Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Security Weekly Digest

22 September 2026

6 vulnerabilities added to CISA's exploited-in-the-wild catalog this week.

One week of Security Weekly Digest, 5 stories, as published.

Exploited CVEs

CVE-2025-39682: Linux Kernel

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Why it matters — Confirmed exploited in the wild. CVSS 9.8 (CRITICAL). CISA remediation deadline 21 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-76460: Cisco Identity Services Engine

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Why it matters — Confirmed exploited in the wild. CVSS 10.0 (CRITICAL). CISA remediation deadline 19 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-7273: Zyxel GS1900 Series Switches

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 24 Sep 2026 — 2 days out.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-58704: Google Pixel

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Why it matters — Confirmed exploited in the wild. CVSS 8.8 (HIGH). CISA remediation deadline 19 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Exploited CVEs

CVE-2026-87886: Acronis Backup

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.

Why it matters — Confirmed exploited in the wild. CVSS 7.8 (HIGH). CISA remediation deadline 19 Sep 2026 — already passed.

CISA KEV · 22 September 2026 · Read the original →

Looks like we're patching the entire stack this weekend.

5 stories, every Tuesday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue