Buletin zilnic de securitate cibernetică – 11 septembrie 2026

Daily Cybersecurity Bulletin – September 11, 2026

The September 11, 2026 bulletin presents actively exploited vulnerabilities in MikroTik, Citrix, and Cisco routers, new critical breaches in IBM systems, and security updates from Microsoft, SAP, and Check Point.

The security bulletin from September 11, 2026 highlights a high number of extreme severity vulnerabilities, a significant portion of which are already actively exploited in cyberattacks. We strongly recommend network administrators and security teams to urgently apply the available patches.

Actively Exploited Vulnerabilities

  • CVE-2026-86060 (MikroTik RouterOS): Incorrect neutralization of argument delimiters in a command, allowing attackers to modify the RouterOS policy mask and obtain elevated privileges. Details: NVD CVE-2026-86060.
  • CVE-2026-67277 (MikroTik RouterOS): Missing authentication for a critical function in the btest service, allowing kernel memory disclosure and Denial of Service (DoS) attacks. Details: NVD CVE-2026-67277.
  • CVE-2026-19490 (Citrix NetScaler): Authentication bypass vulnerability via alternative channel. When the appliance is configured as an AAA virtual server or Gateway, an unauthenticated attacker can bypass authentication. Details: NVD CVE-2026-19490.
  • CVE-2025-25249 (Fortinet Multiple Products): A heap-based buffer overflow vulnerability in FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands via specially crafted packets. Details: NVD CVE-2025-25249.
  • CVE-2026-87491 (Google Chromium V8): Out of Bounds Write in the V8 engine, allowing a remote attacker to execute arbitrary code inside the sandbox via compromised HTML pages. Affects multiple Chromium-based browsers (Chrome, Edge, Opera). Details: NVD CVE-2026-87491.
  • CVE-2026-20079 (Cisco Secure Firewall Management Center): Authentication bypass via alternative channel in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management, which allows an unauthenticated remote attacker to execute scripts and obtain root access on the underlying operating system. Details: NVD CVE-2026-20079.
  • CVE-2026-75650 (Adobe Commerce and Magento): Incorrect neutralization of special elements in a template engine, allowing attackers to execute arbitrary code. Details: NVD CVE-2026-75650.
  • CVE-2026-81963 (Microsoft Windows): Link following vulnerability in Windows Update Stack that allows a local attacker to obtain system privileges (SYSTEM). Details: NVD CVE-2026-81963.
  • CVE-2026-86218 (N-able N-central): Static code injection allowing remote code execution (RCE) without prior authentication. Details: NVD CVE-2026-86218.
  • CVE-2026-85880 (Microsoft Windows): Heap-based buffer overflow in Windows Advanced Local Procedure Call, allowing local privilege escalation. Details: NVD CVE-2026-85880.
  • CVE-2026-85046 (Google Chromium V8): Type Confusion in the V8 engine, allowing remote attackers to execute arbitrary code in the sandbox via specially designed HTML pages. Details: NVD CVE-2026-85046.

New Critical Vulnerabilities

  • CVE-2026-87929 (MaxSite CMS): Hardcoded session encryption key in the default configuration file, allowing unauthenticated attackers to generate administrator cookies and bypass authentication. Details: NVD CVE-2026-87929.
  • CVE-2026-9163 (GisLab Laboratory Management System): SQL Injection vulnerability in versions 1.4.03 to 1.5, facilitating unauthorized querying of databases. Details: NVD CVE-2026-9163.
  • CVE-2026-88899 (knowns): Incorrect validation of the x-opencode-directory header in the /api/opencode proxy endpoint, allowing attackers to perform file operations outside of the project root on the host system. Details: NVD CVE-2026-88899.
  • CVE-2026-89042 (passport-saml-encrypted): Optional SAML signature verification allows attackers to bypass authentication by sending unsigned SAML responses with arbitrary attributes and NameID. Details: NVD CVE-2026-89042.
  • CVE-2026-75940 (Lenovo Health Android Application): A security breach in the application distributed on the Chinese market allows unauthorized access to sensitive medical information. Details: NVD CVE-2026-75940.
  • CVE-2026-85025 (IBM Langflow OSS): Allows arbitrary code execution and accessing or modifying chat sessions via public MCP project endpoints due to poor session isolation. Details: NVD CVE-2026-85025.
  • CVE-2026-19646 (IBM Common Licensing Agent): Improper validation of the HTTP Host header, allowing users to be redirected to arbitrary domains. Details: NVD CVE-2026-19646.
  • CVE-2026-78573 (IBM ContextForge MCP Gateway): Use of default credentials in versions 1.0.0 to 1.0.7 allows remote attackers to obtain full administrative access. Details: NVD CVE-2026-78573.
  • CVE-2026-79724 (IBM Langflow OSS): OS command injection vulnerability due to poor neutralization of special elements in a command, facilitating command execution directly on the operating system. Details: NVD CVE-2026-79724.
  • CVE-2026-80424 (IBM DataStage on Cloud Pak for Data): Allows the creation of arbitrary files via path traversal during archive extraction. Details: NVD CVE-2026-80424.

From the Security Press

  • Check Point Patches Two VPN Vulnerabilities with a 9.8 Score: The company fixed two critical flaws in how its firewalls and management products process VPN certificates, breaches that could allow unauthenticated RCE. Source: The Hacker News.
  • Critical Flaw in Alby Hub Exposed to the Internet: Self-hosted Bitcoin Alby Hub wallets can be compromised if they are directly accessible from the internet, allowing attackers to take control and redirect users’ funds. Source: The Hacker News.
  • New PoC Exploit Bypasses Microsoft Defender Patch (CVE-2026-69414): A researcher has demonstrated that the patch for the ShieldBreak vulnerability can be bypassed using a new exploit called ShieldCrash, indicating the failure of the initial fix. Source: The Hacker News.
  • SAP Patches Kernel Vulnerability with a 10.0 Score: Vulnerability CVE-2026-44756 in SAP Extended Passport (EPP) involves memory corruption and allows unauthenticated remote code execution. Source: The Hacker News.
  • Microsoft Patches a Record 974 Vulnerabilities: In its latest update, Microsoft addressed 974 vulnerabilities, including two actively exploited zero-day vulnerabilities. Source: The Hacker News.

What We Recommend

  • Patch Management: Urgently apply security updates issued by vendors, especially for Microsoft Windows, virtualization platforms, Chromium-based browsers, and exposed network equipment (Cisco, Fortinet, MikroTik, Citrix).
  • Credentials and Configuration Auditing: Immediately change default credentials in recently deployed solutions (such as the patched IBM systems) and ensure that hardcoded session keys are not used in production applications.
  • Limiting Internet Exposure: Avoid directly exposing administrative or critical services to the internet (such as Alby Hub wallets or firewall management panels) and implement restricted access using VPN-type solutions with multi-factor authentication (MFA).
  • Access Log Monitoring: Actively monitor security logs to detect anomalies associated with path traversal, authentication bypass, or command injection attacks.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *