Visualização normal

Hoje — 8 de Setembro de 2026Stream principal

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

8 de Setembro de 2026, 08:19

SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note.

The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.

The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating.

The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and 9.16 through 9.20.

An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability. Organizations using affected SAP kernel components should treat this update as an emergency patching priority.

Another critical vulnerability, CVE-2026-58240, affects SAP NetWeaver Message Server. SAP Note 3759472 addresses a missing authentication check with a CVSS score of 9.8. The issue affects KERNEL versions 9.16, 9.18, 9.19, and 9.20.

Successful exploitation could allow an attacker without valid credentials to access or interact with exposed services, creating a serious risk to SAP environments.

SAP Security Updates September 2026

SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability in multitenant applications using the SAP Cloud Application Programming Model library sap/cds-mtxs.

The flaw has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators should update affected dependencies quickly, especially where they handle tenant data and application credentials.

A fourth critical issue, CVE-2026-66768, impacts SAP GUI for Java in SAP NetWeaver. The improper access control vulnerability, fixed by SAP Note 3781729, has a CVSS score of 9.0. It affects BC-FES-JAV 8.10 and could allow a low-privileged attacker to gain unauthorized access after user interaction.

The September release also includes high-severity fixes, including CVE-2026-76958, an 8.5-rated XXE flaw in SAP Integration Suite Trading Partner Management that could expose sensitive files, enable server-side requests, or disrupt XML processing.

SAP patched insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.

The company also released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools originally addressed during the August 2026 Patch Day.

SAP NoteCVEVulnerabilityAffected product/versionsPriority
3747649CVE-2026-44756Memory corruptionSAP Extended Passport (EPP) Processing
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; WEBDISP: 9.16, 9.18, 9.19, 9.20; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
Critical
3759472CVE-2026-58240Missing authentication checkSAP NetWeaver Message Server
KERNEL: 9.16, 9.18, 9.19, 9.20
Critical
3798315CVE-2026-76969Credential disclosure in multitenant CAP applicationsSAP CAP library sap/cds-mtxs
Versions: ≤1.18.3, ≤2.7.6, ≤3.9.6, ≤4.0.2
Critical
3781729CVE-2026-66768Improper access controlSAP NetWeaver SAP GUI for Java
BC-FES-JAV: 8.10
Critical
3772411CVE-2026-58243Privilege escalation — updated August noteSAP ABAP Developer Tools
SAP_BASIS: 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920
High
3792978CVE-2026-76958XML External Entity (XXE)SAP Integration Suite
Cloud Integration – Trading Partner Management V2: 2.9.2; B2B Integration Factory – Cloud Integration – Trading Partner Management: 1.10.0
High
3784138CVE-2026-76967Insecure deserializationSAP NetWeaver Business Client
BC-WD-CLT-BUS: 8.00, 8.10
High
3757002CVE-2026-66767Memory corruptionSAP NetWeaver AS for ABAP and ABAP Platform
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
High
3791068CVE-2026-2332CRLF injection through Jetty componentsSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
High
3750721CVE-2026-76968Information disclosureSAP Web Dispatcher, Internet Communication Manager, and SAP Content Server
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53; WEBDISP: 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16; CONTSERV: 7.53, 7.54; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20
Medium
3756450CVE-2026-44766SQL injectionSAP S/4HANA Intercompany Matching and Reconciliation
SAPSCORE: 136; S4CORE: 104, 105, 106, 107, 108, 109
Medium
3786489CVE-2026-76971Server-Side Request Forgery (SSRF)SAP Manufacturing Integration and Intelligence
XMII: 15.4, 15.5
Medium
3787345CVE-2026-34477Security misconfiguration due to Apache Log4jSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
Medium
3783189CVE-2026-76977ClickjackingSAPUI5 Frame Options Allowlist
SAP_UI: 750, 754, 755, 756, 757, 758, 816; UI_700: 200
Medium
3365276CVE-2026-76960Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 105, 106, 107
Medium
3371336CVE-2026-76961Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 108
Medium
3365311CVE-2026-76959Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
UIAPFI70: 800, 900, 901, 902
Medium
3657599CVE-2026-76962Missing authorization checkSAP S/4HANA Manage Bank Chains app
S4CORE: 107, 108, 109
Medium
3772838CVE-2026-76963Missing authorization checkSAP NetWeaver and ABAP Platform
SAP_BASIS: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758
Medium
3736494CVE-2026-58234Denial of serviceSAP Process Integration SOAP Adapter
MESSAGING: 7.50; SAP_XIAF: 7.50
Low

Medium-severity fixes cover SQL injection, server-side request forgery, clickjacking, cross-site request forgery, information disclosure, authorization bypass, and Apache Log4j-related security misconfiguration issues. SAP also patched a low-severity denial-of-service flaw in the SAP Process Integration SOAP Adapter.

SAP administrators should review all relevant security notes in the SAP Support Portal, map them to deployed product versions, test patches under change-control procedures, and apply the fixes as soon as possible.

Internet-facing SAP services, NetWeaver Message Server instances, cloud application dependencies, and systems processing sensitive business data should receive priority attention.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport appeared first on Cyber Security News.

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Cyber Security News
  • Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass Abinaya
    Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks. The new releases, Roundcube 1.6.19 and 1.7.4, address flaws in how the open-source webmail platform processes email content, HTML, Cascading Style Sheets, attachment metadata, contact groups, and remote URLs. Admin
     

Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass

7 de Setembro de 2026, 07:49

Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks.

The new releases, Roundcube 1.6.19 and 1.7.4, address flaws in how the open-source webmail platform processes email content, HTML, Cascading Style Sheets, attachment metadata, contact groups, and remote URLs. Administrators running production deployments of Roundcube 1.6.x or 1.7.x are urged to update as soon as possible.

One of the most serious issues fixed is a zero-click stored cross-site scripting vulnerability involving the injection of TNEF MIME tags into attachment URLs.

TNEF, or Transport Neutral Encapsulation Format, is commonly associated with Microsoft Outlook attachments. An attacker could potentially send a specially crafted email that triggers malicious script execution when the victim views the message, without requiring the user to click a link or open an attachment.

The updates also fix another XSS issue in Roundcube’s HTML editor when handling text/enriched email content. Cross-site scripting weaknesses can allow attackers to execute JavaScript in a victim’s webmail session, creating opportunities to steal session tokens, alter mailbox settings, read messages, or perform actions as the logged-in user.

Several fixes address email header injection risks. These bugs affected the subject field, recipient display name, and an identity’s organization field.

Header injection vulnerabilities can be abused to manipulate email metadata or insert unexpected mail headers if malicious input is not correctly sanitized.

Roundcube also patched a cross-user access issue in SQL-based address books. The flaw involved adding or removing members from contact groups.

It could allow one user to modify another user’s group associations under certain conditions. This type of issue can compromise contact privacy and the integrity of address book data in shared or hosted Roundcube environments.

Remote-content protections received multiple fixes, addressing CSS declaration smuggling, HTML body background property injection, CSS-escape bypasses in FuncIRI attributes, and SVG SMIL source animation techniques that could bypass remote-content blocking.

Roundcube Webmail Patches 12 Security Flaws

The updates further fix an is_local_url() validation bypass involving fully qualified domain names with a trailing dot in stylesheet URLs. Attackers could exploit differences in URL parsing to make an external resource appear local and bypass intended restrictions.

A server-side request forgery bypass was also resolved in the Roundcube CSS proxy. The weakness involved hexadecimal IPv6-mapped IPv4 addresses, which could potentially help an attacker bypass address validation and force the server to request internal or restricted network resources.

Roundcube said full technical details are available in the release notes for versions 1.6.19 and 1.7.4. The project strongly recommends that all organizations operating affected Roundcube installations apply the updates promptly.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass appeared first on Cyber Security News.

