Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Tue 15 Sep

Parallels Desktop ParaShells LPE to root (CVE-2026-90894); fix in 27.0.0 — Intel Macs cannot install

JFrog (15 September 2026) documents ParaShells: an unprivileged local user on macOS can get root via Parallels Desktop's prl_disp_service (world-writable Unix socket, weak local-client auth, appliance-extract argument injection into tar --use-compress-program). Lab-proven on Desktop 26.4.0 build 57513 (Apple silicon); treat installs that still expose the same InstallAppliance extract template and dispatcher socket as in scope. CVE-2026-90894. Fixed in Parallels Desktop 27.0.0 (JFrog: fix shipped 1 Sep; CVE/blog 14–15 Sep). THN notes Intel Macs cannot install Desktop 27 — those hosts need interim local-account lockdown / vendor guidance. No in-the-wild exploitation reported by JFrog. Primary: JFrog research blog.

JFrog — ParaShells / Parallels Desktop root shell

vulnerabilities

Vulnerabilities

Tue 15 Sep

Google Pixel Cellular Modem EoP CVE-2026-58704 (CVSS 8.0); limited targeted exploitation

Google’s September 2026 Pixel update (patch level 2026-09-05) addresses CVE-2026-58704 in the Cellular Modem: improper authorization / logic error enabling remote (proximal/adjacent) privilege escalation with low privileges, no user interaction. NVD (published 15 September 2026; Google as source) scores CVSS 3.1 8.0 (AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). BleepingComputer (16 September 2026) cites Google’s Pixel bulletin warning of indications the flaw “may be under limited, targeted exploitation.” Same bulletin set covers 110 Pixel issues including additional critical/high RCE and privilege-escalation fixes. Distinct from desk card android-september-2026-bulletin (AOSP OEM bulletin). Apply Pixel Security update to 2026-09-05+. Primary: NVD CVE-2026-58704; wire: BleepingComputer; vendor bulletin URL (may require Google developer sign-in).

NVD — CVE-2026-58704 (published 15 Sep 2026)

vulnerabilities network

Vulnerabilities

Tue 15 Sep

Chrome 153.0.8010.47/.48 (42 fixes) and Firefox 156 (MFSA 2026-90); no in-wild claim

Google Stable Channel Update for Desktop (15 September 2026) promotes Chrome to 153.0.8010.47/.48 (Windows/Mac) and 153.0.8010.47 (Linux) with 42 security fixes. Critical entries include CVE-2026-91726 (OOB read in WebGL), CVE-2026-91721 (UAF in Internals), and CVE-2026-91749 (UAF in Workers), plus numerous High UAFs, race conditions, and related issues. Distinct from desk card cve-2026-87491 (Chrome 153.0.8010.36/.37 V8 OOB-write 0-day on 8 Sep). Mozilla MFSA 2026-90 (announced 15 September 2026) ships Firefox 156 with individual CVEs for high-impact bugs (privilege escalation / UAF / WebGL boundary issues among others; Thunderbird 156 / ESR trains also updated per SecurityWeek). Neither vendor claims exploitation in the wild for this batch. SecurityWeek (16 Sep) summarised ~115 combined defects. Primary: Chrome Releases + Mozilla MFSA 2026-90.

Chrome Releases — Stable desktop 153.0.8010.47/.48 (15 Sep 2026)

vulnerabilities network

Vulnerabilities

Tue 15 Sep

Oracle September 2026 CSPU: 673 new patches; Access Manager and OID LDAP at CVSS 10.0

