Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

Exploits, Breaches & Advisories. Published every Tuesday, here and by RSS.

67 stories 10 issues 9 categories

Exploited CVEs Breaches Supply Chain Cloud & SaaS Vulnerabilities Threat Actors Ransomware Policy & Compliance Tooling

Top stories

RSS
Exploited CVEs

Langflow and Rails Flaws Actively Exploited

Threat actors are actively exploiting critical vulnerabilities in Langflow (CVE-2026-0768) and Ruby on Rails (CVE-2026-66066) as of September 1, 2026. The Langflow flaw allows arbitrary Python code execution, while the Rails vulnerability enables unauthenticated attackers to read arbitrary files and potentially achieve remote code execution, leading to credential harvesting and command-and-control activity.

Why it matters — Organizations using Langflow or Ruby on Rails with Active Storage and libvips must immediately patch to prevent unauthenticated remote code execution and data exposure.

The Hacker News · 08 September 2026 · Read the original →

Exploited CVEs

CVE-2026-7273: Zyxel GS1900 Series Switches

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 24 Sep 2026 — 2 days out.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2025-39682: Linux Kernel

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 21 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-76460: Cisco Identity Services Engine

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 19 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-58704: Google Pixel

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 19 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Looks like we're patching the entire stack this weekend.

Weekly editions

Each edition is one week's digest exactly as it was published — a summary of the week, then the stories.