← Back to Blog

Security News — 3 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 3 September 2026 · 27 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs03 Sep

CVE-2026-84888 — LOW (CVSS 2.1)

CVSS 2.1 LOW A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory alloca…

Read at source →
CVEDatabase - Recent CVEs03 Sep

CVE-2026-84887 — LOW (CVSS 2.1)

CVSS 2.1 LOW A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation l…

Read at source →
CVEDatabase - Recent CVEs03 Sep

CVE-2026-84886 — MEDIUM (CVSS 5.5)

CVSS 5.5 MEDIUM A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulatio…

Read at source →
CVEDatabase - Recent CVEs03 Sep

CVE-2026-84885 — LOW (CVSS 2.1)

CVSS 2.1 LOW A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched…

Read at source →
CVEDatabase - Critical CVEs02 Sep

CVE-2026-66786 — CRITICAL (CVSS 9.1)

CVSS 9.1 CRITICAL A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by…

Read at source →
CVEDatabase - Critical CVEs02 Sep

CVE-2026-47864 — MEDIUM (CVSS 6.4)

CVSS 6.4 MEDIUM · Vendor: vmware SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-objec…

Read at source →
CVEDatabase - Critical CVEs02 Sep

CVE-2026-47875 — MEDIUM (CVSS 5.6)

CVSS 5.6 MEDIUM · Vendor: broadcom Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The J…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

Security Executive, Architecture & Policy

Schneier on Security02 Sep

Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are…

Read at source →
← All blog posts