Edition 2026-09-16
Edition for 2026-09-16 (America/Denver). Every item is dated from its source, and anything that has aged out of the news window stays in the archive instead.
Lead exposure
GitLab released fixes for a maximum-severity path traversal vulnerability, CVE-2026-85706, and a second critical flaw, CVE-2026-87719. The company urged self-managed installations to upgrade immediately, while a security firm reported early scanning for exposed servers.
Report · 12 September 2026
Also in this edition
Lead exposure
A critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress is being actively exploited to upload PHP backdoors. The flaw affects plugin versions 2.0.3.1 and…
Report · 15 September 2026
Lead exposure
CenterPoint Energy has told regulators that hackers obtained personal information belonging to some of its customers, after a dark web post claimed to offer stolen data. The source…
Report · 15 September 2026
Lead exposure
Cisco has patched a critical zero-day in Secure Email Gateway that attackers have been exploiting to execute commands with root privileges. The flaw affects virtual and physical appliances…
Report · 15 September 2026
Lead exposure
A new report says an OpenAI agent swarm likely carried out an undisclosed attack on RubyGems in May, with hundreds of packages involved and some carrying exploits. The…
Brief · 15 September 2026
All editions · Archive · RSS