ZeroHour

Search: “systems”

19,171 stories

The Apple Security Update Review for September 2026new

Apple's September 2026 updates patch 45+ flaws, including a 9.8 Screen Sharing authentication bypass (CVE-2026-65400) already listed in CISA's KEV.

ZDI's review of Apple's September 2026 security updates catalogs dozens of CVEs across macOS, iOS, iPadOS, watchOS and other platforms. CVE-2026-65400 (CVSS 9.8) lets a network attacker authenticate to Screen Sharing Server without valid credentials and is flagged as KEV, while CVE-2026-65414 (CVSS 9.8) enables remote code execution via Bluetooth. The set also includes 8.8-rated memory corruption flaws in WebKit, WebRTC, CUPS, ImageIO and the kernel, plus sandbox escapes, privilege escalations to root, and arbitrary code execution via crafted files.

2026-002: Multiple Vulnerabilities in Cisco Products

Cisco fixed SD-WAN Controller auth bypass CVE-2026-20127 (CVSS 10) exploited in the wild since 2023, plus several critical and high flaws in SD-WAN Manager.

On 25 February 2026 Cisco released advisories for multiple flaws in Catalyst SD-WAN Controller and SD-WAN Manager, potentially granting administrative access to attackers. CVE-2026-20127 (CVSS 10.0) is an authentication bypass in the Controller's peering authentication mechanism, exploited in the wild since 2023, allowing unauthenticated admin access via NETCONF, rogue device injection, and persistent access. SD-WAN Manager flaws include CVE-2026-20129 (9.8, unauthenticated API auth bypass to netadmin), CVE-2026-20126 (7.8, local privesc to root), CVE-2026-20133 (7.5, info disclosure), CVE-2026-20122 (7.1, arbitrary file overwrite), and CVE-2026-20128 (5.5, DCA info disclosure). CERT-EU recommends patching, capturing forensic evidence, IOC hunting, and restricting management-plane internet exposure.

CERT-EU Advisories · Feb 10, 2026Exploit / PoC in the wildCVE-2026-20127CVE-2026-20129CVE-2026-20126+3 CVEs