Rosetta Daily · Sep 9, 2026
Microsoft published 974 of its own CVEs in one day; 147 of those advisories say an unauthorized attacker can execute code over a network. The two Microsoft flaws that entered KEV the same day are both local privilege escalation.
The other thread runs through the dependency tree: one set of libheif flaws gives Next.js, Astro and sharp unauthenticated remote code execution, three advisories pointing at a single upstream.
Actively exploited (KEV)
[Added detail] Adobe Commerce and Magento: StyleSmuggler patched, catalogued the same day (CVE-2026-75650, CVSS 10)
Adobe has shipped an emergency fix. Sansec, which named the flaw StyleSmuggler, recorded zero-day exploitation starting September 4, dropping a Rust backdoor and a PHP web shell. The bug is improper neutralization of special elements in the template engine; exploitation needs no user interaction and the scope is changed. CISA added it on September 8 with a September 11 remediation deadline for federal civilian agencies.
Sources: The Hacker News · Bleeping Computer · CISA
[Added detail] N-able N-central: static code injection enters KEV, plus two chainable authentication bypasses (CVE-2026-86218, CVSS 10)
CISA added the pre-authentication remote code execution flaw on September 8, deadline September 11. While researching the earlier CVE-2026-18577, Rapid7 found two more: CVE-2026-86206, a semicolon/Forwarded access-control bypass (CVSSv4 6.9), and CVE-2026-86207, a UserTwoFactorLogin authentication bypass (7.7). Chained, they let a remote unauthenticated attacker create an attacker-controlled System administrator account on an affected server. Both are fixed in N-central 2026.3 Hotfix 3.
Sources: The Hacker News · Rapid7
Windows: ALPC heap overflow and Update Stack link following, two privilege escalations exploited in the wild (CVE-2026-85880, CVE-2026-81963)
Both take a local attacker to SYSTEM. CVE-2026-85880 sits in Windows Advanced Local Procedure Call and combines a heap-based buffer overflow with an uninitialized resource; CVE-2026-81963 is improper link resolution before file access in the Windows Update Stack. Both shipped with the September Patch Tuesday and were catalogued by CISA the same day.
Sources: MSRC CVE-2026-85880 · MSRC CVE-2026-81963 · CISA
Google Chrome: the seventh exploited zero-day this year
Google's Tuesday update fixed 230 vulnerabilities in total, among them a Chrome zero-day under active exploitation, the seventh of the year.
Sources: Bleeping Computer
Critical vulnerabilities
Next.js, Astro and sharp: AVIF image optimization gives unauthenticated remote code execution through libheif
Upstream libheif fixed a batch of flaws, two of them rated Critical under CVSSv3, which can lead to code execution on glibc-based Linux under certain conditions with a network attack vector. Three downstream advisories followed: Next.js's Image Optimization API is exploitable without authentication when handling AVIF, and the project disabled AVIF optimization outright until the fix propagates; Astro's default Sharp image service is affected when it processes an untrusted AVIF image, fixed in Astro 7.2.8, which requires Sharp 0.35.4. The condition is simply that an attacker can get the application to process an AVIF image of their choosing.
Sources: Next.js GHSA · Astro GHSA · sharp GHSA
Next.js: unauthenticated remote code execution on Windows-hosted servers (CVE-2026-75604)
Applications using the Pages or App router without Cache Component can be driven to remote code execution when the server runs on a Windows filesystem. The project states there is no known workaround for affected Windows-hosted applications; upgrading is the only fix.
Sources: GitHub Advisory
Ivanti Neurons for ITSM: eight flaws, two of them unauthenticated remote code execution (CVE-2026-12745, CVE-2026-12744, both CVSS 9.8)
Both unauthenticated paths come from deserialization of untrusted data. Three missing-authorization flaws (CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, all CVSS 9.9) and further deserialization bugs (CVE-2026-12650 at 9.9; CVE-2026-12648 and CVE-2026-12651 at 8.8) let an authenticated attacker execute code on the server. Versions before 2026.2 are affected. The same day, Ivanti Endpoint Manager Mobile fixed a missing authorization flaw (CVE-2026-18851, CVSS 8.8) that lets a remote authenticated attacker escalate to admin.