  • ✇Cyber Security News
  • OpenVPN Fixes 7 Security Flaws Affecting VPN Connections and Windows Systems Guru Baran
    The OpenVPN project has shipped version 2.7.7, a security-focused release that patches seven distinct vulnerabilities spanning the software’s core reliability layer and its Windows-specific service components. The update, released on September 3, 2026, addresses issues ranging from denial-of-service conditions to buffer overreads and configuration bypasses that could allow attackers to run unauthorized VPN configurations. The most broadly impactful fix, tracked as CVE-2026-84732, targets O
     

OpenVPN Fixes 7 Security Flaws Affecting VPN Connections and Windows Systems

7 de Setembro de 2026, 06:46

The OpenVPN project has shipped version 2.7.7, a security-focused release that patches seven distinct vulnerabilities spanning the software’s core reliability layer and its Windows-specific service components.

The update, released on September 3, 2026, addresses issues ranging from denial-of-service conditions to buffer overreads and configuration bypasses that could allow attackers to run unauthorized VPN configurations.

The most broadly impactful fix, tracked as CVE-2026-84732, targets OpenVPN’s reliability layer, a component responsible for managing TLS handshakes and acknowledgment packets.

The flaw combined two separate bugs: an unbounded reliable TLS timeout and improper handling of acknowledgments for packets that could never legitimately be outstanding. Both issues were discovered by security researcher Mark Bregman of Fox-IT, and since the reliability layer is shared across all supported platforms, the fix benefits Linux, Windows, and macOS deployments alike.

Six of the seven vulnerabilities specifically affect Windows installations, reflecting how deeply OpenVPN’s Windows service architecture had accumulated edge-case weaknesses.

OpenVPN Fixes 7 Security Flaws

CVE-2026-84256 involved incorrect command-line quoting in the CreateProcess() function, where characters with special meaning to cmd.exe could, in combination with a validation script and a rogue certificate authority, lead to unexpected behavior.

A related flaw, CVE-2026-84226, affected the tapctl utility, which previously invoked netsh.exe without specifying its full file path, a gap that researchers at BreachX Zero Day Labs identified using their Typhon AI Mil v2 tooling.

Local privilege abuse was also on the table. CVE-2026-82312 stemmed from OpenVPN’s use of NULL discretionary access control lists (DACLs) on system objects, including the service exit event and the netsh.exe guard semaphore.

This design flaw enabled a local denial-of-service scenario in which one logged-in user could interfere with another user’s OpenVPN session by blocking the semaphore or triggering spurious events, though the issue applies only to setups that skip the interactive service or rely on the automatic Windows service.

Two additional Windows flaws affected openvpnserv, the Windows service component. CVE-2026-78221 caused a buffer overread when internationalized domain names using UTF-8 encoding were processed, because the NRPT domain size passed to the function was incorrect.

Separately, CVE-2026-78043 revealed that openvpnserv’s configuration path validation failed to block forward slashes, even though Windows file-open APIs treat them as valid path separators. This mismatch could let an attacker slip past administrative restrictions and force openvpn.exe to launch a configuration file it was never authorized to run.

Rounding out the list, CVE-2026-81738 fixed an off-by-one error in write_dhcp_search_str(), where specially crafted DHCP search-domain options could overflow a temporary buffer by a single byte, a bug credited to researchers Andre Kropp of Nexory and ChinhNguyen.

CVE IDComponentPlatformIssue TypeImpact
CVE-2026-84732Reliability layerAll platformsUnbounded reliable TLS timeout + acking non-outstanding packetsPotential DoS via TLS handshake mishandling
CVE-2026-84256CreateProcess()WindowsImproper command-line quoting of cmd.exe special charactersMisbehavior when combined with validation script + rogue CA
CVE-2026-84226tapctl utilityWindowsnetsh.exe invoked without full pathPotential binary hijacking/path abuse
CVE-2026-82312Service exit event / netsh guard semaphoreWindowsNULL DACL on system objectsLocal DoS — one user can interfere with another user’s OpenVPN process
CVE-2026-78221openvpnservWindowsIncorrect NRPT domain size with UTF-8 IDN domainsBuffer overread
CVE-2026-78043openvpnservWindowsConfig path validation doesn’t block ‘/’ separatorBypass of admin-restricted config paths, unauthorized config execution
CVE-2026-81738write_dhcp_search_str()WindowsOff-by-one in temp buffer guardSingle-byte buffer overflow via crafted DHCP options

Beyond the CVE fixes, OpenVPN 2.7.7 adds a Linux-specific improvement that validates netlink replies against the originating request, an enhancement suggested by researcher Joshua Rogers.

The release also reduces the number of future keys retained under the EPOCH data-channel format from sixteen to four, easing log noise and resource usage on high-throughput links, alongside several networking bug fixes affecting TCP handshakes, UDP checksum handling, and OpenSSL’s HMAC key management.

Administrators running OpenVPN on Windows should prioritize this update given the concentration of local-privilege and configuration-bypass flaws, while all users benefit from the reliability-layer patch. The release notes and full CVE details are published on the OpenVPN Community Wiki’s security announcements page.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post OpenVPN Fixes 7 Security Flaws Affecting VPN Connections and Windows Systems appeared first on Cyber Security News.

  • ✇Cyber Security News
  • N-able Released Hotfix for RCE Vulnerability Affecting Platform Abinaya
    N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified as build 2026.3.1.14, was issued for on-premises N-central deployments. N-able urged self-hosted customers to install the hotfix immediately, warning that systems left unpatched remain at risk even though the company has not confirmed exploitation in production environments. C
     

N-able Released Hotfix for RCE Vulnerability Affecting Platform

7 de Setembro de 2026, 05:35

N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server.

The update, identified as build 2026.3.1.14, was issued for on-premises N-central deployments. N-able urged self-hosted customers to install the hotfix immediately, warning that systems left unpatched remain at risk even though the company has not confirmed exploitation in production environments.

CVE-2026-86218 is a pre-authenticated remote code execution vulnerability. This means an attacker may be able to trigger the flaw without first logging in or providing valid user credentials. If successfully exploited, the issue could allow an attacker to run commands on the N-central server.

N-central is used by managed service providers and IT teams to monitor, manage, automate, and secure customer systems. Because the platform can have broad access across endpoints, networks, credentials, and administrative tools, a compromise of the central management server could create serious downstream risks.

Attackers who gain control of an N-central server could potentially use that access to deploy malicious software, alter monitoring settings, steal stored information, create unauthorized accounts, or move further into managed customer environments.

N-able Released Hotfix

The exact technical details and attack vector for CVE-2026-86218 have not been publicly disclosed. N-able said a third party responsibly reported the flaw through its security disclosure program. The vendor stated that it currently has no confirmation of active exploitation.

However, organizations should not treat the lack of known attacks as a reason to delay patching. Public patch releases can help threat actors identify vulnerable systems and develop exploit attempts.

The new release replaces N-central 2026.3 Hotfix 3, build 2026.3.1.13. Customers running versions 2025.4, 2026.1, 2026.2, 2026.3, 2026.3.1 Hotfix 1, or 2026.3.1 Hotfix 2 can upgrade directly to build 2026.3.1.14. Organizations using older releases should first move to a supported upgrade version and then apply the latest hotfix.

N-able confirmed that hosted N-central customers, also known as NCOD users, do not need to take any action because the patches have already been applied to their environments. The urgent action applies to organizations operating their own self-hosted N-central infrastructure.

The company also said administrators do not need to upgrade N-central agents specifically to address CVE-2026-86218. However, it recommended keeping agents up to date with the latest available version as a general security practice.

Security teams should identify all self-hosted N-central instances, confirm their installed build number, and schedule the update to 2026.3.1.14 as soon as possible.

Administrators should also review server access logs, administrator account activity, remote command execution records, and unusual configuration changes for signs of suspicious behavior before and after patching.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post N-able Released Hotfix for RCE Vulnerability Affecting Platform appeared first on Cyber Security News.

Antes de ontemStream principal
  • ✇Cyber Security News
  • ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System Guru Baran
    ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password or any user interaction. Tracked as CVE-2026-75754, the flaw carries a CVSS 4.0 score of 10.0, the highest possible rating, reflecting how easily it can be exploited over a network and the catastrophic scope of wha
     

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

6 de Setembro de 2026, 07:57

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password or any user interaction.

Tracked as CVE-2026-75754, the flaw carries a CVSS 4.0 score of 10.0, the highest possible rating, reflecting how easily it can be exploited over a network and the catastrophic scope of what an attacker can achieve once inside.

ASUS Control Center Vulnerability

The vulnerability actually stems from a chain of three separate weaknesses working together. ASUS Control Center is missing authentication on a critical function, meaning certain sensitive operations can be triggered by anyone who can reach the service over the network.

That gap is compounded by a server-side request forgery flaw, which lets an attacker send a specially crafted HTTP request to trick the system into exposing its own encryption key. Once that key is retrieved, a local service on the host automatically enables an SSH listener on TCP port 2222, effectively opening a hidden backdoor into the machine.

The final piece of the chain is arguably the most damaging: ASUS Control Center contains hard-coded credentials baked into the software itself. Attackers who obtain the encryption key can use these fixed credentials to log directly into the newly opened SSH port and land a full root shell, the highest level of system access available on the machine.

From there, intruders can read, modify, or delete any data stored in ACC, and because the platform is designed to centrally manage fleets of servers, PCs, and workstations, a single compromised ACC instance can hand attackers remote control over an entire corporate IT environment.

The flaw affects all versions of ASUS Control Center Enterprise up to and including 4.0.0.2. ASUS is urging every organization running the software to update immediately to version 3.1.0.9 or later, and confirms further fix details are posted on its official Security Advisory page.

Enterprises unable to patch right away should isolate ACC management interfaces from public networks, block inbound and outbound traffic on port 2222, and audit hosts for unexpected SSH listeners as an interim safeguard.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access Guru Baran
    Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover. MikroTik confirmed on September 3, 2026, that it had discovered a serious security vulnerability affecting RouterOS and had already shipped fixes across every release channel, including 7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, and 6.49.21 long-term. The
     

Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access

6 de Setembro de 2026, 07:25

Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover.

MikroTik confirmed on September 3, 2026, that it had discovered a serious security vulnerability affecting RouterOS and had already shipped fixes across every release channel, including 7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, and 6.49.21 long-term.

The vendor deliberately withheld technical specifics in its initial advisory, stating plainly that it was “not currently publishing detailed information” in order to give administrators time to update before attackers could reverse-engineer the flaw from public disclosure.

Despite that caution, exploitation began almost immediately, and forum users and researchers quickly pieced together the attack mechanics on their own.

MikroTik RouterOS Vulnerability

According to detailed discussion on the official MikroTik support forum, the vulnerability lives inside a core library used by multiple RouterOS services, meaning any exposed service built on that codebase can be leveraged as an entry point.

One forum contributor who reverse-engineered the issue confirmed it is tied to SSH and grants any unauthenticated remote attacker direct shell access to the device, regardless of whether the router relies on password authentication or SSH key-based login.

In practical terms, if the SSH service is reachable from the internet or an untrusted network, the router is vulnerable until it receives the patch, with no additional credential theft or user interaction required.

Latvia’s national CERT issued its own alert corroborating a marked increase in attacker activity specifically targeting MikroTik routers, urging organizations and home users alike to update immediately to the patched builds MikroTik released. The agency’s guidance mirrored MikroTik’s own version list, reinforcing that the fix spans both the newer 7.x stable and legacy long-term branches.

Evidence of live exploitation surfaced quickly within the MikroTik user community. One administrator reported on Reddit that around September 2, 2026, at 08:00 UTC, an unauthorized user account named “ops” was created by another rogue account labeled “0,” granted both write and policy permissions, with the intrusion traced back to an SSH connection originating from the IP address 82.192.72.4.

The administrator noted that while the rogue account appeared to be used mainly for logging in and no obvious malicious scripts were visible in the configuration, the team suspected deeper compromise that RouterOS itself could not detect, ultimately requiring a full netinstall to guarantee the devices were clean.

RouterOS now includes a built-in detection mechanism to help flag this exact scenario. After upgrading, the operating system automatically inspects the full configuration at startup and sets a device to “Flagged” status if it finds signs of unauthorized tampering, logging a critical entry in the system log.

Devices in this state face operational restrictions, including a block on enabling new scheduler entries, SOCKS proxy, PPTP, L2TP, IPsec, proxy, and SMB configurations, until an administrator performs a manual audit.

MikroTik’s guidance is straightforward: if a device shows as flagged, assume it has been compromised, audit every configuration line, rotate all passwords, and only then clear the flagged state.

Even routers that never show a flagged status should not be considered safe by default; MikroTik and independent researchers both recommend manually reviewing configurations for unrecognized users, scripts, or scheduled tasks after updating, since some compromise artifacts may not trigger the automated detection.

Restricting SSH and other management interfaces from the public internet, enforcing key-based authentication, and limiting administrative access to trusted management networks remain essential complementary defenses while the patch rolls out fleet-wide.

Given the scale of MikroTik’s install base and the confirmed low barrier to exploitation, security teams should treat this as an urgent, internet-facing remote code execution scenario rather than a routine maintenance update.

Upgrading to 7.24.2, 7.23.4, or 6.49.21 (or later), auditing every device regardless of flagged status, and hardening remote management access should be treated as immediate priorities rather than items for the next maintenance window.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability Guru Baran
    A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security firm Sansec disclosed the flaw, dubbed StyleSmuggler, on September 5, 2026, warning that unauthenticated attackers can achieve remote code execution on vulnerable installations and that live attacks began the previous day . The company said it was publish
     

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

6 de Setembro de 2026, 00:52

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available.

Dutch e-commerce security firm Sansec disclosed the flaw, dubbed StyleSmuggler, on September 5, 2026, warning that unauthenticated attackers can achieve remote code execution on vulnerable installations and that live attacks began the previous day .

The company said it was publishing its findings early, before completing its full technical analysis, “because stores are being compromised right now”.

StyleSmuggler affects every current version of Magento and Adobe Commerce, including the latest 2.4.9 release, and requires no authentication whatsoever to exploit.

Sansec reproduced the complete unauthenticated attack chain on clean installations of Magento Open Source 2.4.7, 2.4.8, and 2.4.9, confirming the bug is not tied to any single outdated build.

Disturbingly, the first identified victim was running 2.4.6-p15 with July and August 2026 security patches fully applied, meaning fully patched stores were compromised just as easily as neglected ones.

As of September 6, Adobe has not issued an advisory, assigned a CVE identifier, or released any official fix or workaround, and the company’s most recent Commerce security bulletin still dates to August 11.

The exploit unfolds in two distinct stages that abuse Magento’s own template rendering and email systems rather than a single obvious injection point. In the first stage, attackers plant malicious PHP code inside a file that Magento itself writes during normal operation, such as a payment failure report, by manipulating “styles” properties within a GraphQL request to slip past existing input sanitization.

Magento and Adobe Commerce 0-Day RCE

Independent analysis from Magento hosting firm Disrex Group, which handled two breached stores, found that a crafted directive inside the injected text forces a chain of Magento’s own classes to execute code that was only ever meant to run through the command-line dependency-injection compiler, ultimately including the attacker-poisoned log file.

The second stage triggers execution. Sansec found that StyleSmuggler deliberately causes Magento to send its standard “Payment Transaction Failed Reminder” email, and the poisoned code runs the moment Magento renders that message internally, meaning nobody has to open or even receive the email for the attack to succeed.

