
Adobe Releases Emergency Hotfix for 10.0 Vulnerability in Magento and Adobe Commerce
APSB26-146 addresses CVE-2026-75650 exploited since September 4 in fully updated Magento stores. Sansec identified the unauthenticated remote execution route.
Security & Risk
143 analyses

APSB26-146 addresses CVE-2026-75650 exploited since September 4 in fully updated Magento stores. Sansec identified the unauthenticated remote execution route.

CERT Polska coordinated the disclosure of six vulnerabilities in RouterOS; the combination of two of them allows remote root control via SSH without credentials and is already being exploited.

Trezor confirms that ShipMonk retained orders it claimed to have deleted; a flaw in Metabase (CVE-2026-72898) opened an additional 67,000 records, bringing the total to over 80,000.

High-severity vulnerability in the JavaScript V8 engine, identified as CVE-2026-85046, was actively exploited before Google released the patch in the stable channel on September 3.

Program launched on September 3 subsidizes access to cybersecurity models for operators without enterprise budgets, starting in the U.S. with a focus on water,energy, and local governments.

Three of the four largest chatbots in the world experienced outages on Thursday morning within the same timeframe due to sharing the same Microsoft region. Gemini on Google Cloud remained operational.

OpenAI announced on Tuesday (2) that Astra is the company’s first model to achieve 'Critical' status under its Preparedness Framework. 100% on ExploitBench and two zero-days discovered independently triggered access gating.
Advisory cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, affects switches N9K-C9804, N9K-C9808, and eight other references. Data center fabric needs to apply a patch or close the port.

A report by Palo Alto Networks published on September 2 describes an invasion in which tactical execution was delegated to autonomous agents, including an 80-page report left for the victim.

Annual revenue closes at $11.5 billion with a 24% increase, RPO surpasses $20 billion for the first time, and Console is acquired to bring autonomous agents to Cortex.

The U.S. agency added CVE-2026-82078 (CVSS 9.4) and CVE-2026-81578 (CVSS 8.8) to the KEV this Monday; federal agencies have until September 14 to apply the second PaperCut patch under BOD 26-04.

Sygnia detailed on August 30 how the Chinese espionage cluster Fire Ant, with significant overlap with UNC3886, has transitioned from the virtualization layer to Cisco IOS XR routers and TACACS servers for high-value clients.