2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.
P5
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.
P5
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81987.
P20
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19397.
P20
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PAPPL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.
P15
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of PAPPL. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
P10
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71414.
P15
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71415.
P15
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71416.
P15
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19593.
P20
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19592.
P20
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19591.
P20
2026-09-10 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-10 13:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.
P20
2026-09-10 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
An AD RMS Service Group account exports the AD RMS Server Licensor Certificate private key. That 1172-byte key decrypts every document the deployment ever protected, offline, and keeps doing so after the deployment is rebuilt.
P0
2026-09-10 04:00 UTC
Security Journalism
The Record · indexed 2026-09-10 18:45 UTC
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use.
P0
2026-09-10 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-10 16:10 UTC
Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase. Cette injection SQL permet d’obtenir les droits administrateur de...
P0
2026-09-09 21:40 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-09 21:45 UTC
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
P60
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 21:35 UTC
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]
P0
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 16:05 UTC
Bulletin ID: 2026-105-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 08:30 AM PDT Description: AWS Security Agent is a managed AWS service that provides AI-powered code security reviews, threat modeling, and penetration testing. We identified CVE-2026-87912, where a missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before version 1.1.0 might allow remote attackers to obtain the private source ar…
P5
2026-09-09 21:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-09 21:40 UTC
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P5