Sources: NVD CVE-2026-12745 · NVD CVE-2026-12647 · NVD CVE-2026-18851
SAP: OVERPASS in the Kernel scores a 10, and NetWeaver Message Server accepts forged component registration (CVE-2026-44756, CVSS 10; CVE-2026-58240, CVSS 9.8)
OVERPASS is a memory safety flaw in the Extended Passport Protocol processing library: an unauthenticated attacker sending a crafted network request with a malformed EPP header can trigger undefined behaviour and abnormal program termination. NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration, so an attacker with network access can register an unauthorized component and act inside the application environment. SAP fixed 20 issues this month, including unauthenticated credential disclosure in the @sap/cds-mtxs multitenant extension (CVE-2026-76969, 9.4) and a trust-level policy bypass in SAP GUI for Java (CVE-2026-66768, 9.0).
Sources: Bleeping Computer · NVD CVE-2026-44756 · NVD CVE-2026-58240
hawtio-operator: mints client certificates with an attacker-chosen CN using the OpenShift service CA private key (CVE-2026-78234, CVSS 9.9)
The operator reads the service CA's private signing key from the openshift-service-ca namespace and uses it to mint client certificates whose Subject Common Name comes from a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can trigger it. A second flaw in the same operator (CVE-2026-80219, 8.7) creates a cluster-scoped OAuthClient with automatic grant approval and no client secret, with redirect URIs derived from the tenant-controlled routeHostName field.
Sources: NVD CVE-2026-78234 · NVD CVE-2026-80219
XenForo: the OAuth2 token endpoint accepts an empty client_secret (CVE-2026-73309, CVSS 9.1)
PHP treats an empty string as false, so both client secret validation and PKCE code verifier validation are skipped and a valid authorization code is enough to obtain a token pair. The same release fixes authorization codes that are never marked consumed after token issuance and can be redeemed again (CVE-2026-73311, 9.1), refresh tokens that are not marked consumed when the parent access token has expired and can be replayed repeatedly (CVE-2026-73312, 9.1), and a PayPal REST webhook handler that returns true instead of failing when auth_algo cannot be mapped to a supported hash function (CVE-2026-73314, 8.7). Fixed in 2.3.13.
Sources: NVD CVE-2026-73309 · NVD CVE-2026-73314
Siemens Reyrolle 7SR5: predictable session identifiers let an unauthenticated attacker take over the protection relay (CVE-2026-62647, CVSS 9.3; CVE-2026-62645, 9.3; CVE-2026-62646, 9.1)
The random number generator producing security-relevant values such as session identifiers is not seeded from a true random source, so the sequence is predictable; the session identifiers themselves have low entropy and can be brute-forced in a feasible number of attempts; and the web interface exposes information sufficient to calculate current and past session IDs. Two denial-of-service flaws round out the set: the URL length in pre-authentication HTTP messages is not validated before data is appended, causing an out-of-bounds write (CVE-2026-62648, 8.7), and the web server does not limit resources under concurrent requests, crashing and rebooting the device (CVE-2026-62649, 8.7). All versions before V2.70 are affected.
Sources: NVD CVE-2026-62647 · NVD CVE-2026-62645
Netty: a fragmented TLS ClientHello falls back to the default context and bypasses mTLS (CVE-2026-75595)
When the handshake header spans multiple TLS records, SslClientHelloHandler silently falls back to the default SslContext. Where per-SNI context selection is the only thing enforcing mutual TLS on a route, an unauthenticated attacker can bypass that requirement.
Sources: GitHub Advisory
Gitea and Semaphore: repository permissions convert straight into host command execution (CVE-2026-60004, CVE-2026-73294)
Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content: an attacker with ordinary write access runs arbitrary shell commands as the Gitea OS user, and on instances with default open registration an unauthenticated visitor can obtain that access. Semaphore's repository git_url handling carries an OS command injection: any user holding the Manager or Owner role on any project can use git's --upload-pack=<cmd> option to run commands on the Semaphore server host.
Sources: Gitea GHSA · Semaphore GHSA
GitPython: dormant multi-line git-config values become live directives after one unrelated write (CVE-2026-78676)
GitConfigParser decodes multi-line configuration values incorrectly on read, and writing the file back turns previously inert text into effective configuration directives — for example a core.hooksPath pointing at an attacker-controlled path, which leads to code execution. Triggering it requires no attacker-supplied setter argument, only that the program performs some unrelated write to that config file.
