ShieldCrash Zero-Day Bypasses Microsoft Defender Patch and Grants SYSTEM Access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named ShieldCrash on September 9, 2026. The exploit bypasses a recently patched Defender flaw called ShieldBreak and grants SYSTEM…
Critical Kernel Flaw Enables Unauthenticated Remote Code Execution
September 9, 2026 SAP has patched a maximum-severity vulnerability in its kernel that enables unauthenticated remote code execution with administrative privileges. Tracked as CVE-2026-44756 and codenamed OVERPASS, the flaw carries a CVSS score of 10.0…
MikroTik RouterOS Attack Chain Hijacks Devices
September 7, 2026 Threat actors are actively exploiting a chain of two critical vulnerabilities in MikroTik routers. The attack, dubbed “MikroTrick,” allows hackers to bypass SSH authentication and escalate privileges to gain full administrative control…
Critical Citrix NetScaler Authentication Bypass CVE Under Active Exploitation
September 5, 2026 Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, following the public release of proof-of-concept exploit code on September 4, 2026. The flaw, tracked as…
Google Chrome V8 Zero-Day CVE Actively Exploited
September 3, 2026 Google released an emergency security update for Chrome on September 3, 2026, to patch an actively exploited zero-day vulnerability in the V8 JavaScript engine. The high-severity flaw, tracked as CVE-2026-85046, allows remote attackers…
Critical HPE ArubaOS-CX RCE CVE: Unauthenticated Remote Code Execution in Enterprise Switches
September 3, 2026 HPE has patched a critical unauthenticated remote code execution vulnerability in ArubaOS-CX, the network operating system powering its enterprise-grade switches. Tracked as CVE-2026-73749, the flaw could allow remote attackers to take…
Sangoma Switchvox SQL Injection Under Active Exploitation
Threat actors are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, an enterprise VoIP management platform. The flaw allows remote code execution without any credentials, and researchers have observed…
PaperCut Releases Second Emergency Patch After Attackers Bypass Initial Fixes
August 29, 2026 PaperCut has released a second emergency security patch for two critical vulnerabilities in its PaperCut NG and PaperCut MF print management software after security researchers discovered multiple methods to bypass the original emergency…
CISA Imposes 3-Day Patch Mandate on Perfect-10 Oracle WebLogic Proxy Flaw
August 28, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has imposed its tightest emergency patch mandate on a maximum-severity Oracle vulnerability that China-linked threat actors have exploited across government and commercial…
Unpatched Calix GS7 XGS Router CVE Lets Attackers Bypass NAT and Expose Internal Devices
August 24, 2026 An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to bypass NAT and firewall protections and expose internal network devices to the public internet. The flaw, tracked as CVE-2026-75501, affects…