Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution
Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...
MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution
A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...
Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days
Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Fortinet Firewalls Under Siege: New PivotC2 Malware Exploits Critical CAPWAP Flaw
A critical, unauthenticated buffer overflow in FortiOS's CAPWAP service is being actively exploited to plant a custom Node.js post-exploitation toolkit dubbed PivotC2. Researchers say at least 178 devices...
Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack
Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...
Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch
Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...