← Back to Blog

Security News — 4 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 4 September 2026 · 30 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs04 Sep

CVE-2026-86098 — HIGH (CVSS 8.3)

CVSS 8.3 HIGH ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted…

Read at source →
CVEDatabase - Recent CVEs04 Sep

CVE-2026-86097 — HIGH (CVSS 7.1)

CVSS 7.1 HIGH PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'para…

Read at source →
CVEDatabase - Recent CVEs04 Sep

CVE-2026-86096 — MEDIUM (CVSS 6.0)

CVSS 6.0 MEDIUM PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via sh…

Read at source →
CVEDatabase - Recent CVEs04 Sep

CVE-2026-86095 — HIGH (CVSS 8.5)

CVSS 8.5 HIGH Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files w…

Read at source →
CVEDatabase - Critical CVEs04 Sep

CVE-2026-47837 — MEDIUM (CVSS 6.8)

CVSS 6.8 MEDIUM · Vendor: vmware Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Sprin…

Read at source →
CVEDatabase - Critical CVEs04 Sep

CVE-2026-18658 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: IBM IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leve…

Read at source →
CVEDatabase - Critical CVEs04 Sep

CVE-2026-85696 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shel…

Read at source →
CVEDatabase - Critical CVEs04 Sep

CVE-2026-85695 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

Security Executive, Architecture & Policy

Daniel Miessler04 Sep

Socratic AI

A charcoal sketch of a student straining in a squat under a loaded barbell while a purple AI figure spots him with both hands held just off the bar/images/socratic-ai.webp/images/socratic-ai.webp I've been thinking about what AI should loo…

Read at source →
Daniel Miessler04 Sep

Cliff's Notes for Everything

A sienna sketch of a man squatting under a giant open book he is lifting overhead, while a purple robot arm on a desk hands a striped summary sheet to a faint gray figure/images/cliffs-notes-for-everything.webp/images/cliffs-notes-for-ever…

Read at source →
Schneier on Security04 Sep

Using a VM to Contain an AI Agent

It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which th…

Read at source →
Schneier on Security04 Sep

Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia…

Read at source →
Daniel Miessler04 Sep

Peak Human Readership

A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full page/images/peak-human-readers…

Read at source →
← All blog posts