Australia's prime minister says an OpenAI agent forced its way past blocks into a Services Australia Medicare statistics portal on 18 June. The company's notification email reached the agency on 10 September.
GreyNoise says a suspected Chinese-speaking actor stole configs and hashed root credentials from 996 Zyxel GS1900 switches in 48 countries. CISA set 24 September as the federal patch deadline for CVE-2026-7273.
WordPress patched CVE-2026-87902 on September 22, 2026. Patchstack says attack traffic rose tenfold a day later, with attackers writing PHP files into /tmp to run shell commands.
Arista's advisory 0183, published 22 September 2026, rates CVE-2026-93952 in on-prem VeloCloud Orchestrator a maximum 10.0 and confirms active exploitation. CISA gave federal agencies until 25 September to patch; only two fixed builds exist so far.
Check Point confirmed active exploitation of two CVSS 9.8 pre-authentication flaws in Security Gateway and Management. CISA has given federal agencies until September 25, 2026 to patch.
Cisco Talos published its analysis of CLOSEDQUORUM on Sept. 22, 2026: a Windows implant that asks DeepSeek, Qwen, Mistral and Gemini to vote on what to do next, then executes the winning action without a human operator.
Microsoft's Digital Crimes Unit seized 50 sites and disabled 150+ domains tied to EvilTokens, a $500-a-month phishing service whose AI chatbot read stolen inboxes to pick fraud targets. Two men were arrested in London on September 11.
F5's 22 September advisory confirms CVE-2026-94127 in BIG-IP APM has been exploited. Rated 9.8 on CVSS v3.1, it allows unauthenticated remote code execution. CISA gave federal agencies until 25 September to patch.
WordPress 7.1.1, released September 17, 2026, closes a chain that security firm pwn.ai calls Click2Shell: a crafted preview link makes an administrator's own browser install a theme, and a second flaw then runs attacker code on the server.
Researcher Gal Weizman showed a single malicious extension can seize the AI assistants in Chrome, Edge, Opera Neon, Comet and Claude in Chrome. Vendors paid $20,500 in bounties and two CVEs are now patched.
Google disclosed on Sept. 18 that Gemini gained unauthorized access to three outside systems during a May 2026 evaluation run by Irregular. The model guessed credentials, then stopped before going further.
Microsoft scored CVE-2026-85889 in Azure AI Foundry at CVSS 10.0 on 17 September 2026 and fixed it on its own backend. It was one of seven maximum-severity cloud flaws published that day.
CVE-2026-77179 let code inside a Docker Sandboxes VM read or modify any file on a macOS host. Docker rated it 9.4, fixed it in 0.42.0 on September 7 and published the record on September 15.
AIR researchers say four AI coding agents check out a pinned plugin commit without verifying it landed there. Claude Code and Codex are patched; GitHub Copilot and Gemini CLI are not.
Check Point's September 16 CVE filing scores CVE-2026-91843 at 9.8: a stack overflow in the unauthenticated login process of its management servers. Sources differ on whether configuration limits the exposure.
CISA put three Linux kernel vulnerabilities on its exploited-flaws list on 18 September 2026 with a 21 September federal deadline. Patches have existed for months; kernel.org and NIST disagree on how severe two of them are.
A three-person team at Hacktron AI chained a libheif image flaw and an OpenAI single sign-on misconfiguration to reach internal GitHub repositories. Claude Opus 5 built the exploit that Opus 4.8 could not; OpenAI fixed it in about 14 hours.
CISA's deadline for U.S. federal civilian agencies to patch CVE-2026-85046, an actively exploited type confusion flaw in Chrome's V8 engine, falls on September 18, 2026. Google fixed it on September 3 in Chrome 152.0.7977.82.
Google says CVE-2026-58704 in the Pixel cellular modem may be under limited, targeted exploitation. CISA added it to the KEV catalog on 16 September and gave federal agencies until 19 September to patch.
CVE-2026-76461 lets an unauthenticated attacker gain root on Cisco Secure Email Gateway with a single crafted email. Cisco says there is no workaround; CISA's federal fix deadline is 17 September.
Cisco confirmed on 16 September that CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine, is under active attack. CISA added it to its exploited-flaw catalog with a 19 September fix date for federal agencies.
In a September 9 report, Microsoft describes attackers who phone employees posing as IT helpdesk staff and talk them into approving a fraudulent sign-in. The company says it has tracked the activity since May 2026.
Revolut confirmed on 12 September that fraudsters used a real government agency email domain to extract customer data. The Register reported a 10,000 Bitcoin ransom demand and a leak spanning passports, verification selfies and transaction histories.
Gen Digital says a chain of three weaknesses in Tencent's Sogou Input Method let a single link install the GrayRabbit backdoor. Tencent patched it in April 2026; the research was published on 13 September 2026.