Daily Threat Briefing
An automated daily threat intelligence briefing for SOC, incident response, and vulnerability management teams.
Generated every morning around 06:30 (Europe/Berlin) from 20 sources — CISA KEV, EUVD, BSI CERT-Bund, CERT-EU, vendor research blogs, and security news — and summarized by AI.
Subscribe via RSS to get each morning's briefing in your reader.
Briefings
Suricata · Argo Workflows · Mistral Vibe
New vulnerability data identifies critical flaws in Suricata, Argo Workflows, Mistral Vibe and Totolink networking equipment. The Suricata issues are particularly relevant to organisations operating…
Linux Kernel · Gravity Forms Plugin for WordPress · IBM Guardium Data Protection
CISA added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, with remediation due by 2026-09-21. Public exploit code is also reported for four Linux Kernel flaws,…
HGiga OAKlouds · Unbound DNS Resolver · Grav CMS
Multiple high-severity vulnerabilities were disclosed during the reporting window, including unauthenticated remote code execution in HGiga OAKlouds, remote code execution in Grav CMS, and a critical…
Cisco Identity Services Engine · Acronis Backup for cPanel & WHM and Plesk · Google Pixel Cellular Modem
CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on 2026-09-16: Cisco Identity Services Engine, Acronis Backup integrations for cPanel/Plesk, and Google Pixel…
Oracle WebLogic Server · Delinea Secret Server · Google Chrome
Oracle published a large set of critical Fusion Middleware and enterprise-application vulnerabilities, including multiple CVSS 10.0 issues affecting WebLogic Server, Access Manager, Forms, Internet…
Cisco Secure Email Gateway · Apache Storm Nimbus/Client · IBM DataStage on Cloud Pak for Data
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog after confirming active exploitation of an unauthenticated Cisco Secure Email Gateway SQL-injection flaw that can lead to…
Suprema BioStar 2 / BioStar X · HAProxy · Strapi
New EUVD records identify high-severity vulnerabilities in Suprema BioStar access-control software, HAProxy with HTTP/3 enabled, Strapi, and CyberPanel. The most operationally significant issue is…
GitLab Enterprise Edition · The Events Calendar WordPress Plugin · Tutor LMS WordPress Plugin
New vulnerability intelligence identifies a critical GitLab Enterprise Edition authorization flaw and multiple high-severity WordPress plugin vulnerabilities with elevated exploitation likelihood.…
ConnectWise ScreenConnect · JFrog Artifactory · GitLab Community Edition and Enterprise Edition
CISA added four actively exploited vulnerabilities to the KEV Catalog: ConnectWise ScreenConnect, two JFrog Artifactory flaws, and GitLab CE/EE path traversal. JFrog flaws are being chained to obtain…
MikroTik RouterOS · Forgejo · IBM ContextForge MCP Gateway
CISA added two MikroTik RouterOS vulnerabilities to the KEV Catalog following evidence of active exploitation; both affect the btest service or trusted policy handling and have a 2026-09-13…
Cisco Secure Firewall Management Center / Security Cloud Control · Citrix NetScaler ADC / Gateway · Fortinet FortiOS
CISA added four vulnerabilities to the KEV Catalog, including actively exploited Cisco Secure Firewall Management Center, Citrix NetScaler, Fortinet and Chromium flaws. Cisco exploitation is…
Adobe Commerce / Magento Open Source · N-able N-central · Microsoft Windows Update Stack
CISA added four vulnerabilities to the KEV Catalog, including the actively exploited Magento/Adobe Commerce flaw CVE-2026-75650, N-able N-central pre-authentication RCE CVE-2026-86218, and two…
SAP NetWeaver Message Server · SAP Extended Passport Processing · Adobe Commerce / Magento Open Source
Active exploitation continues against MikroTik RouterOS and Magento/Adobe Commerce, while reporting now indicates N-able N-central may also be exploited in the wild, although vendor statements are…
NEC UNIVERGE IX-R/IX-V · N-able N-central · OpenMAIC
New high-impact exposure affects NEC UNIVERGE IX-R/IX-V routers, with an authentication bypass reportedly enabling unauthenticated CLI command execution. N-able also disclosed a separate…
