← Back to Blog

Security News — 22 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 12 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 22 September 2026 · 33 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Recent CVEs22 Sep

CVE-2026-96269 — HIGH (CVSS 7.5)

CVSS 7.5 HIGH GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no parti…

Read at source →
CVEDatabase - Recent CVEs22 Sep

CVE-2026-96260 — MEDIUM (CVSS 6.5)

CVSS 6.5 MEDIUM Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust…

Read at source →
CVEDatabase - Recent CVEs22 Sep

CVE-2026-96259 — MEDIUM (CVSS 5.5)

CVSS 5.5 MEDIUM Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server i…

Read at source →
CVEDatabase - Recent CVEs22 Sep

CVE-2026-95815 — HIGH (CVSS 7.2)

CVSS 7.2 HIGH OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them…

Read at source →
CVEDatabase - Critical CVEs22 Sep

CVE-2026-47116 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can…

Read at source →
CVEDatabase - Critical CVEs22 Sep

CVE-2026-28324 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure co…

Read at source →
CVEDatabase - Critical CVEs22 Sep

CVE-2026-82000 — CRITICAL (CVSS 9.6)

CVSS 9.6 CRITICAL · Vendor: Adobe Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to…

Read at source →
CVEDatabase - Critical CVEs22 Sep

CVE-2026-81995 — CRITICAL (CVSS 9.1)

CVSS 9.1 CRITICAL · Vendor: Adobe Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileg…

Read at source →
CISA Cybersecurity Advisories22 Sep

Siemens Industrial Edge Management

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verifi…

Read at source →
CISA Cybersecurity Advisories22 Sep

OpenPLC Runtime v3

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller…

Read at source →
CISA Cybersecurity Advisories22 Sep

lwIP (Lightweight IP)

View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affec…

Read at source →
CISA Cybersecurity Advisories22 Sep

Siemens WTV676 and WTV776

View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access)…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

SANS Internet Storm Center (Handler Diary)22 Sep

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if…

Read at source →

Security Executive, Architecture & Policy

Schneier on Security22 Sep

GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing: However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published…

Read at source →
← All blog posts