Buletin de securitate cibernetică – 10 septembrie 2026

Cybersecurity Bulletin – September 10, 2026

The CyberSec Intelligence daily bulletin from September 10, 2026: actively exploited vulnerabilities in Citrix, Fortinet, and Cisco, plus a record volume of Microsoft and SAP patches.

The CyberSec Intelligence team (csint.ro) presents the daily cybersecurity bulletin for September 10, 2026. We analyze critical vulnerabilities and those actively exploited in real-world attacks to help you protect your infrastructure.

Actively exploited vulnerabilities

The following security flaws are actively exploited in attacks and require immediate attention:

  • CVE-2026-19490 (Citrix NetScaler): Alternative-channel authentication bypass vulnerability in NetScaler ADC and Gateway, allowing unauthorized remote access. Details in NVD source.
  • CVE-2025-25249 (Fortinet): Heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, allowing remote code execution. Details in NVD source.
  • CVE-2026-87491 (Google Chromium V8): Out-of-bounds write in the V8 engine, allowing arbitrary code execution in the sandbox. Details in NVD source.
  • CVE-2026-20079 (Cisco Secure Firewall): Authentication bypass in FMC and SCC, allowing attackers to execute scripts and obtain root access. Details in NVD source.
  • CVE-2026-75650 (Adobe Commerce / Magento): Improper neutralization of elements in the template engine, facilitating arbitrary code execution. Details in NVD source.
  • CVE-2026-81963 (Microsoft Windows): Link following vulnerability in Update Stack allowing local privilege elevation to SYSTEM level. Details in NVD source.
  • CVE-2026-86218 (N-able N-central): Static code injection allowing remote code execution before authentication. Details in NVD source.
  • CVE-2026-85880 (Microsoft Windows): Buffer overflow in ALPC allowing local privilege elevation. Details in NVD source.
  • CVE-2026-85046 (Google Chromium V8): Type confusion allowing arbitrary code execution in the sandbox. Details in NVD source.

New critical vulnerabilities

  • CVE-2026-61516: Data exposure in Netis NX10 firmware, allowing administrator password extraction without a valid session. Details in NVD source.
  • CVE-2026-68839: Buffer overflow in Windows USB Mass Storage driver, allowing code execution over the network. Details in NVD source.
  • CVE-2026-69356: XSS vulnerability in Microsoft Exchange Server allowing network spoofing. Details in NVD source.
  • CVE-2026-69431: Buffer overflow in Telnet Client that can be exploited for network code execution. Details in NVD source.
  • CVE-2026-69715: Out-of-bounds read in Windows Direct Show, allowing attackers remote code execution. Details in NVD source.
  • CVE-2026-69768: Buffer overflow in Windows RNDIS, allowing remote code execution. Details in NVD source.
  • CVE-2026-69824: Integer underflow in Microsoft Standard XPS allowing network code execution. Details in NVD source.
  • CVE-2026-69845: Buffer overflow in Windows DHCP Server allowing unauthorized code execution over the network. Details in NVD source.
  • CVE-2026-69854: Improper authentication in Spring Cloud Azure allowing privilege escalation over the network. Details in NVD source.
  • CVE-2026-83941: Missing authorization in Entra ID, allowing authorized users remote privilege escalation. Details in NVD source.
  • CVE-2026-82004: Command injection in Adobe Campaign Classic, facilitating code execution without user interaction. Details in NVD source.

From the security press

  • Alby Hub: A critical vulnerability in the self-hosted Lightning Alby Hub wallet (v1.7.0+) could allow attackers to take control of wallets directly exposed to the internet. Details in The Hacker News.
  • Microsoft Defender (CVE-2026-69414): A PoC exploit (ShieldCrash) has been published, demonstrating the bypass of the previous patch for ShieldBreak. Details in The Hacker News.
  • SAP Kernel (CVE-2026-44756): A vulnerability with a maximum CVSS score of 10.0 in SAP Extended Passport (EPP) processing allows remote code execution without authentication. Details in The Hacker News.
  • Record Microsoft Patches: The company patched a record 974 vulnerabilities, including over 110 security flaws rated critical and two actively exploited zero-days. Details in The Hacker News.

What we recommend

To protect your organization’s infrastructure, the CyberSec Intelligence team recommends implementing the following measures:

  • Patch Management (Patch Management): Urgently apply updates for Windows operating systems, Citrix virtualization platforms, and Fortinet security solutions, prioritizing actively exploited vulnerabilities.
  • Asset inventory: Verify the internet exposure of services and cryptocurrency wallets (such as Alby Hub), disabling external access for those that do not require a direct connection.
  • Continuous monitoring: Monitor network activity and connection logs, especially on Exchange servers and Cisco management consoles, to detect authentication bypass attempts.

Security News, in your inbox

New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.

How personal data is used

Leave a Reply

Your email address will not be published. Required fields are marked *