Privilege-Escalation
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
CVE-2026-71362: Unauthenticated Account Takeover Hits Adobe Commerce and Magento, Now on CISA KEV
CISA added CVE-2026-71362 to KEV after Sansec confirmed active exploitation. A session-identity bug lets an unauthenticated attacker hijack any customer's Adobe Commerce or Magento account — no credentials, no interaction.
CVE-2026-86708: ManageEngine Shipped a Live GCP Service-Account Key Inside Its Public Installer
CVE-2026-86708 (CVSS 10.0): Zoho's ManageEngine Applications Manager Linux installer shipped a hard-coded, over-privileged Google Cloud service-account key that anyone who downloaded the installer could extract and use to impersonate the account.
CVE-2026-80521: Unpatched Ubuntu AF_UNIX Race Lets Containers Escape to Host Root
A public exploit for CVE-2026-80521, a use-after-free race in the Linux kernel's AF_UNIX socket garbage collector, lets an unprivileged process inside a default Docker or Kubernetes container break out to root on the host — and Ubuntu still hasn't shipped the fix.
BragJack: One Malicious Extension Hijacks AI Agents Across Five Major Browsers
Researcher Gal Weizman's BragJack proof-of-concept shows how a single malicious extension can hijack the built-in AI agents in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome, earning $20K+ in bounties and two CVEs (CVE-2026-0628, CVE-2026-55945).
SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key Enables Unauthenticated RCE
A hard-coded cryptographic key in SolarWinds Access Rights Manager (CVE-2026-28326, CVSS 8.8) lets an adjacent-network attacker run arbitrary code with no credentials. Patch to ARM 2026.2.1.
CISA Adds Three Linux Kernel Flaws to KEV: TLS Receive Path, ebtables SNAT, and AF_ALG Race Condition Under Active Exploitation
CISA added three Linux kernel CVEs to its Known Exploited Vulnerabilities catalog on evidence of in-the-wild exploitation — a CVSS 9.8 TLS receive-path flaw, an 8.8 ebtables SNAT out-of-bounds write, and a 7.8 AF_ALG race condition — with FCEB remediation due September 21.
CVE-2026-87886: Acronis Backup Plugin for cPanel and Plesk Exploited for Root on Shared Hosting
CVE-2026-87886 (CVSS 7.8) lets a low-privileged local user escalate to root on cPanel, WHM, Plesk, and DirectAdmin hosts via world-writable files left behind by Acronis's backup plugin — already exploited in targeted attacks and added to CISA KEV with a September 19 federal deadline.
CVE-2026-76460: Maximum-Severity Cisco ISE Auth Bypass Exploited Before Disclosure
CVE-2026-76460 (CVSS 10.0) lets unauthenticated attackers bypass Cisco ISE's web management entirely via a privileged API endpoint and get root — Cisco found it while cleaning up a customer who was already compromised, and CISA added it to KEV within a day.
CVE-2026-5430: Active Exploitation of WSO2 API Manager JWT Bypass Delivers Forged Admin Tokens
Attackers are actively exploiting CVE-2026-5430 (CVSS 9.8), a JWT signature-verification flaw in WSO2 API Manager and its Universal Gateway, to forge tokens carrying administrator privileges — watchTowr's honeypots caught the first forged-admin-token traffic on September 13.
CVE-2026-75754: Chained Flaw in ASUS Control Center Enterprise Gives Unauthenticated Root
CVE-2026-75754 (CVSS 10.0) chains a missing-auth SSRF flaw with hardcoded SSH credentials to hand unauthenticated attackers root on ASUS Control Center Enterprise servers — and everything those servers manage.
cPanel CVE-2026-67401: EmailTrack SQL Injection Lets Mail Users Reach Root
A SQL injection in cPanel & WHM's EmailTrack feature lets any account with mail privileges write arbitrary files and execute code as root — CVSS 9.9, every supported version affected.
N-able Ships Fourth N-central Hotfix in Five Weeks After CVE-2026-86218 Pre-Auth RCE Hits Production
CVE-2026-86218, a maximum-severity static code injection flaw in N-able's N-central RMM platform, let unauthenticated attackers run arbitrary code on the server — and CISA confirms it was already exploited before the patch shipped.
Microsoft's September Patch Tuesday Sets a New Record: ~970 Flaws, Two Zero-Days Actively Exploited
Microsoft's largest Patch Tuesday ever ships fixes for roughly 970 CVEs, including two zero-days already under active attack in the Windows Update Stack and ALPC, plus a trio of CVSS 10.0 cloud-identity bugs in Azure AD B2C, Azure AI Language, and Copilot Studio.
MikroTrick: Chained MikroTik RouterOS SSH Bugs Give Unauthenticated Root, 122,500 Devices Exposed
CERT Polska's MikroTrick chain (CVE-2026-67276 + CVE-2026-86060) lets attackers bypass SSH authentication and escalate to full admin on MikroTik RouterOS — exploited in the wild since September 2, before patches shipped.
Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root
Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.
PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE
A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.