Oracle Critical Security Patch Update advisory — September 2026 (Rev 1, 15 September 2026) contains 673 new security patches across product families. SecurityWeek (16 September 2026) notes the matrices cover on the order of 800+ CVE IDs including third-party component fixes, with more than 100 critical-severity issues and over 240 remotely exploitable without authentication. Largest batches include Oracle E-Business Suite, Fusion Middleware, and Hyperion. Notable CVSS 10.0 entries include Oracle Access Manager Authentication Engine CVE-2026-71133 (HTTP, unauthenticated network, versions 12.2.1.4.0 and 14.1.2.1.0) and Oracle Internet Directory OID LDAP Server CVE-2026-83059 (LDAP, unauthenticated network, 12.2.1.4.0 and 14.1.2.1.0). Oracle again warns of exploitation attempts against already-patched issues where customers delayed applying updates; no claim in the advisory that these September flaws are exploited in the wild. Apply the September 2026 CSPU for each product family you run. Distinct from desk card oracle-cspu-20260818. Primary: Oracle CSPU September 2026; wire: SecurityWeek 16 Sep.

Oracle CSPU September 2026 (Rev 1, 15 Sep 2026)

vulnerabilities cloud

Vulnerabilities

Tue 15 Sep

Acronis Backup plugin for cPanel/WHM and Plesk: Linux LPE CVE-2026-87886 (CVSS 7.8); limited in-the-wild exploitation

Acronis security advisory SEC-10986 / update UPD-2609-3d72-20a7 (wired by BleepingComputer 15 September 2026) covers CVE-2026-87886, a high-severity Linux local privilege escalation in Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Acronis assigns severity 7.8. A low-privileged attacker can raise privileges on a vulnerable Linux host without user interaction; further exploit detail withheld while patches propagate. Acronis says exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM plugin deployments (assessment based on a single report from a potentially affected customer; no public IoCs released). Affected: cPanel & WHM plugin builds earlier than 1.9.3.1021 (fixed 1.9.3 HF3); Plesk extension builds earlier than 1.8.11.638 (fixed 1.8.11). Apply those updates immediately. Primary: Acronis SEC-10986; wire: BleepingComputer 15 Sep. UPDATE 16 September 2026: CISA added CVE-2026-87886 to KEV (same alert as Cisco ISE CVE-2026-76460). Distinct from desk card cve-2026-60004 (Gitea / Red Heron).

Acronis SEC-10986 — CVE-2026-87886

vulnerabilities cloud

Vulnerabilities

Tue 15 Sep

WooCommerce Wholesale Lead Capture: unauth file upload to PHP webshell (CVE-2026-27540); actively exploited

BleepingComputer (15 September 2026) relays Wordfence/Defiant telemetry that attackers are actively exploiting CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture WordPress plugin. Unauthenticated AJAX action wwlc_file_upload_handler accepts a user-controlled file_settings allowlist, letting attackers permit .php uploads and drop webshells (researcher: Teemu Saarentaus). Affected: versions 2.0.3.1 and older; fixed in 2.0.3.2 (released 20 February). Wordfence reports 100,000+ blocked attacks with spikes around 4–17 June, 1 July, and 30 August 2026; The Hacker News (16 September) cites CVSS 9.8 and lists recent attacker IPs (including 92.241.13.213, 31.59.129.150, 92.241.13.140, 23.137.105.214, 23.180.120.140, 104.194.9.138, 187.75.114.36, 114.10.43.203, 37.114.144.209 and IPv6 2a0f:85c1:840:5389::1). Hunt admin-ajax.php calls to wwlc_file_upload_handler, unexpected PHP under uploads (e.g. shell.php), and unknown admin accounts; upgrade to 2.0.3.2+. Primary wire: BleepingComputer; UPDATE 17 Sep: CVSS + IoCs from THN/Wordfence.

BleepingComputer — WooCommerce Wholesale Lead Capture CVE-2026-27540 (15 Sep 2026)

vulnerabilities cloud

Vulnerabilities

Tue 15 Sep

Microsoft Windows Shell RCE (CVE-2026-69829); CVSS 9.8 — WASOC 20260915001

WA Cyber Security Unit advisory 20260915001 (15 September 2026, TLP:CLEAR) highlights CVE-2026-69829, a Critical remote code execution flaw in Microsoft Windows Shell with CVSS 9.8. WASOC states successful exploitation could allow an unauthenticated attacker to execute arbitrary code and potentially fully compromise affected systems. Affected products/versions are as listed by Microsoft on the MSRC update-guide entry for CVE-2026-69829 (JS-rendered; versions not mirrored here beyond vendor listing). WASOC reports no exploitation observed on Western Australian Government networks at time of writing and recommends applying Microsoft’s fixes per normal patch timeframes. Primary: Microsoft MSRC CVE-2026-69829; AU wire: WASOC 20260915001.

