CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to Read More …

Google Pixel owners urged to patch actively exploited modem flaw

Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says “may be under limited, targeted exploitation.” The bug is not described as a simple remote takeover, but as a vulnerability that could give Read More …

Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products

Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history. While this CVE count is hardly notable compared to some vendors – hello, Read More …

MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in Read More …

Cisco has warned its customers of three critical-rated flaws in its products

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix. Two of them are present in the Cisco IOS XR operating system that powers the company’s carrier-grade kit. CVE-2026-20274 Read More …

Two critical Chrome flaws put users at risk on malicious websites

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. How to update Read More …

CISA gives feds 3 days to fix actively exploited Ray RCE bug

CISA says attackers are exploiting a critical 2025 vulnerability in Ray, the widely used open source framework for scaling Python and machine-learning workloads. Tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, the bug was first disclosed in November 2025. Read More …

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers. The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is Read More …

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Read More …

IBM’s agentic AI platform is under active attack – patch now

A critical vulnerability in IBM-owned, low-code AI builder Langflow lets unauthenticated attackers execute code remotely on vulnerable default deployments, potentially putting organizations running those instances at immediate risk. The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added CVE-2026-9198 to its Known Read More …