we_are_coded.by CODE · The world, decoded
БГ
we are coded

Security, p. 2

Security

68 stories · page 2 of 8
Security
CVE-2026-71362 (NVD, with the CISA KEV section)24 September 2026Vulnerabilities

A hole in Adobe Commerce and Magento entered the catalogue of actively exploited vulnerabilities

On 24 September CISA added CVE-2026-71362 to the KEV catalogue: incorrect authorisation in Adobe Commerce and Magento that can lead to privilege escalation without user action. The NVD record dates from 11 August. Adobe's bulletin did not open when we checked, so the facts rest on CISA and NVD.

Read →
Security
OpenAI23 September 2026Cyber defence

OpenAI gives Ukraine its vulnerability-hunting models to protect hospitals, power and telecoms

On 23 September OpenAI announced that the Ukrainian government gets access to the Daybreak programme for finding and fixing vulnerabilities. In the same announcement the company points to CERT Polska, which used its models to help find six holes in router software; per the Poles' own bulletin, it is MikroTik's.

Read →
Security
WordPress.org22 September 2026Vulnerabilities

WordPress 7.1.2 closes a critical hole that can let outside code in without an account

The urgent release of 22 September fixes CVE-2026-87902: an attacker with no password can make WordPress load a chosen PHP file from the server. With certain themes and server settings this can lead to remote code execution. The fix has been backported all the way to version 4.7.

Read →
Security
Check Point Blog22 September 2026Vulnerabilities

Two holes in Check Point and one in Arista are being used in attacks, and part of on-premises Arista has no fix yet

On 22 September CISA added three critical vulnerabilities to its catalogue of actively exploited ones. Check Point confirms attacks and has patches for both of its own. Arista says the hosted versions of VeloCloud Orchestrator are already patched, while for customer-installed ones fixes exist so far only for some release trains.

Read →
Security
CISA18 September 2026Vulnerabilities

Three holes in the Linux kernel went onto the exploited list, and their fixes are months old

CISA added three kernel vulnerabilities already used in attacks on 18 September, with a deadline of 21 September. Their NVD entries date from September and October 2025 and June 2026. The problem is the machines that never got the fix.

Read →
Security
CISA16 September 2026Vulnerabilities

Three holes in one day on the exploited list: Cisco ISE, the Pixel modem and Acronis backup for cPanel

CISA added three vulnerabilities already used in attacks on 16 September, with a patch deadline of 19 September. Closest to small business is the third - the backup plugin in hosting control panels.

Read →
Security
Cisco Security Advisory14 September 2026Vulnerabilities

A hole in Cisco's email gateway gives root with a single email, and CISA gave agencies three days

CVE-2026-76461 is an SQL injection in the mail parsing of Cisco AsyncOS. It needs no account, does not depend on configuration and is already being used in attacks. There is no workaround, only the upgrade.

Read →
Security
CISA11 September 2026Vulnerabilities

Two JFrog Artifactory flaws entered the catalog of exploited vulnerabilities, along with GitLab and ScreenConnect

On 11 September CISA listed four vulnerabilities as actively exploited. Two are in JFrog Artifactory, the server where companies keep their packages and artifacts. The other two are in GitLab, rated 10.0, and in ScreenConnect, and for those the deadline is only three days.

Read →
Security
CISA10 September 2026Routers

Two MikroTik RouterOS flaws are now used in attacks, and the fix dates from 3 September

On 10 September CISA listed CVE-2026-86060 and CVE-2026-67277 in RouterOS as actively exploited, with a deadline of 13 September. MikroTik released the fixes a week earlier and advises keeping SSH closed to untrusted networks.

Read →