← Back to Blog

Security News — 11 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 3 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 11 September 2026 · 6 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs11 Sep

CVE-2026-89145 — LOW (CVSS 2.4)

CVSS 2.4 LOW Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can crea…

Read at source →
CVEDatabase - Recent CVEs11 Sep

CVE-2026-89092 — MEDIUM (CVSS 4.2)

CVSS 4.2 MEDIUM The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitati…

Read at source →
CVEDatabase - Recent CVEs11 Sep

CVE-2026-88914 — MEDIUM (CVSS 4.4)

CVSS 4.4 MEDIUM A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a boun…

Read at source →
CVEDatabase - Recent CVEs11 Sep

CVE-2026-78134 — HIGH (CVSS 7.1)

CVSS 7.1 HIGH strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Read at source →

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

← All blog posts