Windows Defender ShieldCrash Exploit Bypasses Patch

A new Windows Defender ShieldCrash exploit grants SYSTEM access on fully patched systems, defeating the fix Microsoft shipped days earlier.

A new Windows Defender ShieldCrash exploit went public on September 9, granting SYSTEM-level access on fully patched Windows 10, Windows 11, and Windows Server systems, including machines that had already installed Microsoft’s own September Patch Tuesday fix for the previous bug in the same family. No CVE has been assigned, and no patch or official…

Read More

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…

Read More

Top 5 Cybersecurity News Stories September 11, 2026

Cybersecurity News Stories September 11, 2026: record Patch Tuesday, Magento CVSS 10 RCE, TerminalFix Berlin, MikroTrick router hijack, BlueMoon Chrome APT kit.

This week’s Cybersecurity News Stories September 11, 2026 expose five distinct layers of the assumed-safe environment, each under active pressure. Microsoft’s September Patch Tuesday arrived with 974 CVEs — the largest single monthly release on record — including two zero-days already exploited in the wild and 20 vulnerabilities that researchers assessed as potentially wormable. A…

Read More

N-able N-central RCE Vulnerability Hit Again

N-able N-central RCE Vulnerability Hit Again

An N-able N-central RCE vulnerability has forced the vendor to ship its fourth emergency hotfix in five weeks, and Huntress investigators say a customer’s server — already patched against an earlier round of flaws — was compromised a second time anyway. Tracked as CVE-2026-86218 with a maximum CVSS score of 10.0, the flaw hits a…

Read More

Adobe Commerce Magento RCE Vulnerability Under Attack

Adobe Commerce Magento RCE Vulnerability Under Attack

An Adobe Commerce Magento RCE vulnerability nicknamed StyleSmuggler let attackers plant Rust-based Linux backdoors on live webshops for at least five days before Adobe shipped a fix. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, the flaw requires no authentication and has already been used to backdoor real merchant sites, not just proof-of-concept…

Read More