Microsoft MSRC — CVE-2026-69829 (Windows Shell RCE)

vulnerabilities australia

Vulnerabilities

Tue 15 Sep

Canonical LXD: multiple critical flaws allow root command execution on host (WASOC 20260915003); CVSS 9.9

WA Cyber Security Unit advisory 20260915003 (15 September 2026, TLP:CLEAR) relays Canonical LXD updates for eight Critical issues (CVE-2026-66897, CVE-2026-66898, CVE-2026-63300, CVE-2026-63299, CVE-2026-63297, CVE-2026-63296, CVE-2026-63294, CVE-2026-62420), each listed at CVSS 9.9. Successful exploitation can let a remote attacker achieve root command execution on the LXD host. Affected lines per WASOC: LXD 6.x prior to 6.10; 5.21.x prior to 5.21.7; 5.0.x prior to 5.0.9; all versions prior to 4.0.13. Canonical GitHub advisory GHSA-q39m-8fx9-42fv (CVE-2026-66897 example) documents instance template path traversal to arbitrary host file write as root, with patched versions including 4.0.13, 5.0.9, 5.21.7, 6.9-ab8fad2, and 6.10; related LXD GHSAs cover further path-traversal / privilege issues in the same wave. WASOC reports no exploitation observed on Western Australian Government networks at time of writing. Patch to vendor-fixed LXD builds; review Canonical LXD security advisories for the full set. Primary: Canonical LXD GHSA index; AU wire: WASOC 20260915003.

Canonical LXD GitHub Security Advisories (patched 4.0.13 / 5.0.9 / 5.21.7 / 6.10)

vulnerabilities australia cloud

Vulnerabilities

Mon 14 Sep

LiteSpeed Web Server Enterprise: critical privilege escalation to root on shared hosts (fix 6.3.7)

cPanel Security advisory (14 September 2026) warns of a critical privilege-escalation flaw in LiteSpeed Web Server Enterprise: on shared-hosting servers a malicious low-privilege website user could gain root-level access, bypassing account isolation including CageFS, and access or alter other sites and the server. Affected: LiteSpeed Web Server Enterprise prior to v6.3.7. Fix: upgrade to 6.3.7 or later. cPanel/LiteSpeed publish the forced update command /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 (auto-update may lag; as of THN 15 Sep, download page still listed 6.3.6 as stable). LiteSpeed store announcement for 6.3.7 (11 September 2026) lists three security changes (lscgid auth, internal redirect URL validation, block internal-use env vars from .htaccess) without naming a CVE or privilege-escalation root cause; neither cPanel nor LiteSpeed assigned a public CVE or CVSS for this Enterprise web-server issue as of 15 September 2026 desk check. Advisory does not state in-the-wild exploitation for this Enterprise flaw (distinct from earlier actively exploited LiteSpeed cPanel-plugin issues CVE-2026-48172 and CVE-2026-54420 already on this desk). OpenLiteSpeed not named in the cPanel advisory. Primary: cPanel; vendor release: LiteSpeed 6.3.7 announcement; wire: The Hacker News (15 Sep 2026).

cPanel — LiteSpeed Enterprise security advisory (14 Sep 2026)

tech cloud identity

Vulnerabilities

Mon 14 Sep

n8n AI Agents: Project Viewer node-exec (CVE-2026-65015) and MCP credential leak (CVE-2026-59207)

