Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Flaw lets repository owners swap pinned plugin code across four AI coding agents

Air Security reported that four AI coding agents fetch plugins pinned to a reviewed commit hash but never verify the code they receive matches it. On code hosts that permit branch names shaped like commit hashes, such as Bitbucket or self-hosted git, a plugin repository owner can point that name at different code, so the agent installs malicious code while reporting the locked version. Because plugins run with the user's access, the swapped code reaches files, credentials, and connected systems. Anthropic fixed it in Claude Code 2.1.179 and OpenAI in Codex 0.146.0; GitHub Copilot has no fix, and Google will not patch the retiring Gemini CLI.

Check
Update Claude Code and Codex to the fixed releases, then inventory installed agent plugins sourced from Bitbucket or self-hosted git rather than GitHub.
Affected
Agents installing plugins from hosts that allow commit-hash-shaped branch names can run attacker-swapped code under the user's own access despite version pinning.
Fix
Upgrade to patched agents, restrict plugins to GitHub-hosted repositories that block such branch names, and review Copilot and Gemini CLI plugin usage.

Exploited Cisco ISE zero-day scores a perfect ten and hands attackers root

Cisco warned that attackers are exploiting a critical zero-day in its Identity Services Engine, the platform that decides which devices are allowed onto a network. Tracked as CVE-2026-76460 and scored 10.0, the flaw is an authentication bypass caused by insufficient authentication controls on an API endpoint, so an unauthenticated attacker can send a crafted request, bypass the management interface, and ultimately gain root. It affects ISE and its Passive Identity Connector regardless of configuration, with no workaround beyond restricting network access. Because a rooted appliance sitting at the network's front door can be used to erase evidence, Cisco urges checking external logs. CISA set a three-day federal patch deadline.

Check
Patch Cisco ISE and its Passive Identity Connector to a fixed release immediately, since there is no workaround and exploitation is active, and restrict who can reach the appliance until patched.
Affected
Organizations running Cisco ISE or ISE Passive Identity Connector in any configuration (CVE-2026-76460); an unauthenticated attacker can bypass authentication through an API endpoint and gain root, exploitation confirmed in the wild.
Fix
Patch now, restrict access with infrastructure access lists, cross-check external network and firewall logs since a rooted device can hide its own indicators, and treat any exposed unpatched ISE as likely compromised.

Critical Check Point management flaw lets unauthenticated attackers gain root

Check Point patched a critical flaw in its management servers that lets an unauthenticated attacker run code as root. Tracked as CVE-2026-91843 and scored 9.8, it is a stack overflow in the login process, which handles requests before a user authenticates, and it can be triggered by a login request carrying an overly long username. It affects Quantum management, Log, and Multi-Domain servers, through the Trusted Clients path. Customers with automatic updates are already protected, and others should apply the vendor's live patch. Check Point reports no exploitation yet, but this is the third serious management-server flaw it has disclosed in weeks, and compromising it means control over the whole firewall estate.

Check
Apply Check Point's live patch for the management-server flaw now if automatic updates are not enabled, and restrict which clients can reach the management, Log, and Multi-Domain servers.
Affected
Organizations running affected Check Point Quantum management, Log, or Multi-Domain servers (CVE-2026-91843); an unauthenticated attacker can trigger a login overflow with a long username to run code as root.
Fix
Patch or confirm automatic updates applied, tightly restrict access to management-plane servers, monitor for anomalous pre-authentication login traffic, and treat the management plane as the highest-value target since it controls every firewall.

Docker sandbox flaw lets guest code escape and change macOS host files

Docker patched two flaws in Docker Sandboxes, the isolated micro-VM environments used to run untrusted code and AI-agent tasks, that let malicious guest code break out and read or modify files on the macOS host. The more serious, CVE-2026-77179 and scored 9.4, is in the file-sharing component: the host improperly follows symbolic links when reopening a file, so a guest can swap a directory for a symlink after a path is approved, escape the shared workspace, and touch arbitrary host files as the account running the VM, potentially leading to host code execution. A second flaw abuses the guest-to-host socket relay the same way. Both are fixed in version 0.42.0.

Check
Update Docker Sandboxes to version 0.42.0 or later on macOS developer machines, and minimize which host directories are mounted into sandboxes, keeping credentials and sensitive repositories out of shared paths.
Affected
Developers running Docker Sandboxes below 0.42.0 on macOS to isolate untrusted code or AI-agent tasks (CVE-2026-77179, CVE-2026-79994); malicious guest code can escape via symlink races and read or modify host files.
Fix
Patch to 0.42.0, treat sandboxes running untrusted code or AI agents as hostile, minimize host-mounted directories, keep secrets out of shared paths, and watch for unexpected host file changes from sandbox processes.

Critical Unbound DNS flaw allows code execution through a malicious zone

NLnet Labs patched a critical heap overflow in the DNSSEC validator of Unbound, one of the most widely used recursive DNS resolvers. Tracked as CVE-2026-81642, the flaw can be triggered when a resolver queries a zone an attacker controls, and it can lead to remote code execution. The bug lies in how the validator parses a signing-key record whose owner name points back into the record's own data. Every Unbound release up to and including 1.26.0 is affected, and the fix is in 1.26.1, which also addresses eight other flaws, including a second that could allow code execution. No exploitation is reported, but resolvers query attacker-controlled zones during normal operation.