Attack chain (Source: Disrex)

Once triggered, a PHP dropper cycles through six different PHP functions until it finds one capable of spawning a process, then downloads and launches a persistent implant. Disrex described the malware as a small, statically linked Rust binary of roughly 1.9 megabytes, compiled for both x86-64 and ARM64 architectures, disguised as a Linux kernel thread named “[kworker/u:8:0]” and restarted every five minutes through a cron entry written directly into the crontab spool file to avoid leaving normal system logs.

Detecting an infection is harder than it sounds because the malware actively evades naive checks. A genuine Linux kernel worker thread is owned by root and consumes no resident memory, so any bracketed “[kworker]” process running under a website’s own user account with real memory usage is a red flag.

Disrex also discovered that the binary running in memory sometimes differs from the file sitting on disk, meaning defenders should hash both the file and the live process to be thorough.

On one compromised store, the implant made no outbound internet connections at all, instead opening 28 simultaneous connections to the site’s own Redis instance to read live Magento session data, which let it operate almost invisibly to network-based monitoring.

Sansec’s own detection guidance searches Magento’s var/report directory for a marker string, but Disrex found both of its breached stores were actually poisoned through var/log/system.log instead, meaning administrators need to check both locations.

With Adobe’s next scheduled security release set for September 8 and no confirmation it will address this flaw, store owners are left relying on stopgap measures. Sansec recommends temporarily disabling GraphQL entirely for stores that don’t rely on headless or progressive web app storefronts, since classic and Hyvä themes generally don’t need it.

Disrex, security researcher ProxiBlue, and vendor Graycore have each independently published unofficial code patches that guard specific Magento classes and email template functions, though all three stress these are hardening measures rather than a genuine fix, and Disrex specifically warns its rules only block the current attack traffic pattern, not the underlying vulnerability.

Server-level protections that don’t depend on understanding the exploit chain at all, such as disabling PHP’s proc_open function and mounting temporary directories with noexec, have also proven effective at stopping the dropper from launching its payload.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws Abinaya
    Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed security issues affecting Plex Media Server versions 1.43.2 and earlier, as well as affected Plex Desktop installations. Plex released Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0 to resolve the flaws. The company has not yet published technical details about the vulnerabilities, inc
     

Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

4 de Setembro de 2026, 09:17

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible.

The update addresses multiple undisclosed security issues affecting Plex Media Server versions 1.43.2 and earlier, as well as affected Plex Desktop installations. Plex released Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0 to resolve the flaws.

The company has not yet published technical details about the vulnerabilities, including their severity, attack requirements, affected components, or potential impact. Plex said it has requested CVE identifiers and will provide more information after they are published.

The lack of public vulnerability details means administrators should treat the update as a priority, especially where Plex servers are exposed to the internet, use remote-access features, or run on systems holding large personal media libraries.

A vulnerable media server could potentially create opportunities for unauthorized access, data exposure, service disruption, or further compromise, depending on the nature of the flaws.

Plex Fixes Multiple Security Flaws

Plex Media Server is widely deployed on Windows, macOS, Linux, network-attached storage devices, Docker environments, and NVIDIA Shield devices.

This broad platform support makes patch management important because update availability may differ by operating system and hardware vendor.

Windows and macOS users with automatic updates enabled should confirm that their Plex Media Server is running version 1.43.3 or later.

Users who do not receive the update automatically can download the newest server package from Plex’s official Media Server downloads page. Plex also recommends that Desktop users move to Plex Desktop version 1.115.0.

Linux administrators should download the appropriate installation file for their distribution. Ubuntu and Debian-based systems use the .deb package, while Fedora and CentOS-based deployments use the .rpm package.

Administrators should verify the downloaded filename before running installation commands and should restart or validate the service after deployment. NAS users may experience delays because vendor-managed application stores do not always publish new Plex packages immediately.

Plex said affected users can manually download the correct package for their NAS model and install it via the device’s web-based app management interface. The company pointed users toward vendor-specific instructions for QNAP, TerraMaster, Western Digital, Netgear, and Synology systems.

Docker users should follow Plex’s official container deployment guidance and ensure they pull and deploy an image containing the fixed Plex Media Server release.

Organizations running Plex in containers should also review image tags, container restart policies, exposed ports, remote access settings, and reverse-proxy configurations.

Administrators should not rely solely on an update notification. They should open the Plex server dashboard or package manager and confirm the installed version after patching.

Security teams may also want to review server logs for unexpected login attempts, unusual remote connections, new administrator sessions, or unexplained configuration changes while waiting for further CVE and technical disclosure details from Plex.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code Abinaya
    TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The flaws, tracked as CVE-2026-18167 and CVE-2026-18330, affect the EasyMesh and web login modules in Archer AX55 hardware version V4. TP-Link released firmware version 1.2.1 Build 20260527 to address both issues. The company published its advisory on September
     

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

4 de Setembro de 2026, 09:16

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices.

The flaws, tracked as CVE-2026-18167 and CVE-2026-18330, affect the EasyMesh and web login modules in Archer AX55 hardware version V4.

TP-Link released firmware version 1.2.1 Build 20260527 to address both issues. The company published its advisory on September 3, 2026.

The most serious issue, CVE-2026-18167, is a stack-based buffer overflow in the router’s EasyMesh component. It has a CVSS v4 score of 7.7 and is rated High severity.

EasyMesh connects compatible networking devices into a single mesh Wi-Fi network. According to TP-Link, the vulnerability becomes exploitable when Mesh mode is enabled on the Archer AX55 v4.

Multiple TP-Link Archer Vulnerabilities

An attacker connected to the target’s local network could send specially crafted input to the EasyMesh service, known as the easymesh daemon. The malicious input could force the service to crash.

In some cases, the flaw could also allow the attacker to run code on the router. Remote code execution on a router is particularly dangerous because the device sits between local systems and the internet.

Attackers who compromise a router may attempt to monitor network traffic, alter DNS settings, redirect users to malicious websites, scan connected devices, or use the router as a foothold to attack the wider network.

TP-Link said successful exploitation could have a high impact on the confidentiality, integrity, and availability of the affected router. However, the attack requires local network access, and Mesh mode must be enabled.

The second vulnerability, CVE-2026-18330, affects the Archer AX55 v4 web login module. The flaw is caused by a hardcoded shared RSA-1024 private key embedded in the product.

A local attacker who captures an HTTP-based administrator login session could use the known private key to decrypt the administrator password. TP-Link also noted that a weak AES session key reduces the effort required to compromise the login session’s confidentiality.

The issue received a CVSS v4 score of 6.1 and is rated Medium severity. Although it does not directly provide code execution, stolen router administrator credentials could give an attacker control over key configuration settings.

The weakness highlights the risks of using HTTP for administrative access. Unencrypted HTTP sessions can expose sensitive login data to attackers on the same network, especially on insecure or shared Wi-Fi networks.

The vulnerabilities affect TP-Link Archer AX55 routers with hardware version V4. The fixed firmware version is 1.2.1 Build 20260527. TP-Link strongly recommends that owners update their devices as soon as possible through the official Archer AX55 V4 firmware download page.

Users should also turn off Mesh mode when not needed, avoid managing the router over HTTP, use a strong, unique administrator password, and ensure that router management access is not exposed to untrusted networks.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code appeared first on Cyber Security News.

  • ✇Firewall Daily – The Cyber Express
  • Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures Mihir Bagwe
    At least 14 people connected to Serbia's student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country. The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at
     

Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures

4 de Setembro de 2026, 03:06

Pegasus, Pegasus Spyware, Serbia, Serbia Protests, Smartphone screen forming an eye shape against an abstract protest crowd, illustrating spyware targeting of Serbian student activists.

At least 14 people connected to Serbia's student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country.

The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at the University of Toronto and by Amnesty International's Security Lab.

