CISA added five actively exploited vulnerabilities to its KEV catalog in entries dated September 10-11, 2026, led by a ConnectWise ScreenConnect flaw rated CVSS 9.9 with a September 14 federal patch deadline.
CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, 2026. GitLab's advisory describes a path traversal bug in the repository commits API, scored 10.0 on CVSS, that lets an unauthenticated user read arbitrary server files. The federal remediation date was September 14.
Google's 8 September 2026 Chrome 153 release says an exploit for CVE-2026-87491, an out-of-bounds write in the V8 engine, exists in the wild. It is the seventh actively exploited Chrome zero-day of 2026 — and the fix only protects you after you relaunch the browser.
Cisco Talos confirmed on September 9, 2026 that three intrusion clusters - one overlapping with Sandworm, one matching Qilin ransomware affiliates - are exploiting CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure Firewall Management Center.
IDScan.net says an unauthorized third party may have copied full names and driver's license numbers from its cloud, after a dark-web service advertised more than 153 million ID scans. The FBI is looking into the incident.
Microsoft's September 8, 2026 Patch Tuesday fixed two Windows zero-days already under attack: CVE-2026-85880 in ALPC and CVE-2026-81963 in the Update Stack. CISA added both to its Known Exploited Vulnerabilities catalog the same day, with a September 22 deadline for federal civilian agencies.
CERT Polska says the MikroTrick chain in MikroTik's RouterOS was used against internet-facing SSH from at least September 2 — a day before MikroTik's September 3 fixes. Shadowserver counted about 122,500 exposed devices.
A technical analysis published Sept. 7 by researcher Scott Helme traces the Manchester Airports Group breach to three Iterable API keys left in public website JavaScript and never rotated for more than four years. Have I Been Pwned lists 8.8 million affected accounts.
GreyNoise says a single actor ran hundreds of autonomous AI agents against PaperCut NG/MF, hitting 395 organizations in 48 countries — 11 of them in 26 seconds.
Hackers are actively exploiting a critical Citrix NetScaler authentication-bypass flaw patched in August, with tens of thousands of appliances still exposed online.
Google rushed out a Chrome update for CVE-2026-85046, a V8 flaw hackers are already exploiting in real attacks — here's what changed and how to update.
SonicWall confirms hackers are exploiting two SMA1000 VPN flaws, one rated a maximum 10.0 severity. CISA gave federal agencies until Sept. 5 to patch or disconnect affected appliances.
Oncology firm Novocure disclosed a mid-August cyberattack that exposed records of more than 1,400 U.S. cancer patients and staff data, an SEC filing shows.
Nearly 22,000 unpatched Microsoft Exchange servers remain exposed to CVE-2026-62911, a flaw that lets attackers hijack mailboxes even though Microsoft shipped a fix in August.
X confirms a wave of unauthorized password-reset attempts hit user accounts after the platform launched its X Money payments feature, but says it found no evidence of a system breach.
Russian-speaking ransomware group Qilin published about 6.3GB of files stolen from a U.S. ATF wiretap-support system after a ransom deadline expired, exposing case files and forensic phone data.
Security firm Sygnia says a China-nexus group called Fire Ant expanded from VMware hypervisors to Cisco IOS XR routers and TACACS servers, turning trusted network gear into spying tools.
Anthropic is forcing sign-outs, wiping saved payment methods and refunding unauthorized charges after infostealer malware on users' own PCs stole active Claude login sessions.
Hackers briefly took over Pokémon's official X account, which has about 8 million followers, posting a fake memecoin promotion before the company regained control and deleted the posts.
Healthcare giant McKesson confirms a cybersecurity incident after extortion group ShinyHunters claims theft of 284 million patient data records and demands a $55 million ransom.
OpenAI, Anthropic, Microsoft and over 100 other companies signed a letter warning hospitals and water utilities face a narrowing window to defend against AI-powered hacking.
PaperCut confirms customer incidents from a zero-day in its NG/MF print software; two chainable flaws allow authentication bypass and remote code execution.