FR
live
tag

#zero-day

D-Link confirms two critical, unpatched flaws in the DIR-822A router, with public exploits

On September 22, 2026, D-Link confirmed two critical flaws in the end-of-life DIR-822A router: a stack-based buffer overflow in the DHCP server (CVE-2026-86296, CVSS 10) and an out-of-bounds write in the L2TP parser (CVE-2026-86510, CVSS 9.9), both with public proof-of-concept code and no patch available. Replace or isolate these routers, and never expose them to the internet.

A zero-day turns Muse, Meta’s AI assistant, into a macOS backdoor

On September 22, 2026, researcher Patrick Wardle showed that an undocumented setting in Muse, Meta’s AI assistant, lets a simple local command redirect voice dictation and steal the account authentication token. Cut back the permissions you grant AI agents and wait for Meta’s fix before deploying new ones.

Google patches a Pixel modem zero-day exploited in targeted attacks

On September 16, 2026 Google confirmed exploitation of CVE-2026-58704, a privilege escalation in the Pixel cellular modem, in limited targeted attacks. Apply the September 2026 patch and make the Android patch level a compliance gate for your mobile fleet.

Chrome 153 fixes CVE-2026-87491, the seventh exploited V8 zero-day of 2026

On September 8, 2026, Google ships Chrome 153, fixing 230 vulnerabilities including CVE-2026-87491, an out-of-bounds write in V8 already exploited in the wild. Update to 153.0.8010.36 or later before the CISA deadline of September 23, and check every Chromium browser in your fleet, Edge, Brave and Opera included.

Chrome patches its sixth exploited zero-day of 2026, a V8 type confusion

On September 4, 2026, Google shipped an emergency Chrome update fixing CVE-2026-85046, a type confusion in the V8 engine already exploited in the wild and rated 8.8 on the CVSS scale. Update to Chrome 152.0.7977.82 or later and check every Chromium browser in your fleet, including Edge, Brave and Opera.

Two chained zero-days yield unauthenticated RCE on SonicWall SMA 1000 appliances

On September 1, 2026, SonicWall disclosed two flaws in the SMA 1000 line — a pre-authentication SSRF (CVE-2026-83548, CVSS 10) and an OS command injection (CVE-2026-83549) — already chained in the wild to reach remote code execution without credentials. Apply the hotfix now, and if compromise is confirmed, re-image the appliance instead of patching over the intrusion.

Metabase Zero-Day CVSS 10.0 Grants Full Admin Access Without Authentication

On August 8, 2026, Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was already being exploited in the wild. The vulnerability lets unauthenticated attackers gain administrator privileges and drain every connected database. Self-hosted Metabase admins must patch, revoke sessions, and rotate all secrets immediately.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss