← Back to Blog

Security News — 18 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 18 September 2026 · 27 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs18 Sep

CVE-2026-93740 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is p…

Read at source →
CVEDatabase - Critical CVEs18 Sep

CVE-2026-93739 — HIGH (CVSS 8.6)

CVSS 8.6 HIGH A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attac…

Read at source →
CVEDatabase - Critical CVEs18 Sep

CVE-2026-75885 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Reques…

Read at source →
CVEDatabase - Recent CVEs18 Sep

CVE-2026-93894 — LOW (CVSS 2.3)

CVSS 2.3 LOW In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segf…

Read at source →
CVEDatabase - Critical CVEs18 Sep

CVE-2026-93738 — HIGH (CVSS 8.6)

CVSS 8.6 HIGH A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attac…

Read at source →
CVEDatabase - Recent CVEs18 Sep

CVE-2026-93574 — MEDIUM (CVSS 6.5)

CVSS 6.5 MEDIUM A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsi…

Read at source →
CVEDatabase - Recent CVEs18 Sep

CVE-2026-93562 — MEDIUM (CVSS 6.5)

CVSS 6.5 MEDIUM A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker ca…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

Security Executive, Architecture & Policy

Schneier on Security18 Sep

Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual h…

Read at source →
← All blog posts