Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
CVE-2026-39987 in Marimo: human operator bypassed traps and reached SSH bastion in eight seconds
The critical vulnerability CVE-2026-39987 (CVSS 9.3) in Marimo interactive notebooks — pre-authentication remote code execution via the terminal WebSocket endpoint ...
CVE-2026-68820 — use-after-free in Windows AFD for WinSock with confirmed exploitation
The CVE-2026-68820 vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) component is being actively exploited by attackers. According ...
CVE-2026-81963: actively exploited privilege escalation vulnerability in Windows Update Stack
Microsoft reports active exploitation of the CVE-2026-81963 vulnerability in the Windows Update Stack component. The vulnerability allows a local authenticated ...
GitLab fixes CVE-2026-85706 file-reading vulnerability with maximum CVSS — scanning has already started
GitLab has released emergency security updates to fix several vulnerabilities, including CVE-2026-85706 with the maximum CVSS 10.0 rating — a ...
Fortinet discloses FortiSandbox vulnerability — unauthenticated access to sensitive data
Fortinet has published security advisory FG-IR-26-166 describing an Improper Access Control vulnerability (CWE-284) in the web interface of FortiSandbox, FortiSandbox ...
Critical vulnerability in FortiMonitorOnSight enables authentication bypass via static JWT key
Fortinet has published security advisory FG-IR-26-170 describing a critical vulnerability in the FortiMonitorOnSight web portal. The issue has been scored ...
Vulnerability in AOMEI Backupper driver allows writing data to the physical disk without privileges
The CERT Coordination Center (CERT/CC) has published advisory VU#687587 describing the CVE-2026-12780 vulnerability in the kernel driver amwrtdrv.sys, which is ...
Certificate validation vulnerability in FortiOS and FortiProxy allows interception of ZTNA portal traffic
Fortinet has published security advisory FG-IR-26-174 describing an improper certificate validation vulnerability (CWE-295) in the agentless ZTNA portal of FortiOS ...
CERT/CC warns of SSRF vulnerability in ONLYOFFICE integration plugin for ownCloud with no available patch
CERT/CC published advisory VU#943094 on September 8, 2026, about a server-side request forgery (SSRF) vulnerability in the ONLYOFFICE integration plugin ...