Citizen Lab, in its own findings, said it verified an infection with NSO Group's Pegasus on the iPhone of a student activist who asked not to be named. High-confidence infection indicators span December 2025 through January 2026, delivered by a zero-click iMessage exploit that required no interaction from the target. Apple has since patched the underlying flaw; the fix shipped in iOS 18.4.1. Pegasus grants an operator access to notes, photographs and messages decrypted on the device, and can silently activate the microphone and camera.

Amnesty's Security Lab confirmed a new variant of NoviSpy, an Android implant first identified in Serbia in 2024, on two additional devices. SHARE said the rebuilt version was designed to evade the detection methods that exposed its predecessor.

Also read: Investigative Journalists in Serbia Hit by Advanced Spyware Attack

The circumstances of two infections are what elevate the findings beyond routine spyware reporting. SHARE said one NoviSpy infection appeared after police seized a student's phone during questioning, and another after private messages from that device were published by a pro-government media outlet. Donncha Ó Cearbhaill, who heads Amnesty's Security Lab, said the evidence suggests "infections are being carried out during detention by Serbian authorities."

Suspicion centers on Serbia's Security Information Agency, or BIA. Amnesty's December 2024 report "A Digital Prison" found earlier NoviSpy samples configured to send collected data to IP addresses associated with BIA servers, and documented the agency's parallel use of Cellebrite extraction tools on journalists and activists. In March 2025, Amnesty reported that two journalists at the Balkan Investigative Reporting Network were targeted with Pegasus.

The current cases surfaced through Apple's threat notification wave of Aug. 13, which reached users in 110 countries. The timing is politically loaded. The targeting overlaps with protests that followed the November 2024 collapse of a railway station canopy in Novi Sad, spans local elections held March 29 in 10 municipalities, and precedes October parliamentary elections widely read as a test of the ruling Serbian Progressive Party.

Ana Toskic Cvetinovic, a legal expert cited in the reporting, noted that deploying intrusive software without judicial authorization is unlawful under Serbian law. SHARE published an analysis of the domestic legal framework in January arguing the same. Criminal complaints filed over the 2024 cases remain pending before Serbian courts, with no resolution.

Also read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

NSO has been on the U.S. Commerce Department's Entity List since 2021.

Serbia is an accession candidate, the European Parliament has previously questioned the Commission over unlawful spyware use in the country, and the Commission published its 2026 enlargement country report in July. Amnesty's submission for that package raised surveillance directly.

Both groups urged at-risk users to enable Lockdown Mode on iOS or Advanced Protection on Android.

  • ✇Cyber Security News
  • Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host Guru Baran
    Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization. The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the
     

Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

3 de Setembro de 2026, 08:31

Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization.

The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the pair, CVE-2026-59346, is an integer-overflow flaw in the VMXNET3 virtual network adapter. Broadcom rates it at a maximum CVSSv3 score of 9.3, placing it firmly in the critical range.

According to the advisory, a malicious actor who already has local administrative privileges on a virtual machine configured with a VMXNET3 adapter could exploit the flaw to execute code on the host machine itself, effectively escaping the sandboxed VM environment.

The second issue, CVE-2026-59347, is a stack-based buffer-overflow vulnerability in the Host-Guest File System, better known as HGFS, which handles shared folders between a VM and its host.

This flaw carries a CVSSv3 score of 8.1 and is classified as important rather than critical. Exploiting it would allow an attacker with administrative access inside a guest VM to execute code as the VMX process running on the host, giving them a foothold in host-level operations without needing to breach the network adapter directly.

Both vulnerabilities were privately reported to Broadcom rather than discovered through public exploitation, and the company credited multiple independent research teams for the findings.

CVE-2026-59346 was reported separately by researcher h4urek of secsys lab and by Y² and Stan S, working through Trend Micro’s Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen of Tencent’s Xuanwu Lab.

The vulnerabilities affect VMware Workstation versions 25H2 and 26H1 running on any host operating system, as well as VMware Fusion versions 25H2 and 26H1 running on macOS.

Broadcom has released version 26H1u1 to remediate both flaws across the affected product lines. Notably, the advisory states there are no workarounds available for either vulnerability, meaning organizations and individual users cannot mitigate the risk through configuration changes alone and must apply the patch to be protected.

Given that both flaws require only local administrative privileges inside a guest VM to trigger a host-level compromise, security teams running VMware Workstation or Fusion in lab, testing, or malware-analysis environments should treat this as a priority patch.

Virtualization platforms are frequently used to isolate untrusted code, and a working VM-escape chain like this one could let attackers pivot from a contained sandbox straight into production infrastructure.

Administrators are advised to update to version 26H1u1 as soon as possible and audit which virtual machines use VMXNET3 adapters or shared folder features in the interim.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host appeared first on Cyber Security News.

  • ✇Cyber Security News
  • WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks Abinaya
    A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7.110. The issue was reported to Wordfence on August 14, 2026, by security researcher Jack Taylor through the Wordfence Bug Bounty Program. Taylor received a $5,761 bounty for discovering the vulnerability, which received a
     

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

3 de Setembro de 2026, 05:52

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version 7.110.

The issue was reported to Wordfence on August 14, 2026, by security researcher Jack Taylor through the Wordfence Bug Bounty Program. Taylor received a $5,761 bounty for discovering the vulnerability, which received a CVSS score of 8.8.

All-in-One WP Migration and Backup is widely used to export, import, restore, and migrate WordPress sites. It creates .wpress archive files containing website files and database data.

The vulnerable versions, up to and including 7.109, contain an unauthenticated second-order SQL injection flaw in the archive restore process.

Unlike a typical SQL injection attack, the malicious SQL code is not executed immediately. An attacker can first place a specially crafted payload in a WordPress site through the core trackback feature. Trackbacks can be submitted without logging in when a public post accepts pings.

WordPress All-in-One WP Migration Plugin Flaw

The attacker submits malicious trackback data with a carefully prepared blog name and URL. WordPress stores that data in the comments table. At this stage, the payload remains inactive and appears to be ordinary comment-related data.

The attack becomes dangerous when a site administrator exports the website using the plugin and later restores it. During restoration, All-in-One WP Migration rewrites URLs and database table prefixes in SQL statements before importing them.

According to a Wordfence report, a flaw in the plugin’s regular expression handling of backslashes and quoted strings can cause the stored payload to escape its intended SQL string boundary.

As a result, attacker-controlled content can become executable SQL during the database restore process. The injected SQL can retrieve the plugin’s ai1wm_secret_key, a secret value used to protect the plugin’s unauthenticated import action.

Wordfence Firewall ( Source :wordfence)
Wordfence Firewall (Source: Wordfence)

The attacker can then leak this secret key into an approved comment and retrieve it through the site’s public WordPress REST API. With the secret key, the attacker may access the plugin’s import process and upload a malicious .wpress archive.

A crafted archive could include a malicious must-use WordPress plugin. Since must-use plugins load automatically, the malicious code can execute when a visitor or administrator opens a page.

This can grant the attacker remote code execution on the server and enable a full site compromise, including deploying a webshell, stealing data, or installing additional malware.

The exploit requires an administrator to perform an export followed by an import after the malicious trackbacks have been planted. Although this adds an interaction requirement, backup and restore operations are routine tasks for many WordPress administrators.

Wordfence deployed a firewall rule for Premium, Care, and Response users on August 16, 2026. Free Wordfence users are scheduled to receive the protection on September 15, 2026. ServMask acknowledged the report on August 17 and released version 7.110 on August 20.

Website owners using All-in-One WP Migration and Backup should update immediately, turn off unnecessary trackbacks, review suspicious comments, and verify that no unauthorized plugins or administrator accounts have been added.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks appeared first on Cyber Security News.

CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk

3 de Setembro de 2026, 06:27

CVE-2026-84115

A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint.   MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3. 

