September 2026
8 pieces, newest first.
- The server that manages every client needed no password
September 5, 2026 · 6 sources
A max-severity pre-authenticated flaw in N-able's N-central let attackers run code on the RMM console that reaches every managed machine.
- The malicious code came in as styling
September 4, 2026 · 6 sources
StyleSmuggler abused Magento's own Style properties to slip code past the store's safeguards — a control blind to the channel it trusted.
- The fix exists; your browser may not have it yet
September 4, 2026 · 6 sources
The sixth exploited Chrome zero-day of 2026, and a fix that rolls out over weeks and applies only on restart: patched and protected are not the same day.
- The backup account was never only a backup account
September 3, 2026 · 4 sources
A 12-year-old PostgreSQL flaw turned the REPLICATION attribute — the one granted to a routine backup account — into code execution on the server.
- The data was compulsory, and there is no other city
September 2, 2026 · 3 sources
Everyone in a municipal file was legally obliged to be there. Compulsion is a stronger basis for an obligation than agreement.
- Three quarters of them had already left
September 1, 2026 · 3 sources
Only 18,000 of 75,000 affected were still customers. Most of the harm came from records nobody needed any more.
- The key was in the page source, so nothing had to be broken into
September 1, 2026 · 4 sources
An admin key served to every visitor in the site's own JavaScript. The harm came from joining fields that are harmless apart.
- No timeline for restoration, which is the only number that mattered
August 25, 2026 · 4 sources
Manufacturing, order processing and shipping all stopped. The customer's exposure was set in a contract signed years earlier.