2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-4153.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.
P0
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
P10
2026-09-09 04:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 06:20 UTC
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
P45
2026-09-09 04:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 04:40 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
P70
2026-09-09 02:36 UTC
Other
JPCERT · indexed 2026-09-09 03:10 UTC
P0
2026-09-09 02:36 UTC
Other
JPCERT · indexed 2026-09-09 03:10 UTC
P5
2026-09-09 02:03 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-09 09:10 UTC
P0
2026-09-09 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-09 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-09 01:16 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-09 01:25 UTC
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
P0
2026-09-09 01:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
P0