Skip to main content

GitLab CE and EE Repository Commits API Path Traversal Allows Unauthenticated Arbitrary File Read (CVE-2026-85706)

Scope: GitLab Community Edition and Enterprise Edition Self-Managed Installations (GitLab.

Google Pixel September 2026 Update Patches Modem Privilege Escalation Under Targeted Exploitation and 46 Critical Flaws (CVE-2026-58704)

Scope: Google Pixel Devices (All Models Running Security Patch Level Earlier Than 2026-09-

Cisco Secure Email Gateway Unauthenticated Root Command Execution via Email Parsing Zero-Day (CVE-2026-76461)

Scope: Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) — Virtual

Microsoft Exchange Server Unauthenticated Network Remote Code Execution via Double-Free Vulnerability (CVE-2026-55007)

Scope: Microsoft Exchange Server (All Supported On-Premises Versions Prior to September 20

Gitea Self-Hosted Git Service Unauthenticated RCE Actively Exploited to Deploy Cryptocurrency Miners (CVE-2026-60004)

Scope: Gitea Versions 1.17 through 1.27.0 (All Versions Prior to 1.27.1)

Microsoft Defender "ShieldCrash" Zero-Day Bypasses September 2026 Patch, SYSTEM File Read Confirmed on All Windows Versions

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

ConnectWise ScreenConnect Authentication Bypass Under Active Exploitation Grants Full Remote Control of Managed Endpoints (CVE-2026-77924)

Scope: ConnectWise ScreenConnect (All Versions Prior to Latest Patched Release)

Subscribe to Advisories