← Back to Blog
Security News
Security News — 9 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 4 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 9 September 2026 · 9 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs09 Sep
CVSS 4.3 MEDIUM The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions…
Read at source →
CVEDatabase - Recent CVEs09 Sep
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9 does not validate a user-supplied HTML tag name in one of its Beaver Builder widgets before echoing it into the render…
Read at source →
CVEDatabase - Recent CVEs09 Sep
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to th…
Read at source →
CVEDatabase - Recent CVEs09 Sep
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule th…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer09 Sep
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
Read at source →
The Hacker News09 Sep
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in W…
Read at source →
The Hacker News09 Sep
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch…
Read at source →
BleepingComputer09 Sep
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)09 Sep
Read at source →