Antonio De Turris (deturris.io, 14 September 2026) details two authorization bypasses in n8n’s AI Agents feature. CVE-2026-65015: a read-only Project Viewer can instruct an agent’s run_node_tool to execute arbitrary n8n nodes (including HTTP Request) with the project’s credentials; if Execute Command is enabled on self-hosted, that path can reach host command execution. Affected: all versions before 2.29.8, plus 2.30.0; fixed in 2.29.8 and 2.30.1. GitHub GHSA-x5vx-c2c8-m3w9 rates High (CVSS 4.0 overall 7.2). CVE-2026-59207: the agent MCP client sends credential headers without enforcing “Allowed HTTP Request Domains”, so a use-only credential holder can point MCP at an attacker host and exfiltrate the secret. Affected: all before 2.27.4, plus 2.28.0; fixed in 2.27.4 and 2.28.1. GHSA-h44j-f5r5-ph73 High (CVSS 4.0 overall 7.1). Reported June 2026; vendor advisories published with the fixes. Primary: researcher writeup; vendor: n8n GitHub security advisories.

De Turris — n8n AI Agents authorization bypasses (14 Sep 2026)

tech ai cloud identity

Vulnerabilities

Mon 14 Sep

IBM Db2 Mirror for i web GUI: Silent Signal pre-auth chain to Liberty JSP RCE and QSECOFR

Silent Signal (14 September 2026) documents a pre-authentication vulnerability chain in the IBM Db2 Mirror for i web interface (Db2MirrorServlet on the IBM i administrative Liberty instance; lab IBM i V7R5, GUI WAR build timestamp late 2025). The write-up describes how authentication/validation filters can be confused, enabling unauthenticated reach into powerful admin features (arbitrary file read via log/trace viewers, attacker-influenced writes into an expanded WAR path that becomes JSP execution in Liberty, then a native helper crossing to QSECOFR on the local IBM i system). No CVE identifier is assigned in the post; the author withholds exploit/JSP payload bodies and frames the piece as vulnerability mechanics plus hardening guidance. Confirm IBM PSIRT/bulletin status for your Db2 Mirror for i / IBM i web stack build before declaring patched. Primary: Silent Signal; no separate vendor bulletin URL confirmed at desk time.

Silent Signal — Db2 Mirror for i pre-auth RCE chain (14 Sep 2026)

vulnerabilities identity network

Vulnerabilities

Mon 14 Sep

Cisco Secure Email Gateway AsyncOS SQL injection to root (CVE-2026-76461); exploited; CVSS 9.8

Cisco PSIRT advisory cisco-sa-esa-inj-2bLVGmhX (14 September 2026) covers CVE-2026-76461, a Critical SQL injection in email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway (physical and virtual, any configuration). Unauthenticated remote attackers can send a crafted email with malicious SQL statements and gain command execution as root on the underlying OS. Cisco CVSS 3.1 base 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CWE-89; Bug CSCwu56234. Not affected: Secure Email and Web Manager, Secure Web Appliance. Cisco PSIRT became aware of active exploitation in September 2026; Cloud customers with detected malicious activity were contacted directly; Cloud fleet already upgraded to 16.5.0-780. IoC guidance: grep mail_logs for suspicious SQL (example COPY.*TO PROGRAM); also review external network/firewall logs because root access can erase on-box evidence. No workarounds. Fixed AsyncOS: 15.5 and earlier → 15.5.5-014; 16.0 → 16.0.4-302; 16.5 → 16.5.0-780 (Cisco strongly recommends 16.5.0-780). CISA added CVE-2026-76461 to KEV with FCEB remediation due 17 September 2026 (wire: BleepingComputer / THN 15 Sep). Same-day Cisco also shipped other critical SEG/SEWM fixes (CVE-2026-76440/76441/20353/76443) without claimed in-the-wild use — covered here only as context, not separate desk cards. Primary: Cisco PSIRT; wires: BleepingComputer, The Hacker News, SecurityWeek (15 Sep 2026).

Cisco PSIRT cisco-sa-esa-inj-2bLVGmhX (CVE-2026-76461, 14 Sep 2026)

vulnerabilities network cloud