CVE-2026-84115 Targets JWT Refresh Token Handler 

According to the vulnerability analysis, CVE-2026-84115 involves an unknown function within the JWT Refresh Token Handler component. The affected functionality processes requests sent to /api/connections, where manipulation of the Bearer argument in HTTP authorization headers can lead to improper privilege management.  The weakness is classified as CWE-269, which refers to Improper Privilege Management. The flaw can allow an attacker to manipulate authentication-token arguments and potentially bypass intended access controls, gaining privileges beyond those assigned to the account. 

Remote Exploitation Raises CVE-2026-84115 Risk 

The vulnerability is remotely exploitable because the attack can be conducted through network-based HTTP requests without requiring local or physical access to the targeted system. The risk is heightened because a public exploit has reportedly been made available.  An attacker exploiting CVE-2026-84115 could potentially obtain unauthorized administrative access, view sensitive information stored within Harmony, or interfere with integration workflows managed through the platform. Such activity could affect the confidentiality, integrity, and availability of systems that depend on Cleo Harmony for file transfer and API connectivity.  The VulDB analysis links the exploitation method to authentication bypass through token manipulation. Attackers could potentially intercept legitimate traffic or create forged requests using malformed or replayed bearer tokens to circumvent JWT refresh-token controls. In environments where Cleo Harmony is connected to other systems, successful exploitation could also provide opportunities for further lateral movement. 

CVE-2026-84115 Remediation Requires an Upgrade 

Organizations using affected Cleo Harmony versions should upgrade to version 5.8.1.11 or later. The release contains the necessary correction for the privilege-management problem affecting the JWT Refresh Token Handler.  Until patching is possible, organizations can strengthen input validation on API endpoints and monitor for unusual patterns involving bearer tokens. These measures may improve detection and reduce exposure, but they do not replace the recommended software upgrade, particularly given the reported public exploit.  VulDB is listed as the responsible organization, with the vulnerability recorded under VDB-397558. Disclosure took place on September 1, 2026, and the entry has an accepted moderation status, with CPE marked as ready. CWE-269 is confirmed for the vulnerability. VulDB assigns CVE-2026-84115 a CVSS score of 8.3 and an EPSS score of 0.00284. The vulnerability record also identifies an exploit as available for download.

SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity

3 de Setembro de 2026, 04:47

Graphic showing SonicWall SMA1000 devices, CVE-2026-83548, the maximum-severity SonicWall SMA1000 pre-authentication vulnerability

SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix.

The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance's Appliance Work Place interface, rated 10.0 on the CVSS scale. It lets a remote attacker with no credentials reach sensitive internal functionality. The second, CVE-2026-83549, is an operating-system command injection bug in the Appliance Management Console rated 7.8; on its own it requires administrative authentication, but paired with the SSRF flaw it yields remote code execution.

The vendor said it found both issues internally and then observed them being used together in live attacks. SonicWall has not published indicators of compromise or described the attackers.

Affected products are the SMA1000 series 6210, 7210 and 8200v, in both hardware and virtual form. Fixed builds are 12.4.3-03526 and later, and 12.5.0-02952 and later. SonicWall firewalls running SSL-VPN and the separate SMA 100 line are not affected.

Remediation guidance goes beyond patching. SonicWall told customers to contact its support organization to review appliances for signs of intrusion and, where compromise is suspected, to re-image or redeploy the device, rotate all credentials and reset TOTP tokens — an acknowledgment that one-time-password seeds stored on a breached appliance survive a software update. The company said customers should move to the hotfix release as quickly as possible.

Shadowserver Foundation scanning has tracked more than 400 internet-exposed SMA1000 appliances, though an unknown share of those are already patched. The small install base belies the risk profile. These are remote-access gateways that sit at the network edge and hold credentials for the environments behind them.

The disclosure extends a difficult run for the product line. Attackers exploited a separate pair of SMA1000 zero-days in July 2026, tracked as CVE-2026-15409 and CVE-2026-15410, to deploy custom malware; CISA later confirmed ransomware operators were abusing that access.

Read: CISA Adds SonicWall SMA1000 Vulnerabilities to KEV Catalog Following Active Exploitation

Another zero-day surfaced in December 2025. Seventeen SonicWall vulnerabilities across the company's product families currently sit in CISA's Known Exploited Vulnerabilities catalog. Edge appliances from SonicWall, Ivanti, Citrix and Fortinet have collectively become the preferred initial-access route for ransomware affiliates and espionage crews, because they are internet-facing by design and rarely instrumented with endpoint detection.

  • ✇Cyber Security News
  • FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately Abinaya
    FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services. Because it processes network data from remote servers and supports features such as graphics, smart cards, USB redirection, clipboard sharing, and aut
     

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

2 de Setembro de 2026, 09:10

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly.

FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services.

Because it processes network data from remote servers and supports features such as graphics, smart cards, USB redirection, clipboard sharing, and authentication, memory-handling mistakes can create serious security exposure.

The 3.31.0 release includes fixes for 22 GitHub Security Advisories, covering issues reported through the project’s security process. The advisory identifiers include GHSA-c5gr-hmqp-pwj4, GHSA-h5w2-q35j-443h, GHSA-m85m-3qxv-63h5, and 19 others.

While the release notes do not provide public technical details for every flaw, the vendor’s “update ASAP” warning shows that maintainers consider the addressed issues significant.

FreeRDP Fixes 22 Security Flaws

Several changes in the release point to security-sensitive code paths. FreeRDP fixed bounds checking in the AVC444v2 YUV decoder, which processes remote desktop graphics data.

It also corrected parsing and length-validation problems in dynamic virtual channels, Remote Desktop Gateway tunnel responses, clipboard format lists, smart-card data, USB redirection, and device-redirection components.

The update further resolves use-after-free conditions involving the printer driver singleton and the reallocation of aligned memory. Use-after-free bugs occur when software continues to access memory after it has been released.

Depending on the affected code path and surrounding protections, such flaws can lead to application crashes, information disclosure, or possibly remote code execution. Authentication and cryptographic components also received attention.

The release improves NTLM and SSPI memory handling, adds checks before accessing signature buffers, fixes SPNEGO mechanism fallback behavior, and improves error handling when BIO or SSL object creation fails.

These changes are important because FreeRDP often handles authentication exchanges and encrypted connections to remote systems.

In addition to security fixes, version 3.31.0 brings performance improvements. The project said an optimized YUV decoder should deliver faster client-side graphics for AVC and H.264 remote desktop sessions. It also adds support for more hardware decoders and switches AV1 decoding to dav1d in supported configurations.

Administrators should identify systems that package or embed FreeRDP, including desktop clients, remote-access gateways, virtual desktop tools, and third-party products built on the library.

Organizations should install FreeRDP 3.31.0 through their supported distribution channel or build the updated release from the official source package. Teams should also verify the downloaded archive using the published SHA-256 checksum and signature where possible.

Prompt patching is especially important for systems that connect to untrusted or internet-exposed RDP servers. The official release includes source archives, ZIP packages, signatures, and checksums for version 3.31.0.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers Abinaya
    Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM versions before 1.83.0 and allows authenticated users to access the sensitive /config/update endpoint without the required administrator role. LiteLLM acts as an AI gateway between enterprise applications and model providers. It can store provider API keys, database connecti
     

Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

2 de Setembro de 2026, 08:44

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control.

The issue, tracked as CVE-2026-35029, affects LiteLLM versions before 1.83.0 and allows authenticated users to access the sensitive /config/update endpoint without the required administrator role.

LiteLLM acts as an AI gateway between enterprise applications and model providers. It can store provider API keys, database connection details, user data, spending records, and administrative credentials.

This makes exposed LiteLLM control planes a valuable target for attackers seeking cloud credentials, AI service keys, or a path into connected infrastructure. The vulnerability stems from the absence of an authorization check on the /config/update API route.

Hackers Exploit LiteLLM Admin API Flaw

In affected releases, an authenticated account with a limited role, such as the read-only proxy_admin_viewer role, could modify settings reserved for full administrators. LiteLLM corrected the issue in version 1.83.0 by requiring the proxy_admin role for configuration changes.

