing-auth SSRF flaw with hardcoded SSH credentials to hand unauthenticated attackers root on ASUS Control Center Enterprise servers — and everything those servers manage.
Three Strikes: How Cisco's Firewall Brain Became Everyone's Favorite Target
In 2026, Cisco Secure FMC took three separate maximum-severity zero-days — and the third one put a Russian APT and a ransomware affiliate on the same box, in the same weeks, running the same playbook. That convergence is the story, not the CVE.
CVE-2026-89094: A Malicious Template Repository Gets You RCE on Forgejo — and Gitea
A crafted .forgejo/template file lets any low-privileged authenticated user turn 'create repository from template' into remote code execution as the Git-forge service account. Forgejo (CVE-2026-89094, CVSS 9.9) and upstream Gitea both shipped emergency patches.
CVE-2026-85102 & CVE-2026-85103: Dutch NCSC Warns Exploitation of Check Point VPN Certificate RCE Flaws Is Imminent
Two unauthenticated CVSS 9.8 RCE bugs in Check Point's VPN certificate handling have hotfixes since September 9 — the Dutch NCSC says active exploitation is likely imminent even though no public PoC exists yet.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing
A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.
cPanel CVE-2026-67401: EmailTrack SQL Injection Lets Mail Users Reach Root
A SQL injection in cPanel & WHM's EmailTrack feature lets any account with mail privileges write arbitrary files and execute code as root — CVSS 9.9, every supported version affected.
N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production
CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.
Microsoft's September Patch Tuesday Sets a New Record: ~970 Flaws, Two Zero-Days Actively Exploited
Microsoft's largest Patch Tuesday ever ships fixes for roughly 970 CVEs, including two zero-days already under active attack in the Windows Update Stack and ALPC, plus a trio of CVSS 10.0 cloud-identity bugs in Azure AD B2C, Azure AI Language, and Copilot Studio.
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root
Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.
Two Critical Command Injection Flaws in Advantech WISE-6610 Industrial Gateways (CVE-2026-79697, CVE-2026-79698)
Two CVSS 9.9 command injection bugs in Advantech's WISE-6610 cellular IoT gateway let an attacker with access to the admin web UI run arbitrary OS commands as root, with public exploit code already circulating.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
The WannaCry Bugs Never Left: Windows' Core Network Stack Just Had Its Worst Year Since EternalBlue
Netlogon, DNS Client, DHCP Server, DNS Server — four unauthenticated, network-reachable, CVSS-9.8-class memory corruption bugs in Windows' core infrastructure services in five months. This is not four unlucky patch cycles. It's a pattern, and most vulnerability-management programs are triaging it wrong.
PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE
A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.
Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches
A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
HPE Aruba AOS-CX: Two Independent Unauthenticated RCE Paths in the Same Switch OS (CVE-2026-73749, CVE-2026-73782)
HPE's September security bulletin for ArubaOS-CX patches 24 flaws, including two unrelated bugs that each let an unauthenticated attacker fully compromise a switch with a single crafted packet.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.