Security news

Latest security news

Thu, 3 Sept 2026

  1. F5 security advisory (AV26-878)

    Serial Number: AV26-878 Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0 NGINX JavaScript 9.9 Prior to 1.0.1 APM Clients Prior to 7.2.6 BIG-IP APM Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. K000162872: Out-of-band Security Notification (September 2, 2026)

    Canadian Centre for Cyber SecurityF5, Nginx
  2. Jenkins security advisory (AV26-877)

    Serial Number: AV26-877 Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a_4e5e4ec98 Jenkins Microsoft Entra ID (previously Azure AD) Plugin Prior to or equal to 710.v0b_ff8e9cc2d2 Jenkins Parameterized Remote Trigger Plugin Prior to or equal to 3.2.2 Jenkins Performance Plugin Prior to or equal to 1015.v09ca_52b_3370e Jenkins Pipeline: Build Step Plugin Prior to or equal to 599.v4b_67ea_11b_152 Jenkins SAML Plugin Prior to or equal to 4.618.v441a_27fa_46d2 Jenkins Script Security Plugin Prior to or equal to 1412.v7737b_3405f86 Jenkins TICS Plugin Prior to or equal to 2025.1.1 Jenkins ThinBackup Plugin Prior to or equal to 2.1.4 Jenkins XebiaLabs XL Deploy Plugin Prior to or equal to 26.1.0 Jenkins update-center2 Prior to or equal to 3.18.3 The Cyber Centre encourages use

    Canadian Centre for Cyber SecurityMicrosoft, GitLab, Jenkins
  3. Cisco security advisory (AV26-876)

    Serial Number: AV26-876 Date: September 3, 2026 As of September 2, 2026, Cisco is affected by vulnerabilities in the following products: Cisco IOS XR Software Multiple versions Cisco Nexus 9000 Series Switches Multiple products Cisco Desk Phone 9800 Series and Video Phone 8875 Prior to 5.0(1) IP Phone 7800 and 8800 Prior to 14.4(1)SR3 IP Phone 8845 and 8865 Prior to14.4(1)SR4 Wireless IP Phone 8821 Prior to 11.0(6)SR8 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability Cisco IOS XR Software Security Hardening Release: September 2026 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability Cisco Security Advisories

    Canadian Centre for Cyber SecurityCisco, iOS
  4. Your phone or computer may soon ask how old you are

    California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.

    Malwarebytes LabsLinux
  5. Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of

    The Hacker News
  6. Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in

    The Hacker News
  7. CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

    CriticalUsed in attacksThe Hacker NewsSonicWall

Wed, 2 Sept 2026

  1. AI's Vulnerability Surge May Be More Manageable Than First Feared

    New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

    Dark Reading
  2. SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

    Dark ReadingSonicWall
  3. JFrog security advisory (AV26-867) – Update 1

    Serial number: AV26-867 Date: September 1, 2026 Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database. Artifactory Self-Managed Releases JFrog Security Advisories CISA KEV: CVE-2026-82329

    CriticalUsed in attacksCanadian Centre for Cyber SecurityJFrog

About this news

1,265
Stories
32
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets