Windows Defender ShieldCrash Exploit Bypasses Patch

A new Windows Defender ShieldCrash exploit grants SYSTEM access on fully patched systems, defeating the fix Microsoft shipped days earlier.

A new Windows Defender ShieldCrash exploit went public on September 9, granting SYSTEM-level access on fully patched Windows 10, Windows 11, and Windows Server systems, including machines that had already installed Microsoft’s own September Patch Tuesday fix for the previous bug in the same family. No CVE has been assigned, and no patch or official…

Read More

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…

Read More

Adobe Commerce Magento RCE Vulnerability Under Attack

Adobe Commerce Magento RCE Vulnerability Under Attack

An Adobe Commerce Magento RCE vulnerability nicknamed StyleSmuggler let attackers plant Rust-based Linux backdoors on live webshops for at least five days before Adobe shipped a fix. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, the flaw requires no authentication and has already been used to backdoor real merchant sites, not just proof-of-concept…

Read More

Chrome Zero-Day Vulnerability Exploited Before the Patch

A Chrome zero-day vulnerability was already being exploited when Google shipped the fix — the sixth such Chrome bug patched in 2026.

Google says a Chrome zero-day vulnerability was already being exploited in the wild when it shipped a fix for it. Tracked as CVE-2026-85046 (CVSS 8.8), the flaw sits in V8, Chrome’s JavaScript and WebAssembly engine, and lets a crafted web page execute attacker-controlled code inside the browser sandbox. Security reporting identifies it as the sixth…

Read More

SonicWall SMA1000 RCE Vulnerability: Patch Now

SonicWall SMA1000 RCE vulnerability

A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…

Read More