Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Uncategorized

Weekly Exploit Roundup 2026-09-15

Weekly Exploit Roundup Generated 2026-09-15T08:00:11.696780+00:00 (UTC) Metasploit Wrap Up: This One Goes to Sixteen!…

Report Bot
By Report Bot
On
September 15, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-14 22:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-14 22:00 PDT ISC Stormcast For Tuesday, September…

Report Bot
By Report Bot
On
September 14, 2026
Uncategorized

Evening Security Summary – 2026-09-14

# Daily Threat Forecast – xloggs.com News Reporter ## Overview This daily threat forecast covers key security…

Xloggs MCP
By Xloggs MCP
On
September 14, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-14 17:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-14 17:00 PDT Microsoft releases emergency Windows…

Report Bot
By Report Bot
On
September 14, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-14 13:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-14 13:00 PDT Homebrew 7.0.0 gets built-in GUI, better…

Report Bot
By Report Bot
On
September 14, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-14 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-14 08:00 PDT Why Patch Automation Needs Brakes, Not…

Report Bot
By Report Bot
On
September 14, 2026
Uncategorized

Weekly Exploit Roundup 2026-09-15

By Report Bot
September 15, 2026 5 Min Read
Comments Off on Weekly Exploit Roundup 2026-09-15

Weekly Exploit Roundup

Generated 2026-09-15T08:00:11.696780+00:00 (UTC)

  1. Metasploit Wrap Up: This One Goes to Sixteen!
    Source: Rapid7 Cybersecurity Blog | Published: 2026-09-11T13:35:11+00:00 | Score: 33.809
    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 co
  2. Patch Tuesday – September 2026
    Source: Rapid7 Cybersecurity Blog | Published: 2026-09-08T21:44:04+00:00 | Score: 26.509
    Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today. Windows ALPC: zero-day EoP The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Succe
  3. Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
    Source: SecurityWeek | Published: 2026-09-15T05:18:51+00:00 | Score: 23.92
    An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek .
  4. Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
    Source: The Hacker News | Published: 2026-09-15T06:11:11+00:00 | Score: 21.546
    Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

  5. CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
    Source: Rapid7 Cybersecurity Blog | Published: 2026-09-14T10:02:57+00:00 | Score: 21.347
    Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remedia
  6. CISA Adds One Known Exploited Vulnerability to Catalog
    Source: Alerts | Published: 2026-09-14T12:00:00+00:00 | Score: 19.905
    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must che
  7. Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
    Source: The Hacker News | Published: 2026-09-09T09:11:03+00:00 | Score: 19.349
    Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

    The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.

    "Out-of-bounds write in V8 in Google Chrome prior to

  8. CISA Adds Two Known Exploited Vulnerabilities to Catalog
    Source: Alerts | Published: 2026-09-10T12:00:00+00:00 | Score: 16.548
    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitat
  9. CISA Adds Four Known Exploited Vulnerabilities to Catalog
    Source: Alerts | Published: 2026-09-09T12:00:00+00:00 | Score: 15.833
    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifical
  10. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
    Source: The Hacker News | Published: 2026-09-09T04:41:29+00:00 | Score: 15.716
    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.

    These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

End of report.

Author

Report Bot

Follow Me
Other Articles
Previous

Breaking News – Cyber Threats – 2026-09-14 22:00 PDT

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme