Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

LiteSpeed Enterprise flaw lets one hosting tenant gain root on a shared server

LiteSpeed disclosed that versions of its Enterprise web server before 6.3.7 contain a flaw that lets a low-privilege website user gain root access on the underlying server. On shared hosting, that means one tenant, reachable through a cheap plan or a stolen webmail login, can take over the whole machine and every other customer on it. Neither LiteSpeed nor cPanel has published how the flaw works, its severity, a CVE identifier, or whether it has been exploited, leaving defenders with little to hunt for. Because the update may be slow to arrive automatically, administrators are urged to install 6.3.7 manually. LiteSpeed's cPanel plugin had two similar exploited flaws earlier this year.

Check
Manually update LiteSpeed Enterprise to 6.3.7 now rather than waiting for auto-update, and on shared servers review tenant activity and privileges for signs of abuse given the missing technical details.
Affected
Shared-hosting providers and multi-tenant servers running LiteSpeed Enterprise before 6.3.7; a low-privilege website user can escalate to root and take over the entire server, exposing every other tenant's sites and data.
Fix
Install 6.3.7 manually across affected servers, isolate tenants, monitor for unexpected root processes and privilege escalation, rotate credentials on any suspected compromise, and treat shared hosting as one account from takeover.

Critical GitLab flaw lets one request read any file from self-hosted servers

CISA warned that attackers are exploiting a critical flaw in self-managed GitLab servers, adding it to its exploited-vulnerabilities catalog with a forensic-triage requirement. Tracked as CVE-2026-85706 and scored 10.0, it is a path-traversal bug in GitLab's repository commits API caused by improper path confinement and missing authentication, letting an unauthenticated attacker read any file on the server with a single crafted request. Exposed files can include SSH keys, database credentials, deploy tokens, CI/CD variables, and source code. GitLab patched it on September 10, and researchers observed in-the-wild probing within about a day. GitLab.com is unaffected; the risk is concentrated on the many self-managed instances organizations run.

Check
Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2, or later immediately, then rotate secrets the server could expose, including access tokens, deploy tokens, CI/CD variables, SSH keys, and cloud credentials.
Affected
Organizations running self-managed GitLab CE or EE from 18.7 up to the patched releases (CVE-2026-85706); an unauthenticated attacker can read arbitrary files, including secrets and source, in one request.
Fix
Patch now, rotate all potentially exposed secrets, review commits-API and web-server logs for unauthenticated requests with traversal patterns and unusual file access, and treat exposed unpatched instances as possibly already breached.

Check Point patches two critical VPN certificate flaws enabling unauthenticated code execution

Check Point patched two critical flaws in how its firewall and management products handle VPN certificates, each scored 9.8, that could let an unauthenticated remote attacker run code. CVE-2026-85102 is improper certificate-trust validation during VPN negotiation that can lead to code execution on the Security Gateway. CVE-2026-85103 is a heap overflow while decoding a certificate's structure, affecting both the gateway and the management server. Notably, because the second flaw is about certificate processing, Check Point says it could be triggered even where VPN is not running, so management servers need the fix regardless. Check Point found the issues internally and reports no exploitation yet, though its products were attacked twice this year.

Check
Apply Check Point's Live Patch or the latest Jumbo Hotfix to affected gateways and management servers now, and patch management servers even with the VPN blade off, since certificate processing stays reachable.
Affected
Organizations running affected Check Point Quantum Security Gateway and Management systems (CVE-2026-85102, CVE-2026-85103); an unauthenticated attacker could execute code through VPN certificate handling, and management servers are affected without VPN in use.
Fix
Patch gateways and management servers promptly, confirm Live Patch installed, restrict who can reach these devices, monitor for anomalous certificate-related activity, and treat security infrastructure as a repeatedly targeted asset.

CISA flags exploited Cisco, Citrix, Fortinet, and WatchGuard edge flaws

CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.

Check
Immediately patch internet-facing Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, and WatchGuard Firebox devices to fixed versions, prioritizing anything reachable from the internet, and hunt exposed appliances for signs of compromise.
Affected
Organizations running affected Cisco Secure FMC, Citrix NetScaler, Fortinet FortiOS, or WatchGuard Firebox appliances (CVE-2026-20079, CVE-2026-19490, CVE-2025-25249); all are exploited, from unauthenticated root access to RAT and ransomware deployment.
Fix
Patch these appliances now given the short federal deadline and active exploitation, restrict management interfaces from the internet, monitor for auth-bypass and script-execution activity, and treat any exposed unpatched device as compromised.

Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key

Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.