Hummingbird WordPress Plugin · MikroTik RouterOS · AutoAgent
A Magento/Adobe Commerce zero-day is reportedly being exploited in the wild to backdoor online stores without authentication; organizations operating affected e-commerce platforms should treat this…
Google Chromium V8 · PowerJob Worker · SonicWall Network Security Manager
Google Chrome’s V8 vulnerability CVE-2026-85046 has been added to the CISA KEV catalog following confirmed exploitation and should be treated as the highest-priority endpoint action. New critical…
Microsoft Entra ID / Azure Active Directory B2C · Azure AI Language Authoring · Microsoft Entra ID
New intelligence highlights critical privilege-escalation and authentication-bypass vulnerabilities in Microsoft Entra and Azure services, alongside multiple high-impact flaws in developer tooling.…
SonicWall SMA1000 Appliances · Kestra OSS · JFrog Artifactory
SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited and can be chained to achieve unauthenticated remote code execution. CISA added seven vulnerabilities…
HPE Networking Fabric Composer · Team Password Manager · Elastic Elasticsearch
New EUVD records identify critical authentication and remote-code-execution risks in HPE Networking Fabric Composer, including unauthenticated administrative access, and a critical unauthenticated…
PaperCut NG/MF · MCPHub · ProfilePress
CISA added two PaperCut NG/MF vulnerabilities to the KEV Catalog, confirming active exploitation and a chained attack path that can enable unauthenticated configuration changes followed by arbitrary…
ash-project AshAi · Dell PowerStore
Two newly published critical vulnerabilities require prioritisation: CVE-2026-77956 enables unauthenticated remote Elixir code execution in AshAi, while CVE-2026-58574 permits unauthenticated access…
argocd-mcp · BookStack · pac4j / pac4j-oidc
New disclosures include a critical unauthenticated exposure in argocd-mcp, authentication and authorization weaknesses in enterprise-relevant application frameworks, and a remote-code-execution flaw…
Ubiquiti UniFi Talk Application · Ubiquiti UniFi Protect and Access Applications · JFrog Artifactory
The highest-priority new risks are critical Ubiquiti UniFi command-injection vulnerabilities with high EPSS scores, including CVE-2026-77554 at 0.99, and a JFrog Artifactory authentication weakness…
ownCloud · Linux Kernel · JFrog Artifactory
CISA added three actively exploited vulnerabilities to its KEV Catalog: ownCloud authentication bypass, Linux Kernel privilege escalation, and JFrog Artifactory path traversal. All have near-term…
Citrix NetScaler ADC and NetScaler Gateway · Microsoft SQL Server · Linux Kernel
Six new CISA KEV entries dominate today's report, including actively exploited vulnerabilities in Microsoft SQL Server (CVE-2019-1068), the Linux Kernel (CVE-2022-0995), and Citrix NetScaler…
Gitea · Mass Use-After-Free Update · NVIDIA OpenShell for Linux
The dominant new development today is CVE-2026-60004, a Gitea code injection vulnerability added to the CISA KEV catalog with a three-day remediation deadline of 2026-08-28. Google Chrome 152 has…
Oracle HTTP Server / WebLogic Server Proxy Plug-in · Keycloak · Microsoft SharePoint
The most critical new development today is CVE-2026-21962 — an Oracle HTTP Server / WebLogic Server Proxy Plug-in improper access control flaw added to the CISA KEV catalog with a three-day…
StackGres Kubernetes Operator · exceljs · justhtml
Today's most notable new items are a privilege escalation flaw in StackGres (CVSS 9.9) allowing database tenants to gain cluster admin rights, a cluster of vulnerabilities in the exceljs library…
Fabrik Extension for Joomla · Mailgun for WordPress · NLTK
Today's new vulnerability data is dominated by a large cluster of critical flaws in the Fabrik extension for Joomla (multiple CVSS 10.0 unauthenticated RCE and path traversal CVEs) and a separate…
GitLab · Microsoft Azure SQL Database · Incus
A new npm supply chain attack distributes the AI-powered RedC2 4.0 Linux backdoor via 14 trojanized packages. CVE-2026-19478 (GitLab code injection, CVSS 9.4) is under active exploitation within days…