← Back to Blog

Security News — 14 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 9 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 14 September 2026 · 23 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs14 Sep

CVE-2026-12944 — CRITICAL (CVSS 9.6)

CVSS 9.6 CRITICAL · Vendor: IBM IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. Th…

Read at source →
CVEDatabase - Critical CVEs14 Sep

CVE-2026-76441 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: Cisco As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive interna…

Read at source →
CVEDatabase - Critical CVEs14 Sep

CVE-2026-20353 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: Cisco As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive interna…

Read at source →
CVEDatabase - Critical CVEs14 Sep

CVE-2026-90703 — HIGH (CVSS 8.5)

CVSS 8.5 HIGH A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The at…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

SANS Internet Storm Center (Handler Diary)14 Sep

Apple Updates Everything, (Mon, Sep 14th)

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the incr…

Read at source →

Security Executive, Architecture & Policy

Schneier on Security14 Sep

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET. I’m speaking at CanSecWest 2026 in Vancouver, Canada. The confere…

Read at source →
Schneier on Security14 Sep

Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running three weap…

Read at source →
Schneier on Security14 Sep

Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high crit…

Read at source →
← All blog posts