Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
Cisco patched a RADIUS flaw in Identity Services Engine letting unauthenticated remote attackers trigger denial of service on ISE nodes.
A vulnerability in the RADIUS feature of Cisco Identity Services Engine allows an unauthenticated remote attacker to cause a denial of service by sending crafted RADIUS requests directly to an affected device. The flaw stems from improper handling of certain RADIUS requests and can render ISE nodes unavailable. In single-node deployments, endpoints that have not yet authenticated would be unable to access the network until the node recovers. Cisco has released software updates addressing the issue.
Apple Updates Everything, (Mon, Sep 14th)
Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.
Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.
ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability
ZDI disclosed an unauthenticated infinite-loop denial-of-service flaw (CVE-2026-4890) in dnsmasq DNSSEC NSEC/NSEC3 bitmap processing.
The Zero Day Initiative published ZDI-26-584 describing an infinite loop in dnsmasq's processing of DNSSEC NSEC/NSEC3 type bitmaps. Remote unauthenticated attackers can trigger a denial-of-service condition on affected installations. ZDI assigned a CVSS score of 7.5 and the identifier CVE-2026-4890.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability
Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.
A vulnerability in the VPN and management web servers of Cisco ASA Software and Cisco Secure FTD Software allows an unauthenticated remote attacker to exhaust system memory or buffer blocks, causing a denial of service. Originally scoped to the ASAv and FTDv virtual appliances, Cisco updated the advisory on September 16, 2026 to cover all ASA and FTD platforms.
GDCM <= 3.2.7: six memory-safety and denial-of-service vulnerabilities, no CVE
Six memory-safety and denial-of-service flaws disclosed in the GDCM DICOM parsing library, affecting versions through 3.2.7.
Researcher Abhinav Agarwal disclosed six vulnerabilities in GDCM (Grassroots DICOM), an open-source C++ library for parsing and processing DICOM files. All six were confirmed against GDCM 3.2.6 using AddressSanitizer and UndefinedBehaviorSanitizer, and source review found the vulnerable patterns through version 3.2.7 and the upstream master snapshot. Potential impacts include heap corruption, process-memory disclosure, stack exhaustion, and process termination in applications parsing untrusted DICOM files. No CVE identifiers have been assigned at the time of disclosure.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Cisco patched an unauthenticated remote DoS in ASA and FTD Remote Access SSL VPN that reloads devices via crafted HTTP requests.
Cisco disclosed a denial-of-service vulnerability in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests allows an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload. Cisco has released software updates addressing the flaw.
USN-8774-1: libheif vulnerabilities
Ubuntu patches libheif image-parsing flaws allowing denial of service or arbitrary code execution (CVE-2026-62291, CVE-2026-62377).
Ubuntu Security Notice USN-8774-1 addresses two vulnerabilities in libheif, the HEIF image library. CVE-2026-62291, discovered by Ali Firas, involves incorrect handling of certain images that could allow an attacker to cause a denial of service or execute arbitrary code. CVE-2026-62377, discovered by Dmitrijs Trizna, involves incorrect handling of image sequences leading to possible denial of service.
USN-8739-1: ImageMagick vulnerabilities
Canonical released USN-8739-1 fixing five ImageMagick flaws that could cause denial of service or arbitrary code execution.
Ubuntu security notice USN-8739-1 patches five ImageMagick vulnerabilities: CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, and CVE-2026-56373 allow denial of service via crafted images on Ubuntu 14.04 through 22.04 LTS. CVE-2026-56370 affects Ubuntu 22.04 LTS and 26.04 LTS and could allow denial of service or arbitrary code execution. Users should apply the updated ImageMagick packages to affected releases.
USN-8738-1: FFmpeg vulnerabilities
Ubuntu's USN-8738-1 fixes multiple FFmpeg vulnerabilities allowing denial of service, arbitrary code execution, and sensitive information exposure.
Ubuntu Security Notice USN-8738-1 addresses several FFmpeg flaws. CVE-2026-66036 involves mishandled video frames in the hqdn3d filter, allowing denial of service or arbitrary code execution. CVE-2026-66038, found by Adrian Junge, leaks sensitive information via compressed video files, and CVE-2026-66039 allows denial of service or code execution through crafted audio files. Additional subtitle-file handling flaws were also fixed.
USN-8716-2: FFmpeg vulnerabilities
Ubuntu issued USN-8716-2 fixing FFmpeg VobSub, Vulkan HEVC, and NVDEC decoder flaws that could allow denial of service or code execution.
USN-8716-2 provides the Ubuntu 26.04 LTS counterpart to the FFmpeg fixes in USN-8716-1. Crafted media files could cause denial of service or arbitrary code execution through the VobSub subtitle demuxer (CVE-2026-64830), the Vulkan HEVC hardware decoder (CVE-2026-64831), and the NVDEC video decoder path.
NextGen Healthcare Mirth Connect
CISA warns NextGen Healthcare Mirth Connect <=4.7.1 has SQL injection and XXE flaws enabling credential theft, file writes, and DoS.
CISA released advisory ICSMA-26-253-01 covering three vulnerabilities in NextGen Healthcare Mirth Connect versions 4.7.1 and earlier: SQL injection CVE-2026-82583 (CVSS 8.3), XXE CVE-2026-78224 (CVSS 8.2), and XXE CVE-2026-82578 (CVSS 7.5). Exploitation could expose stored credentials for connected systems, enable arbitrary file writes, and cause denial-of-service conditions. No public exploitation has been reported; the product is deployed worldwide in the Healthcare and Public Health sector.