← Back to Blog

Security News — 19 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 5 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 19 September 2026 · 12 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs19 Sep

CVE-2026-93985 — CRITICAL (CVSS 9.4)

CVSS 9.4 CRITICAL OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project wr…

Read at source →
CVEDatabase - Critical CVEs19 Sep

CVE-2026-93742 — HIGH (CVSS 8.6)

CVSS 8.6 HIGH A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack…

Read at source →
CVEDatabase - Critical CVEs19 Sep

CVE-2026-93741 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buf…

Read at source →

Independent Investigative Journalism & Breaking News

Security Executive, Architecture & Policy

Daniel Miessler19 Sep

My Early Thoughts on Jev

A charcoal sketch of a small purple sorting machine taking in a flood of envelopes, dropping most into bins, and sending two glowing envelopes up a narrow ramp to a large engine behind it/images/jev-decision-gate.webp/images/jev-decision-g…

Read at source →
← All blog posts