Security news
Latest security news
Tue, 8 Sept 2026
- Ivanti security advisory (AV26-897)
Serial Number: AV26-897 Date: September 8, 2026 As of September 8, 2026, Ivanti is affected by vulnerabilities in the following products: Endpoint Manager Mobile Prior to 12.10.0.0 Prior to 12.9.0.2 Prior to 12.8.0.4 Neurons for ITSM (Cloud/SaaS) Prior to mo2026.2 Neurons for ITSM On-Prem Prior to 2025.2 Sept 2026 Security Patch Prior to 2025.3 Sept 2026 Security Patch Prior to 2025.4 Sept 2026 Security Patch Prior to 2026.1 Sept 2026 Security Patch Prior to 2026.2 Sentry Prior to R10.8.2 Prior to R10.7.3 Prior to R10.6.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory Ivanti Neurons for ITSM (Multiple CVEs) Security Advisory - Ivanti Endpoint Manager Mobile (CVE-2026-18851) Security Advisory Ivanti Sentry (CVE-2026-83527) September 2026 Security Update
Canadian Centre for Cyber SecurityIvanti - September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
SANS Internet Storm CenterMicrosoft, Windows - Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
Serial Number: AV26-896 Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authen
Canadian Centre for Cyber SecurityMicrosoft, Windows, Linux - Adobe security advisory (AV26-888) – Update 1
Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal
Canadian Centre for Cyber SecurityAdobe - Microsoft releases Windows 10 KB5122878 extended security update
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes.
BleepingComputerMicrosoft, Windows - Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
BleepingComputerMicrosoft2 outlets - Commvault security advisory (AV26-895)
Serial Number: AV26-895 Date: September 8, 2026 As of September 8, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 11.36.0 Prior to 11.36.123 11.40.0 Prior to 11.40.72 11.44.0 Prior to 11.44.20 11.46.0 Prior to 11.46.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CV_2026_07_1: Command Center API Authentication Bypass Commvault Cloud Security Advisories
Canadian Centre for Cyber Security - SAP security advisory – September 2026 monthly rollup (AV26-894)
Serial Number: AV26-894 Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior or equal to 2.7.6 prior or equal to 3.9.6 prior or equal to 4.0.2 SAP NetWeaver (SAP GUI for Java) - version BC-FES-JAV 8.10 SAP Integration Suite Version Cloud Integration - Trading Partner Management V2 2.9.2, Version B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0 SAP NetWeaver Business Client – versions BC-WD-CLT-BUS 8.00 and 8.10 SAP NetWeaver Application Server for ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become
Canadian Centre for Cyber SecuritySAP - Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
BleepingComputerMicrosoft, Windows - Hitachi security advisory (AV26-893)
Serial Number: AV26-893 Date: September 8, 2026 As of September 8, 2026, Hitachi is affected by vulnerabilities in the following product: Cosminexus Component Container Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerability in Cosminexus Hitachi Vulnerability Information
Canadian Centre for Cyber Security
About this news
- 1,265
- Stories
- 19
- Added in the last 24 hours
- 13
- Critical in the last 7 days
- 4
- Reported by several outlets