Researchers observed attackers abusing the flaw to modify environment variables and configuration values. One technique changes UI_LOGO_PATH, a setting that identifies the dashboard logo file.

By replacing the normal image path with a sensitive server-side file, such as /app/.env or /proc/self/environ, an attacker can cause LiteLLM to read it.

The content can then be retrieved through the /get_image endpoint, which reportedly does not require authentication in vulnerable deployments.

This technique can expose secrets stored in environment files and configuration files. Potentially exposed data includes model-provider API keys, the LiteLLM master key, database URLs, AWS credentials, and observability platform tokens.

The flaw can also be used to overwrite UI_USERNAME and UI_PASSWORD environment variables, enabling an attacker to replace dashboard credentials and take over the administration interface.

The security impact can extend beyond data theft. Advisories state that attackers can register malicious pass-through endpoint handlers through altered configuration.

Such handlers may point to attacker-controlled code or infrastructure, creating a route to remote code execution or secret exfiltration.

Zenity honeypot telemetry recorded roughly 3,900 requests against LiteLLM administrative API endpoints between February and June 2026, including about 1,000 requests targeting /config/update.

The first configuration-update probes appeared on April 7, one day after CVE-2026-35029 was publicly disclosed. Researchers later saw direct file-read payloads attempting to load common secret locations, including /app/.env, /home/litellm/.env, /app/config.yaml, and /app/proxy_server_config.yaml.

The activity also included attempts to guess master keys such as sk-1234 and sk-litellm-master-key, generate new API keys, create administrator accounts, enumerate users and keys, probe SCIM provisioning routes, and delete models.

These actions show that threat actors are not merely scanning for the CVE they are mapping and attempting to control exposed AI gateway environments.

Organizations using LiteLLM should immediately upgrade to version 1.83.0 or later. This release adds the missing authorization enforcement for /config/update.nvd.nist+1

Administrators should also remove LiteLLM control-plane services from public internet exposure, place the Admin UI and administrative endpoints behind an authenticated reverse proxy or internal network, and ensure a strong, unique master key is configured. Default or documentation-example values must never be used.

Security teams should review logs for suspicious requests to /config/update, /get_image, /key/generate, /user/new, /model/delete, and /scim/. Requests that set UI_LOGO_PATH to local file paths should be treated as likely attempts at exploitation.

Finally, organizations that operated an exposed LiteLLM version before 1.83.0 should rotate all potentially exposed secrets. This includes LiteLLM master keys, LLM provider API keys, database passwords, cloud credentials, and third-party monitoring tokens, as the vulnerability can expose these values via configuration manipulation and arbitrary file reads.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems Abinaya
    HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary commands, and fully compromise affected systems. The flaws affect HPE Networking Fabric Composer version 7.3.3 and earlier. Fabric Composer is used to manage and automate data-center network fabrics, making a successful compromise particularly serious because the platform can contro
     

Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems

2 de Setembro de 2026, 05:35

HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary commands, and fully compromise affected systems.

The flaws affect HPE Networking Fabric Composer version 7.3.3 and earlier. Fabric Composer is used to manage and automate data-center network fabrics, making a successful compromise particularly serious because the platform can control important network infrastructure.

The most severe vulnerabilities are tracked as CVE-2026-76657 and CVE-2026-76658. Both received a maximum CVSS score of 10.0.

HPE said the API authentication-bypass flaw, CVE-2026-76657, could allow a remote attacker to circumvent existing authentication controls and obtain administrative privileges without valid credentials. This access could lead to a complete takeover of the Fabric Composer host.

CVE-2026-76658 affects the product’s SSH daemon. An unauthenticated remote attacker could exploit the issue to gain administrative access and execute arbitrary commands as a privileged user on the underlying operating system.

HPE Fabric Composer Flaws

In practical terms, a successful exploit may give an attacker control of the appliance and the ability to alter its configuration, steal information, or use it as a foothold for further movement inside an organization’s network.

HPE also fixed CVE-2026-19766, an adjacent-network authentication bypass rated 9.6. The vulnerability could allow an unauthenticated attacker on a connected network segment to execute arbitrary code with privileged operating-system permissions.

Other serious findings include unauthenticated remote code execution bugs, stored cross-site scripting issues, command injection, arbitrary file write, SQL injection, privilege escalation, information disclosure, and denial-of-service flaws.

Several weaknesses are especially concerning because they can be chained. For example, an attacker may first use an information-disclosure bug to understand internal services, then exploit an authentication bypass or remote code execution flaw to take control of the server.

Lower-privileged Fabric Composer users may also be able to exploit API and web interface flaws to escalate to administrative access.

HPE said its internal security researchers discovered the vulnerabilities. At the time the advisory was released, the company said it was not aware of public exploit code or public discussion targeting the issues.

However, the broad range and high severity of the bugs make prompt patching important, particularly for systems whose management interfaces are reachable from untrusted networks.

Organizations using Fabric Composer should upgrade to version 7.4.0 or later in the 7.4 branch, or version 7.3.4 or later in the 7.3 branch.

HPE also recommends restricting command-line and web-based management interfaces to a dedicated Layer 2 segment or VLAN, enforcing Layer 3 firewall controls, and using logging and accounting controls to track access and user activity.

Older releases that have reached End of Maintenance should be treated as potentially exposed unless HPE has explicitly stated otherwise.

Administrators should identify all Fabric Composer installations, confirm their running versions, apply the vendor’s fixes, and review administrator accounts, SSH exposure, API access, and network management logs for suspicious activity.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems appeared first on Cyber Security News.

  • ✇Firewall Daily – The Cyber Express
  • AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields Ashish Khaitan
    CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqlite's get_path/2 functionality.  The Erlang Ecosystem Foundation's CNA issued the vulnerability entry on August 30, 2026. The issue affects AshSqlite, the SQLite data layer used by the Ash Framework. Although it involves database queries, CVE-2026-77846 is not SQL injection.   Instead, the AshS
     

AshSqlite Vulnerability (CVE-2026-77846) Exposes Hidden JSON Fields

31 de Agosto de 2026, 06:14

CVE-2026-77846

CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqlite's get_path/2 functionality.  The Erlang Ecosystem Foundation's CNA issued the vulnerability entry on August 30, 2026. The issue affects AshSqlite, the SQLite data layer used by the Ash Framework. Although it involves database queries, CVE-2026-77846 is not SQL injection.   Instead, the AshSqlite vulnerability results from unsafe construction of JSON paths and the way SQLite interprets special characters in those paths. 

How the CVE-2026-77846 AshSqlite Vulnerability Works 

In affected releases, AshSqlite generated JSON paths using $."-style path construction through the expression: 
path = "$." <> Enum.join(right, ".") 
The individual path segments were neither escaped nor quoted. Consequently, a key intended to represent the literal name private.secret could instead be interpreted as two JSON levels. Characters such as ., [, ], and $ could similarly alter JSONPath interpretation.  The GitHub advisory describes the flaw as “JSONPath injection in AshSqlite.SqlImplementation get_path”, stating that an attacker controlling a get_path/2 segment can traverse nested JSON and disclose private fields. The affected package is ash_sqlite, with versions 0.1.2-rc.0 through before 0.2.18 affected and 0.2.18 listed as the patched release.  The flaw remains separate from SQL injection because the generated JSON path is supplied to SQLite's json_extract as a bound expression parameter. The attacker manipulates the JSONPath grammar, rather than injecting SQL commands. 

What CVE-2026-77846 Can Expose? 

