Check Point VPN Certificate Vulnerability: Patch Now

A Check Point VPN certificate vulnerability pair (CVSS 9.8) allows pre-auth RCE. Dutch NCSC warns exploitation is imminent; patch today.

Check Point disclosed a Check Point VPN certificate vulnerability pair, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, on September 9, and the Dutch National Cyber Security Centre has since warned that large-scale exploitation is likely imminent, even though Check Point itself has not yet observed attacks in the wild. Both flaws allow unauthenticated remote code execution…

Read More

Windows Defender ShieldCrash Exploit Bypasses Patch

A new Windows Defender ShieldCrash exploit grants SYSTEM access on fully patched systems, defeating the fix Microsoft shipped days earlier.

A new Windows Defender ShieldCrash exploit went public on September 9, granting SYSTEM-level access on fully patched Windows 10, Windows 11, and Windows Server systems, including machines that had already installed Microsoft’s own September Patch Tuesday fix for the previous bug in the same family. No CVE has been assigned, and no patch or official…

Read More

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…

Read More

Adobe Commerce Magento RCE Vulnerability Under Attack

Adobe Commerce Magento RCE Vulnerability Under Attack

An Adobe Commerce Magento RCE vulnerability nicknamed StyleSmuggler let attackers plant Rust-based Linux backdoors on live webshops for at least five days before Adobe shipped a fix. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, the flaw requires no authentication and has already been used to backdoor real merchant sites, not just proof-of-concept…

Read More

Chrome Zero-Day Vulnerability Exploited Before the Patch

A Chrome zero-day vulnerability was already being exploited when Google shipped the fix — the sixth such Chrome bug patched in 2026.

Google says a Chrome zero-day vulnerability was already being exploited in the wild when it shipped a fix for it. Tracked as CVE-2026-85046 (CVSS 8.8), the flaw sits in V8, Chrome’s JavaScript and WebAssembly engine, and lets a crafted web page execute attacker-controlled code inside the browser sandbox. Security reporting identifies it as the sixth…

Read More