The CyberSec Intelligence team presents the daily analysis of security vulnerabilities from September 19, 2026. Today we highlight a series of major security breaches, some of which are already actively exploited in real-world cyberattacks, targeting operating systems, Cisco network equipment, and enterprise applications.
Actively exploited vulnerabilities
- CVE-2025-39964 (Linux Kernel): A race condition allows concurrent writes to the same AF_ALG socket, causing corruption of its internal state. Details on NVD.
- CVE-2026-53266 (Linux Kernel): An out-of-bounds write vulnerability in ebtables SNAT target allows direct writing to protected memory areas. Details on NVD.
- CVE-2025-39682 (Linux Kernel): Improper validation of exceptional conditions on the TLS receive path, bypassing the recvmsg() packet processing mechanisms. Details on NVD.
- CVE-2026-58704 (Google Pixel): Authorization error in the cellular modem, which could allow an attacker to bypass permissions and obtain elevated privileges. Details on NVD.
- CVE-2026-76460 (Cisco Identity Services Engine): Incorrect use of privileged APIs in Cisco ISE and ISE-PIC, allowing an unauthenticated remote attacker to bypass the web management interface. Details on NVD.
- CVE-2026-87886 (Acronis Backup): Incorrect default permissions in the Acronis Backup plugin for cPanel & WHM and the extension for Plesk, which could facilitate privilege escalation. Details on NVD.
- CVE-2026-76461 (Cisco Secure Email Gateway): A SQL Injection vulnerability in Cisco AsyncOS for SEG allows unauthenticated remote attackers to execute arbitrary commands with root privileges on the operating system. Details on NVD.
New critical vulnerabilities
- CVE-2026-93603 (vm2): Incorrect handling of receivers in the vm2 library which allows sandbox escape and execution of arbitrary commands on the host system. Details on NVD.
- CVE-2026-93605 (vm2 NodeVM): Omission of the child_process module from the DANGEROUS_BUILTINS list, allowing attackers to escape the sandbox in affected configurations. Details on NVD.
- CVE-2023-54399 (Hongjing e-HR): SQL Injection in the /servlet/codesettree endpoint allowing an unauthenticated attacker to extract data from the database, including credential tables. Details on NVD.
- CVE-2026-75878 (IBM Sterling File Gateway): Allows authentication bypass via an unvalidated SSO header. Details on NVD.
- IBM Guardium Data Protection (Version 12.2): Multiple extremely severe vulnerabilities have been identified, including second-order SQL Injection (CVE-2026-80441), OS command injection in exportCertificate (CVE-2026-80442), insecure deserialization allowing RCE (CVE-2026-81657, CVE-2026-82340 on TCP port 16017), IP-based authentication bypass (CVE-2026-82967), code execution through poor web generation (CVE-2026-82832), and SQL Injection (CVE-2026-84064, CVE-2026-84073).
From the security press
- CVE-2026-85889: Microsoft has published security patches for a critical maximum-severity flaw (CVSS 10.0) in Azure AI Foundry, which allowed network privilege escalation. Details on The Hacker News.
- No CVE assigned (Check Point): A critical vulnerability in Check Point Security Management and Log Servers allows unauthenticated users to execute remote code with root privileges. Details on The Hacker News.
- CVE-2026-77179 (Docker Sandboxes): A critical virtual machine escape vulnerability in Docker Sandboxes on macOS allows malicious code to read and modify any file on the host system. Details on The Hacker News.
- CVE-2026-81642 (Unbound DNSSEC Validator): A heap overflow flaw in Unbound implementations prior to version 1.26.1 could allow remote code execution (RCE) via a malicious DNS zone. Details on The Hacker News.
What we recommend
- Immediate Patch Management: Apply the recommended security updates for Linux Kernel systems, Google Pixel mobile systems, and affected platforms from IBM and Cisco.
- Isolation of sensitive ports: Configure firewall rules to restrict unauthorized external access to TCP port 16017 (associated with IBM Guardium services) and Internet-exposed administrative consoles.
- Elimination of vulnerable dependencies: Software projects using the vm2 library should urgently migrate to secure sandbox solutions, given that vm2 has reached its end-of-life and is vulnerable to code execution.
- Strict shared directory policies: Docker Sandboxes users on macOS must severely limit shared directories from the host machine to mitigate the risk of unauthorized local file modification.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