The AshSqlite vulnerability becomes relevant when an application permits untrusted input to reach get_path/2, such as through a public calculation, filter, or API that lets callers select JSON fields.  A normal endpoint might permit a caller to request a top-level title field. However, supplying private.secret can cause AshSqlite to generate $.private.secret, allowing traversal into a nested object that the API was never intended to expose. Malformed input, such as an unbalanced bracket or bare $, can also produce SQLite JSON path errors that reveal information about the underlying structure.  The published proof of concept used AshSqlite 0.2.17, Bandit, and Req. It created a JSON record containing {"title":"hello","private":{"secret":"s3cr3t-api-key-9f2c"}}. A benign key=title request returned hello, while key=private.secret returned s3cr3t-api-key-9f2c. Captured SQL showed json_extract(p0."data", ?) with the parameter $.private.secret, confirming the traversal. The PoC concluded that a single attacker-controlled path segment could leak a nested value through an endpoint designed to expose only top-level keys. 

Fixes and Administrator Actions for CVE-2026-77846 

The fix replaces the unsafe path joining with encoding that represents keys safely, escapes backslashes and quotes, and handles numeric array indexes separately. Administrators should upgrade to AshSqlite 0.2.18 or later and audit applications that accept network-controlled field-selection input.  Until upgrades are completed, applications should restrict dynamic get_path/2 calls to predefined names, reject dangerous path characters such as periods and brackets, and avoid exposing arbitrary JSON paths.  After upgrading, dependency locks and deployment images should be checked for older ash_sqlite versions. Logs should also be reviewed for unusual dots, brackets, or JSONPath symbols in field-selection requests. Such requests do not prove exploitation, but can help identify systems requiring investigation.  The practical risk of CVE-2026-77846 depends on application architecture. Internal applications without untrusted callers face lower exposure, while public search, filtering, and field-selection APIs require careful validation and access controls. 
  • ✇Cyber Security News
  • Critical ServiceNow Flaws Let Attackers Execute Code and Access Data Abinaya
    ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges. The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs. ServiceNow said each vulnerabilit
     

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data

28 de Agosto de 2026, 22:54

ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.

The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs.

ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates or upgrade to a patched release.

ServiceNow Fixes Critical Flaws

Three of the flaws affect the ServiceNow AI platform. CVE-2026-18885 is a critical code injection vulnerability that could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.

Successful exploitation could also let an attacker access or modify instance data beyond intended permissions. This creates a serious risk for organizations that use ServiceNow to manage IT operations, security workflows, employee requests, customer service records, and enterprise automation.

An attacker who gains unauthorized code execution may be able to abuse the platform’s access to connected business processes and sensitive operational information.

The second critical issue, tracked as CVE-2026-18886, is another code injection flaw in the ServiceNow AI platform. ServiceNow said an unauthenticated attacker could potentially create or alter instance data outside expected authorization limits. This could lead to privilege escalation, enabling an attacker to gain broader access than originally granted.

The third critical vulnerability, CVE-2026-74820, is a SQL injection flaw affecting the ServiceNow AI platform. If exploited, the issue could allow an unauthenticated attacker to execute arbitrary SQL statements against the affected instance’s underlying database.

This could expose sensitive data stored in ServiceNow environments or allow attackers to modify database-backed records. ServiceNow also addressed CVE-2026-6876, a high-severity sandbox escape vulnerability in the Now Platform.

The company said the issue could allow an unauthenticated user to execute arbitrary code on the platform and potentially gain access beyond what was intended.

Sandbox escape flaws are particularly concerning because they can allow attackers to break out of restricted execution environments designed to limit the impact of untrusted code.

Customers enrolled in the ServiceNow Patching Program have already received the appropriate updates. However, organizations should verify that their instances are running a fixed version.

Patched releases include Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and later supported fixes; Zurich Patch 7b Hot Fix 3 through Patch 12; and Australia Patch 2 Hot Fix 3 through Patch 5.

Organizations operating self-hosted ServiceNow deployments should treat the three critical AI platform vulnerabilities as a priority.

Security teams should confirm installed versions, apply relevant hotfixes, review privileged access, and monitor instance activity for suspicious data changes, unexpected code execution, or abnormal database queries.

The post Critical ServiceNow Flaws Let Attackers Execute Code and Access Data appeared first on Cyber Security News.

  • ✇Cyber Security News
  • Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth Abinaya
    A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals. The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages major hardware functions, including movement, cameras, speakers, voice features, and other peripherals. The r
     

Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth

28 de Agosto de 2026, 22:52

A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals.

The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages major hardware functions, including movement, cameras, speakers, voice features, and other peripherals.

The research, dubbed UniBLEed, describes a multi-stage exploit involving Bluetooth Low Energy, Unitree’s cloud API, Wi-Fi provisioning system, and services running on the robot’s Linux-based control environment.

Hackers Control Unitree G1 Robots

The attack was assigned CVE-2026-76639 and CVE-2026-76640 and was reportedly reproduced on four Unitree G1 robots. The most serious chain begins with a Bluetooth service that accepts writes without requiring Bluetooth pairing.

A nearby device can send a cleartext request to a GATT characteristic identified as 0xFFE2 and receive an encrypted bootstrap package from the robot.

That is the bug that turns Unitree’s legitimate decrypt-and-bind endpoint into a decryption oracle for any nearby robots (source : boschko )

That package includes data needed to recover the robot’s unique AES-128 encryption key. However, the key is initially protected using RSA encryption.

The weakness becomes critical because Unitree’s cloud endpoint, called devicebindExtData, reportedly decrypted this data for any authenticated Unitree account without verifying that the account owned the targeted robot.

An attacker could create or use a free Unitree account, collect the encrypted Bluetooth response and serial number from a nearby G1, submit them to the cloud API, and retrieve the device-specific AES key.

The issue was an authorization failure rather than an authentication failure: the API accepted valid user accounts but did not verify the account-to-robot ownership relationship.

Root RCE via BLE BSS Buffer Overflow in btgatt-server (source : boschko )
Root RCE via BLE BSS Buffer Overflow in btgatt-server (source : boschko )

Once attackers recovered the AES key, they could complete the G1’s Bluetooth application-level handshake and send Wi-Fi configuration commands. Researchers found that the robot’s Wi-Fi setup script could be manipulated through unsafe handling of Wi-Fi credentials.

By supplying a specially crafted, overlong password, an attacker could force the script into a manual configuration path and inject additional network blocks into the generated wpa_supplicant configuration. This could make the robot join an attacker-controlled Wi-Fi hotspot.

From that network position, the attack chain used another flaw in the G1 Bluetooth server. A Wi-Fi SSID handler copied incoming data into a 500-byte buffer without correctly checking the total amount of data received.

The attacker could send a 1,050-byte payload across one or more Bluetooth connections, corrupting adjacent memory in the server process.

The Boschko research states that the corruption could alter an event-loop cleanup structure and cause the process to invoke a command through system() as root.

A separate root code execution chain, CVE-2026-76639, affected the robot’s ChatGo AI service and BashRunner service.

Root RCE via AI Service chat_go Path Traversal into bashrunner Execution (source : boschko )
Root RCE via AI Service chat_go Path Traversal into bashrunner Execution (source : boschko )

Attackers with access to the internal robot network could exploit a path-traversal issue in ChatGPT’s knowledge-upload feature to write files to a directory trusted by BashRunner.

Restarting the service caused BashRunner to execute the attacker-created file as root. The impact is significant because the targeted locomotion computer runs Linux services with root privileges and controls functions critical to a physical robot.

The researchers warned that the Bluetooth chain was potentially wormable: a compromised G1 could theoretically help spread the same exploit to additional vulnerable robots within Bluetooth range.

Unitree reportedly implemented an ownership-binding check for the cloud decryption endpoint in July 2026, before the public disclosure. The researcher said Unitree had patches, including internal fixes, for most or all of the reported issues at the time of publication.

Robot owners should apply the latest vendor firmware and mobile application updates, avoid exposing robots to untrusted nearby Bluetooth devices, and isolate robot management networks from sensitive enterprise systems.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth appeared first on Cyber Security News.

❌
❌