← Back to Blog

Security News — 5 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 5 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 5 September 2026 · 15 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs05 Sep

CVE-2026-86150 — LOW (CVSS 2.0)

CVSS 2.0 LOW A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The at…

Read at source →
CVEDatabase - Critical CVEs05 Sep

CVE-2026-86149 — CRITICAL (CVSS 9.4)

CVSS 9.4 CRITICAL A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The…

Read at source →
CVEDatabase - Critical CVEs05 Sep

CVE-2026-86148 — CRITICAL (CVSS 9.4)

CVSS 9.4 CRITICAL A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in o…

Read at source →
CVEDatabase - Recent CVEs05 Sep

CVE-2026-86060 — CRITICAL (CVSS 9.2)

CVSS 9.2 CRITICAL RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. E…

Read at source →
CVEDatabase - Critical CVEs05 Sep

CVE-2026-86190 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers…

Read at source →
CVEDatabase - Critical CVEs05 Sep

CVE-2026-86189 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath paramet…

Read at source →

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

← All blog posts