Check
Update Unbound to 1.26.1 across recursive resolvers, including any bundled in appliances or home-network setups, and if you cannot upgrade immediately, apply the vendor's source patches or temporarily disable DNSSEC validation.
Affected
Anyone running Unbound 1.26.0 or earlier as a recursive DNS resolver (CVE-2026-81642); querying an attacker-controlled zone can trigger a heap overflow with possible remote code execution, and normal resolution reaches such zones.
Fix
Patch to 1.26.1, apply the standalone source patches if you cannot upgrade, treat DNS resolvers as exposed infrastructure since they process untrusted data, and monitor resolvers for crashes and unexpected behavior.

Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated

Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.

Check
Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
Affected
Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
Fix
Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.

Parallels Desktop flaw lets a normal Mac user become root, stranding Intel Macs

Researchers at JFrog disclosed a flaw in Parallels Desktop, which runs Windows and Linux virtual machines on a Mac, that lets a non-administrator user gain root on the Mac itself. Tracked as CVE-2026-90894 and named ParaShells, the issue is that Parallels' root-level background service listens on a socket that was left world-writable, so any program running as a normal user can connect to it and escalate to root. It needs code already running locally, not network access. The fix is in Parallels Desktop 27, but Intel Macs cannot install that version, leaving those users without a patch. Apple-silicon users should update to the latest release on that line.

Check
Update Parallels Desktop to 27.0.1 or later on Apple-silicon Macs; on Intel Macs, which cannot install the fix, limit who can run code locally and consider alternatives until a fix is available.
Affected
Mac users running Parallels Desktop below version 27 (CVE-2026-90894); a non-admin local user can reach the world-writable service socket to gain root, and Intel Macs cannot install the fixed version.
Fix
Patch Apple-silicon Macs to the latest Parallels release, restrict local code execution on Intel Macs that cannot update, monitor for unexpected privilege escalation, and weigh alternative virtualization for unpatchable systems.

Acronis cPanel backup plugin flaw exploited to escalate privileges on hosting servers

Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.

Check
Update the Acronis Backup plugin for cPanel and WHM to the fixed version immediately, and update the Plesk extension too, then review shared servers for signs of privilege escalation and unauthorized access.
Affected
Web hosts and managed service providers running the Acronis Backup plugin for cPanel and WHM (CVE-2026-87886); an attacker with a foothold can escalate privileges to reach backups, system files, and tenants' data.
Fix
Patch the backup plugin and extension, tighten file permissions and account isolation on shared hosting, monitor for privilege escalation and backup access, and treat a compromised hosting account as a server-wide risk.

Exploited Cisco email gateway flaw lets a crafted email run commands as root

Cisco warned that attackers are exploiting a critical zero-day in its Secure Email Gateway appliances that lets them run commands as root just by sending a crafted email. Tracked as CVE-2026-76461 and scored 9.8, the flaw is a SQL injection in the appliance's email-parsing logic, so an unauthenticated attacker needs no access to the management interface at all. It affects physical and virtual gateways in any configuration, and Cisco confirmed it was exploited as a zero-day before disclosure. CISA added it to its exploited-vulnerabilities catalog with a three-day federal deadline. Because successful attacks grant root, intruders can erase their own tracks, so Cisco urges inspecting mail logs for suspicious activity.

Check
Patch Cisco Secure Email Gateway appliances immediately given active exploitation, and inspect mail and network logs for suspicious SQL statements and signs of compromise, despite the risk that root access erased indicators.
Affected
Organizations running physical or virtual Cisco Secure Email Gateway appliances in any configuration (CVE-2026-76461); an unauthenticated attacker can send a crafted email to run commands as root, exploited in the wild.
Fix
Apply the fixed AsyncOS releases now, hunt for compromise using Cisco's indicators while assuming a rooted device may hide them, and apply the four other critical email-gateway fixes shipped the same day.

Attackers forge admin tokens through a WSO2 API Manager JWT bypass flaw

Attackers are exploiting a JWT authentication-bypass flaw in WSO2 products, including its widely used API Manager and Identity Server. Tracked as CVE-2026-5430 and rated 9.8, the flaw is an algorithm-confusion bug: the token validator accepts JWTs signed with algorithms other than the ones it is configured to trust, so an attacker can craft a forged token that passes validation. That lets them mint tokens as an administrator and take over the deployment, gaining control over the APIs and identities the platform manages. Because WSO2 sits at the center of API and identity infrastructure, a takeover can cascade to everything behind the gateway. Active exploitation attempts have been observed against exposed instances.

Check
Apply WSO2's fixes for the JWT authentication-bypass flaw across API Manager, Identity Server, and other affected products, and keep the Carbon management console and admin interfaces off the public internet.
Affected
Organizations running affected WSO2 products such as API Manager or Identity Server (CVE-2026-5430); an attacker can forge a JWT with an unsupported algorithm to bypass authentication, become an administrator, and take over.
Fix
Patch to fixed WSO2 versions, restrict management interfaces to trusted networks, enforce strict JWT algorithm validation, monitor for forged-token and anomalous admin activity, and rotate keys and tokens if compromise is suspected.