ZeroHour

Search: “open source”

105 stories

Adobe security advisory (AV26-888)

Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.

Canadian Centre for Cyber Security advisory AV26-888 (September 8, 2026) covers CVE-2026-75650 in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe states the vulnerability is being exploited in the wild. Affected versions extend through the August 2026 patch levels across the 2.4.4-2.4.9 branches, with B2B versions 1.3.x-1.5.x also affected. Administrators are urged to apply the available hotfixes and updates.

Adobe security advisory (AV26-808) – Update 1

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

Canadian Centre for Cyber Securityupdated · 23m agofirst · 6d agoAdvisory in the wild 19 sourcesCVE-2026-71362

Oracle Critical Security Patch Update, September 2026 Review

Oracle's September 2026 Critical Patch Update fixes 673 vulnerabilities, including 104 critical, with many remotely exploitable in E-Business Suite and Fusion Middleware.

Oracle released 673 security patches in its September 2026 Critical Patch Update: 104 rated critical, 503 high, and 59 medium. Oracle E-Business Suite received the most patches (159, 24% of total), with 19 exploitable without credentials including CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 at CVSS 9.8. Fusion Middleware received 153 patches with 78 remotely exploitable without authentication, and 41 patches address third-party open-source component flaws. Qualys published detection QIDs for vulnerable assets.

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 1d agoAdvisory

ConnectWise security advisory (AV26-903)

ConnectWise patches ScreenConnect CVE-2026-84869, reported exploited in the wild; administrators should update to 26.6.5.

ConnectWise shipped ScreenConnect 26.6.5 to fix a vulnerability tracked as CVE-2026-84869 affecting versions prior to 26.6.5. Open-source reporting indicates the flaw is being exploited in the wild. The Canadian Centre for Cyber Security issued advisory AV26-903 urging users and administrators to apply the patch.

Canadian Centre for Cyber Securityupdated · 2h agofirst · 6d agoAdvisory in the wild 5 sourcesCVE-2026-84869

Mikrotik security advisory (AV26-887)

Canada's Cyber Centre urges MikroTik RouterOS updates as CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 are reported exploited in the wild.

Canadian Centre for Cyber Security advisory AV26-887 covers MikroTik RouterOS vulnerabilities affecting versions prior to 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3. Open-source reporting indicates CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 are being exploited in the wild. The Cyber Centre urges users and administrators to review the vendor advisories and apply the necessary updates.

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.

Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.

The Hacker News · 19d agoAdvisory