
“Fragnesia”: Next Privilege Escalation Vulnerability in Linux Kernel
Microsoft warns of “Fragnesia,” a new Linux kernel vulnerability (CVE-2026-46300, CVSS 9.9) that represents a variant of the Dirty Frag flaw; it affects the XFRM-ESP subsystem in IPsec and allows attackers to gain root privileges, discovered by William Bowling using an AI-powered tool, with exploit code and patches alr
Apple Investigates macOS Issue Discovered by Claude Mythos
As part of the European Commission-funded Glasswing project, Anthropic is collaborating with Apple to identify security vulnerabilities in macOS, with the Claude Mythos AI model deployed by security firm Calif to exploit two bugs and memory errors to gain elevated access rights; details have not yet been published.
F5 BIG-IP: Quarterly Security Update Closes Multiple Vulnerabilities
F5 has published its quarterly security update closing vulnerabilities in BIG-IP, BIG-IQ Centralized Management, NGINX Plus and NGINX Open Source, with a particularly critical flaw in NGINX allowing unauthenticated code execution via crafted HTTP requests that could enable DoS, privilege escalation and access to protec
Ivanti EPM: Security Vulnerabilities Enable SQL Injection and Privilege Escalation
Ivanti warns of three security vulnerabilities in Endpoint Manager (EPM): an SQL injection flaw in the web console allows authenticated attackers to inject malicious code, improper privilege assignment enables local privilege escalation, and a core server error threatens credentials; all three vulnerabilities reported
Update Closes 79 Security Vulnerabilities in Google Chrome
Google’s weekly Chrome update patches a total of 79 security vulnerabilities, including 14 critical ones; eight of the critical flaws are use-after-free bugs, while others involve integer overflows, buffer overflows, and a race condition in the Payments component, and Google confirms that none have been actively exploi
Patch Now! Attackers Targeting Cisco Catalyst SD-WAN Controller
Attackers are actively exploiting a critical vulnerability (CVE-2026-20182) in the Cisco Catalyst SD-WAN Controller rated with a CVSS score of 10 out of 10, which allows remote attackers to bypass authentication and gain unauthorized access through a flaw in the peering authentication mechanism.
CISA Adds Critical Cisco SD-WAN Vulnerability to KEV Catalog
CISA has added a critical authentication vulnerability (CVE-2026-93) in Cisco SD-WAN Controller to its KEV catalog; federal agencies must patch by May 2026, and threat group UAT-8616 is already actively exploiting it while at least ten threat groups are exploiting related vulnerabilities and installing web shells on sy











