Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
A CVSS score 6.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L severity vulnerability discovered by 'WONJOON HWANG (@joon1337)' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Adam Bedard' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Adam Bedard' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Xavier DANEST' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 7.5 AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'GangMin Kim' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N severity vulnerability discovered by 'Dmitry "InfoSecDJ" Janushkevich of TrendAI Zero Day Initiative' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'NiNi (@terrynini38514) from the DEVCORE Research Team' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 10.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'Habibullo Izzatilloyev' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
A CVSS score 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by 'YJK(@YJK0805) of ZUSO ART' was reported to the affected vendor on: 2026-09-02, 1 days ago. The vendor is given until 2026-12-31 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
EVerest 2025.9.0 - DoS
Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
PodcastGenerator 3.2.9 - Stored XSS
Ghost_CMS 6.19.0 - Remote Code Execution
Langflow 1.10.0 - RCE
Fullhan FH8626V100 - Multiple Vulnerabilities
Marimo 0.20.4 - RCE
Wolf CMS 0.8.3.1 - RCE v
Payload CMS 3.72.0 - Blind SQL Injection
Bludit CMS - Stored XSS
Grav CMS 2.0.7 - RCE
miniOrange 5.4.3 - Unauthenticated Auth Bypass
EasyAppointments 1.5.1 - Blind SQL Injection
C-MOR 6.0104 - Directory Traversal
C-MOR 6.0104 - Cross-Site Scripting (XSS)
CubeCart 6.7.4 - SQL injection
CubeCart 6.7.4 - SQL
CubeCart 6.7.4 - Stored XSS
CubeCart 6.7.4 - Cross-Site Scripting
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
Langflow 1.8.4 - Path Traversal to Remote Code Execution