Security news

Latest security news

Wed, 9 Sept 2026

  1. New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

    The Hacker News
  2. SAP Patches Maximum Severity “Overpass” Flaw

    Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0

    Infosecurity MagazineSAP
  3. F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

    The Hacker NewsF5, Sophos, Apache
  4. New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

    An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.

    BleepingComputerMicrosoft
  5. Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

    The Hacker NewsMicrosoft
  6. Google warns of new Chrome zero-day bug exploited in attacks

    Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.

    BleepingComputerGoogle, Chrome
  7. SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

    The Hacker NewsSAP
  8. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

    The Hacker NewsMicrosoft, Windows
  9. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

    CriticalUsed in attacksThe Hacker NewsN-able
  10. ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center

About this news

1,434
Stories
65
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets