Four Apache Impala vulnerabilities expose systems to remote code execution and authentication bypass. Upgrade to Impala 4.5.2 to secure your clusters now.
A critical MapLibre XSS vulnerability allows zero-click code execution in 2.7M weekly downloads. Discover how CVE-2026-85061 works and how to patch now.
A critical CVE-2026-67401 cPanel SQL injection flaw in EmailTrack allows authenticated users to gain full control of the server. Patch your system today.
Microsoft has released security updates for CVE-2026-69485, an Important-rated remote code execution vulnerability affecting the Windows Remote Desktop Client.
The flaw could allow an authenticated attacker with low privileges to execute code on an affected server by sending a specially crafted network request.
The vulnerability was disclosed on September 8, 2026, and is tracked as CVE-2026-69485. Microsoft assigned it a CVSS 3.1 base score of 8.8, while the temporal score is 7.7.
The issue has a network attack vector, low attack complexity, requires low privileges, and does not need user interaction. Microsoft said the flaw stems from the Remote Desktop Client using an uninitialized resource.
Uninitialized resources can cause software to use memory, handles, or other system objects before they are properly prepared. In this case, an attacker may trigger the faulty condition through a crafted network request and gain the ability to run code.
Windows Remote Desktop Client Vulnerability
Remote code execution flaws are highly significant because they can give attackers control over vulnerable systems. Successful exploitation could affect the targeted device’s confidentiality, integrity, and availability.
Depending on the permissions available to the compromised account, an attacker could access sensitive data, modify files or system settings, install additional tools, or disrupt services.
According to Microsoft’s advisory, exploitation requires an attacker to first authenticate with low-level access to an affected server. The attacker could then send a specially crafted request to execute code on that server.
The attack does not require a user to click a link, open a file, or approve a prompt, reducing opportunities for defenders to stop it through user awareness controls alone.
Microsoft’s initial assessment states that the vulnerability was not publicly disclosed before the security update and has not been detected in active exploitation.
The company rates exploitation as “Exploitation Less Likely” at the time of publication. However, organizations should treat the finding as a priority because public patch releases can help threat actors study the vulnerability and develop working exploit techniques.
The affected products include Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including Server Core installations.
Microsoft also listed several Windows client editions, including Windows 10 versions 1607, 1809, 21H2, and 22H2, along with Windows 11 versions 23H2, 24H2, 25H2, and 26H1 for supported x64 and ARM64 systems.
Administrators should deploy Microsoft’s September security updates as soon as possible.
KB Update
Windows Version
KB5123099
Windows Server 2016 / Windows 10 1607
KB5122876
Windows Server 2019 / Windows 10 1809
KB5122882
Windows Server 2022
KB5122878
Windows 10 21H2 / 22H2
KB5122880
Windows 11 23H2
KB5124008
Windows 11 24H2 / 25H2
KB5124012
Windows 11 26H1
KB5122871
Windows Server 2025
Security teams should also review Remote Desktop exposure, restrict RDP access to trusted networks, enforce least-privilege access, and monitor authentication and Remote Desktop logs for unusual activity. Microsoft credited security researchers yhw and txz for reporting the vulnerability through coordinated disclosure.
cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers.
cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a valid cPanel account with mail-related privileges to exploit the vulnerability.
While this requirement limits unauthenticated internet-wide exploitation, the potential impact remains severe for shared-hosting providers, managed servers, and organizations with multiple cPanel users.
CVE-2026-67401 is an SQL injection vulnerability in cPanel’s EmailTrack functionality. EmailTrack monitors and reviews email delivery activity, including message routing and delivery information.
A malicious authenticated user can abuse the vulnerable functionality to create arbitrary files on the underlying server. Arbitrary file creation is especially dangerous in a hosting environment because it can let attackers place controlled content in sensitive locations.
Cpanel Vulnerability
cPanel said successful exploitation can result in code execution as the root user. Root access provides unrestricted control over the operating system, allowing attackers to access hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.
An attacker with root-level access could also install persistence mechanisms, deploy malware, alter website content, steal customer data, turn off security tools, or use the compromised server to launch further attacks.
In multi-tenant hosting environments, compromising one privileged cPanel account could put other customers hosted on the same server at risk.
Security researcher Ali Mustafa, also known as (nd abe)1526, reported the vulnerability. The vulnerability affects all supported cPanel/WHM versions before the following patched builds:
cPanel/WHM Release
Patched Version
cPanel & WHM 11.110
11.110.0.143
cPanel & WHM 11.134
11.134.0.55
cPanel & WHM 11.136
11.136.0.39
cPanel & WHM 11.138
11.138.0.4
WP2 release
11.138.1.9
Server administrators should verify their installed cPanel/WHM version immediately and upgrade to a patched release. Organizations using managed hosting should also confirm with their provider that the update has been applied across all affected systems.
The primary mitigation is toupdate cPanel/WHM to the latest available patched version. Administrators should not rely only on restricting public access, because exploitation requires a legitimate authenticated account rather than anonymous access.
Security teams should review cPanel accounts with email-related permissions and remove unnecessary privileges. Enable passwords and multi-factor authentication for accounts that may have been exposed or are no longer required.
Administrators should also investigate for suspicious files, unexpected changes to web directories, modified configuration files, unusual root-level processes, and unexplained outbound network connections. Reviewing cPanel, web-server, authentication, and system logs may help identify exploitation attempts.
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in GitHub advisory GHSA-jrc7-96c5-q579. This vulnerability affects maplibre-gl versions 6.4.0 and earlier and is resolved in version 6.4.1. Critical MapLibre GL JS Flaw The issue lies in the DOM.sanitize() function in src/util/dom.ts, which […]
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses […]
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persistent post-exploitation of FortiOS appliances. Researchers at SOCRadar’s Threat Research Unit (STRU) reported that this campaign has targeted over 30,000 internet-exposed FortiGate IP addresses and has successfully compromised at least 178 devices since […]
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]
JetBrains fixed 29 JetBrains vulnerabilities in Hub and YouTrack. Learn how these critical 9.8 CVSS bugs impact developer servers and how to patch now.
Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers.
Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]
ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authentication. This vulnerability allows an unauthenticated nearby attacker to potentially take control of an affected host through a direct connection to the agent. The issue affects versions before 1.7.24 and was published and updated […]