Sources: GitHub Advisory
NLTK: two pickle deserialization paths execute arbitrary code (CVE-2026-78683, CVE-2026-79657)
TransitionParser.parse() calls pickle_load() with the default restricted=False, so loading a malicious model file runs arbitrary Python. The library does ship a RestrictedUnpickler, but in the current source the supposedly safer allowlisted loading trusts whole module namespaces rather than exact safe globals, so a crafted pickle can still reach dangerous in-namespace callables through pickle REDUCE.
Sources: NLTK GHSA-rhp5 · NLTK GHSA-x99w
Vendor advisories
Microsoft September Patch Tuesday: a record single-day CVE count
The published totals differ: Bleeping Computer 966, CrowdStrike 972, Talos 973, Rapid7 and The Hacker News 974. The spread comes from whether non-Microsoft CVEs are counted and from when each outlet went to press; Rapid7's accounting is 974 own-product vulnerabilities plus 25 non-Microsoft CVEs that Microsoft published, for 999 on the day. Windows accounts for 723, Office and Office 2016 for 111, SQL for 62 and developer tools for 22, with 113 rated critical. Microsoft confirms two are exploited in the wild; both are above.
Sources: The Hacker News · Rapid7 · Talos · CrowdStrike
NSA and CISA: China-based AI companies are running industrial-scale distillation against U.S. frontier models
The joint advisory says China-based AI companies treat knowledge distillation as the core of their model development strategy rather than a supplement, systematically extracting restricted proprietary functionality and capabilities from U.S. AI companies' models. It acknowledges distillation as a legitimate research technique and points at the scale and intent instead.
Sources: CISA
Web security research
WeChat: a zero-click worm that takes over an account through an incoming call
Researchers at the security firm Calif built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since acted on it.
Sources: The Hacker News
Project Zero: reproducing race conditions with memory access tracing and stack-based delay injection
Race condition bugs only surface under a particular interleaving, which makes three things hard: confirming candidates found manually or by static analysis, writing a regression test that reliably triggers a fixed race, and getting a fuzzer to reach code paths that only execute concurrently. Project Zero's approach traces memory accesses and injects delays keyed on the call stack, turning a matter of luck into an interleaving you can specify.
Sources: Project Zero
AI security
ChatGPT: one planted instruction can hand a user's Gmail data to another account
In Check Point Research's proof of concept, an instruction planted in a conversation makes ChatGPT quietly work for an attacker while answering the user's question as usual: the hidden work reads data from the user's connected Gmail account and passes it to a second ChatGPT account through a covert channel. The research traces this to the shared surface of the sandboxed execution environment — once an assistant can run code, install dependencies, read user files and reach connected services, its security model is no longer that of text generation.
Sources: Check Point Research · The Hacker News
Other
[Added detail] ShinyHunters claims data from Florida's DAVID DMV platform
The group says it breached DAVID, the online platform for the Florida Department of Motor Vehicles database, and stole more than 200,000 records about drivers in the state, posting proof samples and a September 11 deadline on its leak site.
Sources: Bleeping Computer · RansomLook
DoppelCart: a fake-storefront network built on 119,000 domains
The operation runs more than 119,000 domains as fake e-shops whose purpose is to steal payment card details.
Sources: Bleeping Computer
Liquid Network: nearly 4,000 bitcoin taken, 3,400 returned the next day
Someone took nearly 4,000 bitcoin from the Liquid sidechain through an Elements bug on Sunday, September 6; Bitcoin's public record shows 3,400 came back the following day, with about 598.5 still missing. Liquid holds real bitcoin to back a token called L-BTC, and the network remains paused, so holders cannot convert that token back into bitcoin.
Sources: The Hacker News
Grindr pays £26 million to settle U.K. data-sharing claims
The suit, filed in April 2024, alleged the app violated U.K. privacy law by sharing users' personal information — including HIV status — with third parties for commercial purposes such as advertising. The settlement is about $35.1 million.
Sources: The Hacker News
The EU Cyber Resilience Act's vulnerability reporting duties take effect September 11
For flaws already under active exploitation, vendors have as little as 24 hours to report.
Sources: Bleeping Computer