Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7

Public exploit runs commands as git on unpatched self-managed GitLab servers

A researcher at depthfirst published a working exploit on July 24 for a GitLab flaw patched on June 10, running commands as the git user on any self-managed 18.11.3 server that has not updated. Any authenticated user who can push to a project can trigger it: the attacker commits a crafted Jupyter notebook and opens its commit diff to leak a heap pointer, repeats until an automated probe locates libraries in memory, then fires the payload with two more notebooks. No administrator rights, runner access, or victim interaction are needed. The bug sits in the notebook renderer, which passes repository-controlled data to a parser inside a long-lived worker.

Check
Move self-managed GitLab to a supported release containing the June fix, and for Helm or Operator deployments verify the GitLab version inside the Webservice image rather than only the chart version.
Affected
Self-managed GitLab servers on 18.11.3 or other unpatched builds; any authenticated user able to push a project can run commands as the git service account, with public exploit code now available.
Fix
Upgrade to a fixed release, since no workaround is offered, and note GitLab did not classify the fix as a security issue, so track upstream library bumps rather than security advisories alone.

Certighost lets any domain user impersonate a domain controller and seize the domain

Researchers published a working exploit on July 24 for Certighost, an Active Directory Certificate Services flaw that lets a low-privileged domain user obtain a certificate for a domain controller and authenticate as that machine. Because domain controller accounts hold directory replication rights, the resulting credential can extract the krbtgt secret through DCSync, effectively handing over the whole domain. Microsoft patched it in the July 14 updates as CVE-2026-54121, an improper authorization issue scored 8.8. Exploitation needs only network access and an ordinary domain account, with no administrator rights or user interaction, and it was tested against a default enterprise certificate authority setup.

Check
Apply the July Microsoft updates to enterprise certificate authorities, and where immediate patching is not possible, disable the vulnerable chase fallback per Microsoft's guidance and restart the certificate service.
Affected
Active Directory environments running an unpatched Enterprise Certification Authority (CVE-2026-54121); any standard domain account can impersonate a domain controller, run DCSync, and take full control of the domain.
Fix
Deploy the July fix, audit certificate authority enrollment and issuance logs for domain controller impersonation, restrict machine account creation, and monitor for unexpected DCSync replication activity.

Cl0p affiliates hit exposed Windchill and FlexPLM through an unauthenticated flaw

Cl0p affiliates are exploiting internet-exposed PTC Windchill and FlexPLM product lifecycle platforms through an unauthenticated remote code execution flaw, in a data theft extortion campaign. Product lifecycle management systems track a product from design to retirement and hold computer-aided design files, bills of materials, engineering data, and workflows, making them a concentrated store of intellectual property for manufacturers in automotive, aerospace, defense, medical, and electronics. Cl0p's established pattern is mass exploitation of one enterprise product followed by extortion over stolen data rather than encryption. PTC patched a critical deserialization flaw in the Windchill data management component earlier this year that has already seen exploitation.

Check
Identify any Windchill or FlexPLM instance reachable from the internet, confirm it is on a patched release, and place it behind access controls rather than leaving it directly exposed.
Affected
Manufacturers running internet-exposed PTC Windchill or FlexPLM; unauthenticated code execution lets Cl0p steal design files, bills of materials, and engineering intellectual property for extortion.
Fix
Patch and restrict access to product lifecycle platforms, require multi-factor authentication, monitor for bulk downloads and unusual export activity, and confirm what intellectual property these systems hold before an incident.

Vatican prayer app left personal data of 700,000 users exposed

Researchers found that an official Vatican prayer app exposed the personal information of more than 700,000 users worldwide through an insecure configuration. The exposed data included details that can identify individuals and tie them to their use of the app. Faith and health apps are sensitive because the mere fact of using them can be revealing, and religious affiliation is a protected category in many jurisdictions, so even a modest data set carries outsized risk for the people in it. The exposure stemmed from the way the app's backend was set up rather than a sophisticated intrusion, a recurring pattern in mobile app data leaks where access controls are misconfigured.

Check
App developers should review backend access controls and confirm that user data stores require authentication and are not readable by anyone who can reach the endpoint.
Affected
More than 700,000 users of the Vatican prayer app whose personal information was exposed; because the data links people to a religious app, it is sensitive even where individual fields seem limited.
Fix
Developers should enforce authentication on all data endpoints, apply least privilege to backend stores, test for misconfiguration before release, and minimize the personal data collected by faith and health apps.

GitHub delays Dependabot version updates to keep poisoned packages out

GitHub is adding a default three-day cooldown before Dependabot opens pull requests for new package versions, aimed at supply chain attacks where a poisoned release spreads through automated updates before anyone catches it. Security updates that answer a known advisory still ship immediately; only routine version updates wait. GitHub points to the September 2025 compromise of chalk, debug, and other packages, whose crypto-stealing versions were live for roughly two hours, and notes its advisory database logged more than 6,500 npm malware advisories in the year to May 2026, around eighteen a day. Most malicious releases are caught within hours, so a short delay filters out the majority.

Check
If you use Dependabot, confirm the cooldown is enabled and consider tuning the window in dependabot.yml, and apply similar delay logic to any other automated dependency tooling you run.
Affected
Projects with automated dependency updates that pull new releases immediately; a poisoned version of a popular package can reach reviewers and installs during the short window before it is caught and yanked.
Fix
Adopt a cooldown on version updates while keeping security fixes immediate, pin and verify dependencies, review update pull requests rather than auto-merging, and monitor for advisories on packages you rely on.