Check
Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
Affected
Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
Fix
Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.

New cPanel flaw lets a mail-privileged hosting account run code as root

cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.

Check
Update cPanel and WHM to the patched builds now, review which accounts hold mail-related privileges, and because no indicators were published, hunt broadly for unexpected root processes, files, and hidden accounts.
Affected
Shared-hosting providers and multi-tenant servers running unpatched cPanel and WHM (CVE-2026-67401); an authenticated account with mail privileges can inject SQL, create files, and execute code as root, taking over the entire machine.
Fix
Patch to the fixed builds, restrict mail-related privileges, isolate tenants, monitor for root-level file creation and command execution, rotate credentials on any suspected compromised server, and assume shared servers are one-account-from-root.

Critical Alby Hub flaw lets attackers drain internet-exposed Bitcoin wallets

Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.

Check
If you run Alby Hub, remove any public internet access to its management interface first, then update to the current release, and check exposed instances for unauthorized access or unexpected outgoing payments.
Affected
Owners of self-hosted Alby Hub Lightning wallets on versions 1.7.0 through 1.18.5 reachable from the internet; an attacker reaching the management interface could take control of the wallet and send bitcoin.
Fix
Update Alby Hub to the current version, keep the wallet's management interface off the public internet behind a VPN or local network, use strong unique credentials, and monitor for unexpected transactions.

Microsoft's record Patch Tuesday fixes 974 flaws and two exploited Windows zero-days

Microsoft shipped its largest-ever Patch Tuesday, fixing a record 974 vulnerabilities, including two Windows zero-days already exploited in attacks. Both zero-days are local privilege-escalation flaws that let an attacker gain SYSTEM access: CVE-2026-85880 is a heap buffer overflow in the Advanced Local Procedure Call component that can let code in a low-privilege sandbox escape and elevate, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The release also includes about 20 potentially wormable flaws, remotely exploitable without authentication, across services like DNS, DHCP, SMB, and Active Directory, plus critical fixes in Exchange, SharePoint, SQL Server, and Kerberos. The sheer volume makes prioritization essential.

Check
Prioritize the two exploited zero-days and the roughly 20 wormable, internet-facing flaws in this month's update, deploying them first, then work through the rest based on exposure and asset criticality.
Affected
Windows and Microsoft server environments across the board (CVE-2026-85880, CVE-2026-81963, and others); the exploited zero-days give local attackers SYSTEM privileges, while wormable flaws in core network services could spread remotely without authentication.
Fix
Apply the September updates promptly, patching exploited and wormable issues first, watch for privilege-escalation activity these flaws enable when chained with initial access, and test large rollouts given the release size.

Critical SAP kernel flaw lets unauthenticated attackers run commands as admin

SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.

Check
Apply SAP's September security notes for the kernel and NetWeaver Message Server immediately, and identify any SAP systems whose Internet Communication Manager is reachable from the internet as top priority.
Affected
Organizations running affected SAP systems, especially with an internet-facing Internet Communication Manager (CVE-2026-44756, CVE-2026-58240); unauthenticated remote attackers can execute commands as admin or run code across the whole SAP cluster.
Fix
Patch the SAP kernel and Message Server now, restrict and monitor internet exposure of the Internet Communication Manager and message server ports, and watch for unusual command execution on affected SAP hosts.

FreeIPA flaw chain lets anonymous clients grant themselves admin credentials

Red Hat disclosed a flaw chain in FreeIPA, the identity-management system that controls logins across Linux domains, that lets a client which never authenticated create an administrator account for itself. The FreeIPA flaw, CVE-2026-76578 and rated 9.8, is an access rule that lets anyone write a one-time-password token without logging in, and does not restrict what else is written alongside it. The second flaw, CVE-2026-76560 in the underlying 389 Directory Server, treats an unauthenticated client's empty name as matching an empty ownership field, so it passes an owner-only check by being nobody. Together they let an anonymous client write a Kerberos identity into the administrators group; a default install is affected.

Check
Apply Red Hat's updates for FreeIPA and 389 Directory Server as soon as available, and audit your directory for unexpected Kerberos identities and accounts recently added to the administrators group.
Affected
Organizations running FreeIPA or Red Hat Identity Management (CVE-2026-76578, CVE-2026-76560); an unauthenticated client can create an admin-level Kerberos identity, and a default install is vulnerable, putting the whole identity system at risk.
Fix
Patch FreeIPA and the directory server promptly, restrict who can reach the directory service over the network, hunt for rogue tokens and admin accounts, and rotate credentials if abuse is found.