← Back to Blog

Security News — 23 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 9 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 23 September 2026 · 22 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs23 Sep

CVE-2026-93352 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address…

Read at source →
CVEDatabase - Critical CVEs23 Sep

CVE-2026-6928 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause…

Read at source →
CVEDatabase - Critical CVEs23 Sep

CVE-2026-6730 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

Read at source →
CVEDatabase - Critical CVEs23 Sep

CVE-2026-6721 — CRITICAL (CVSS 9.8)

CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

Red Team, Bug Bounty & Exploit Research

Security Executive, Architecture & Policy

Schneier on Security23 Sep

Research on Models Engaging in Genie-Like Behavior

New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language mo…

Read at source →
← All blog posts