US agencies say Iran-linked actors are disrupting water and energy control systems

CISA, the FBI, NSA, EPA, and Department of Energy updated a joint advisory warning that Iran-affiliated actors are exploiting internet-facing operational technology across US critical infrastructure, and in some cases disrupting it. Since at least March 2026 the group has targeted programmable logic controllers, the small industrial computers that run automation processes, extracting device project files and then modifying or deleting the control logic. Water, wastewater, energy, and government facilities are among the affected sectors, and some victims experienced operational disruption and financial loss. The July update broadened the range of affected device makers, added detection guidance, and refreshed the published indicators of compromise.

Check
Take internet-facing PLCs and operational technology offline or behind a VPN, change default and weak device passwords, and check for unexpected changes to control logic and project files.
Affected
Water, wastewater, energy, and government operators with internet-exposed programmable logic controllers; attackers extract project files and alter control logic, which can push processes into unsafe states.
Fix
Remove operational technology from direct internet exposure, enforce strong unique credentials and multi-factor authentication, segment control networks, back up device logic offline, and apply the advisory's detection guidance and indicators.

Check Point patches exploited SmartConsole flaw giving attackers full admin access

Check Point has fixed an actively exploited flaw in SmartConsole, the graphical admin panel used to manage its security products. CVE-2026-16232, rated 9.3, is an authentication bypass letting an unauthenticated remote attacker obtain a login token and authenticate with administrator privileges, after which they can alter security configuration and policy on a Security Management or Multi-Domain Management server. Exploitation requires the management server to be reachable from the internet with no restrictions on trusted GUI clients. The same update fixes a second critical authentication bypass and a Gaia Portal issue letting read-only users run commands as root.

Check
Install the July 22 Jumbo hotfix on Security Management and Multi-Domain Management servers, then restrict trusted GUI clients to approved addresses and firewall management access to known sources.
Affected
Organizations running Check Point Security Management or Multi-Domain Management with the console reachable from the internet (CVE-2026-16232); attackers gain administrator access and can rewrite the security policy protecting the network.
Fix
Apply the hotfix, limit trusted clients to specific addresses, keep management interfaces off the public internet, and review policy changes and administrator logins for unauthorized modifications.

Nine year old Linux kernel flaw gives local users root on default RHEL installs

Qualys disclosed RefluXFS, a race condition in the Linux kernel's XFS copy-on-write path that lets an ordinary local user overwrite protected files and take root. Tracked as CVE-2026-64600, it triggers when two concurrent direct writes target the same reflinked file: the kernel briefly drops its inode lock, and a second writer can make the first write land on a stale block. The overwrite happens at the block layer, so ownership, permissions, timestamps, and the setuid bit stay untouched and no kernel log entry appears. Qualys reports it works with SELinux enforcing and estimates over 16 million affected systems.

Check
Update kernels on hosts using XFS with reflink enabled, then reboot to apply, and prioritize shared systems where untrusted users or workloads already have local execution.
Affected
Systems running Linux 4.11 or later with a reflink enabled XFS filesystem (CVE-2026-64600), which is the default on Red Hat Enterprise Linux and derivatives, Oracle Linux, Amazon Linux, and Fedora Server.
Fix
Install vendor backported kernels and reboot, since the fix merged upstream on July 16. Debian, Ubuntu, and SUSE are exposed only where an administrator chose XFS with reflink at install.

Ubuntu snap-confine flaw turns any local account into root on default desktops

Qualys disclosed a privilege escalation flaw in snap-confine, the component that builds the sandbox for every snap application. CVE-2026-8933, rated 7.8, affects default installations of Ubuntu Desktop 24.04, 25.10, and 26.04, and stems from a 2025 hardening change that moved snap-confine from a setuid root binary to a capabilities model, introducing a race during sandbox setup. An attacker mounts a filesystem over the temporary scratch directory, plants a symlink so a privileged write lands on another file, then drops a udev rule that makes a system service run commands as root. Fixes shipped July 21.

Check
Update snapd across desktops and developer workstations, and verify the installed snapd version on each machine rather than assuming an older release or prior patching leaves it unaffected.
Affected
Default installations of Ubuntu Desktop 24.04, 25.10, and 26.04 (CVE-2026-8933); anyone with local execution, whether from stolen credentials or a malicious app, can escalate to full root control of the host.
Fix
Install the updated snapd packages, limit local shell access to trusted users until patched, and treat local privilege escalation as urgent since footholds on endpoints are routinely obtained through phishing.

Attackers exploit Windmill flaw to read server files and reach superadmin access

VulnCheck reports active exploitation of a path traversal flaw in Windmill, an open source platform for building internal tools, jobs, and workflows. CVE-2026-29059 lets an unauthenticated attacker read arbitrary files through the log file endpoint, and while observed attempts included reading the password file, the higher value target is the superadmin secret. Where that is configured, an attacker can authenticate as a super administrator and run arbitrary code through the job preview API. VulnCheck counted roughly 170 exposed instances across 24 countries, including deployments reachable through a proxy path rather than directly.

Check
Update Windmill to a fixed release, confirm whether any instance was reachable from the internet, and treat the superadmin secret and any credentials stored in configuration as exposed.
Affected
Organizations running internet-reachable Windmill deployments (CVE-2026-29059); unauthenticated attackers read server files, and where the superadmin secret is set, escalate to full administrative access and code execution.
Fix
Patch to the fixed version, rotate the superadmin secret and stored credentials, keep internal automation platforms off the public internet or behind authentication, and review logs for file read attempts.