Security news

Latest security news

Wed, 2 Sept 2026

  1. SonicWall security advisory (AV26-872) – Update 1

    Serial Number: AV26-872 Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: SMA1000 - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory SonicWall Security Advisories CISA KEV: CVE-2026-83548 CISA KEV: CVE-2026-83549

    CriticalUsed in attacksCanadian Centre for Cyber SecuritySonicWall
  2. Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

    Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path. CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions. Although, by leveraging the SSRF vulnerability CVE-2026-83548 an attacker could potentially exploit CVE-2026-83549 to execute arbitrary OS commands without prior authentication. SonicWall SMA1000 appliances are enterprise secure remote access gateways used to provide employees and other authorized users with acces

    CriticalUsed in attacksRapid7 BlogSonicWall
  3. SonicWall's SMA1000 boxes under active attack again

    Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'

    The RegisterSonicWall
  4. Progress Software security advisory (AV26-875)

    Serial number: AV26-875 Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672) Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)

    Canadian Centre for Cyber SecurityProgress
  5. Google security advisory (AV26-874)

    Serial number: AV26-874 Date: September 2, 2026 As of September 2, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.75 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop

    Canadian Centre for Cyber SecurityGoogle, Chrome
  6. Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

    The Hacker News
  7. HPE security advisory (AV26-873)

    Serial number: AV26-873 Date: September 2, 2026 As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking AOS-CX Prior to or equal to 10.10.1180 Prior to or equal to 10.13.1180 Prior to or equal to 10.16.1051 Prior to or equal to 10.17.1021 Prior to or equal to 10.18.0001 HPE Networking Fabric Composer Prior to or equal to 7.3.3 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05133 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer HPESBNW05134 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX) HPE Security Bulletin Library

    Canadian Centre for Cyber Security
  8. [Control systems] Schneider Electric security advisory (AV26-871)

    Serial Number: AV26-871 Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on NetBotz 5 - 750/755 Products Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute™ Serial Shutdown Schneider Electric Security Notifications

    Canadian Centre for Cyber Security
  9. Two critical Chrome flaws put users at risk on malicious websites

    Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.

    Malwarebytes LabsChrome
  10. Hackers Chain Two New SonicWall Zero-Day Vulnerabilities

    SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild

    Infosecurity MagazineSonicWall

About this news

1,265
Stories
33
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets