[HIGH] – Google Patches Actively Exploited Chrome V8 Flaw
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.
[CRITICAL] – CISA Adds N-able N-central RCE to KEV Catalog
CISA added a pre-authentication N-central remote-code-execution flaw to KEV; self-hosted administrators should apply N-able's hotfix.
[MEDIUM] – Calif Discloses Mitigated WeChat Zero-Click Worm Demo
Calif demonstrated a zero-click WeChat account-takeover worm; it says Tencent has mitigated the exploit.
[HIGH] – Google Details Agentic AI Credential-Harvesting Campaign
Google observed an agent-enabled credential-harvesting campaign planned and executed in under six hours.
[HIGH] – Check Point Reports Cross-Account ChatGPT Data-Leakage Channel
Check Point demonstrated a prompt-driven ChatGPT channel that could relay connected-app data across accounts.
[CRITICAL] – SAP Releases Fix for CVE-2026-44756 EPP Memory Corruption
SAP's September security updates address a CVSS 10.0 Extended Passport Processing memory-corruption vulnerability.
[CRITICAL] – FreeIPA Flaw Enables Unauthenticated Administrator Access
A critical FreeIPA flaw can give an unauthenticated LDAP client administrator-group membership.
[CRITICAL] – Sangoma Switchvox RCE Added to CISA KEV After Active Exploitation
CISA-listed, actively exploited Switchvox SQL injection can enable unauthenticated remote code execution.
[CRITICAL] – Microsoft Patches Two Actively Exploited Windows Elevation Flaws
Microsoft addressed two Windows privilege-escalation flaws that CISA added to the KEV Catalog on September 8.
[HIGH] – Berlin Investigates Newly Published Credentials and Government-Breach Data
Berlin says newly released breach data includes login credentials; officials are assessing affected systems and people.
