NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
CISA has added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog and prioritizes this security issue under BOD-26-04 guidance, setting a remediation deadline of 2026-09-12.
Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.
Unsafe .NET type instantiation in Business Connectivity Services enables remote code execution with SharePoint service account privileges; developed as a Pwn2Own entry and affects all supported SharePoint versions.
Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.
A CVSS-10.0 vulnerability in SAP Extended Passport Processing enables complete remote code execution without authentication and requires immediate patch implementation for all SAP instances.
A patch for CVE-2026-69414 (ShieldBreak) has not fully remediated the issue; the researcher demonstrated with ShieldCrash that the vulnerability can still be triggered under specific conditions and arbitrary files can be read with SYSTEM privileges.
Multiple state-sponsored APT groups, including China-aligned APT31, are deploying a newly discovered exploit kit (BlueMoon) that chains multiple Windows and Chrome vulnerabilities to compromise targets in Western countries.
Coordinated exploitation of a chain of zero-day vulnerabilities by Chinese espionage groups signals elevated threat to Western infrastructure and supply chains, with ongoing and expanding activity.
The Rhysida attack on Berlin reveals systematic security gaps in the defensive architecture of critical German infrastructure that serves as a warning signal for other DACH organizations.
CAV3RN exploits Google Apps Script and DNS-based channels for C2 communication, demonstrating how modern APT groups abuse legitimate cloud services to obfuscate threat activity.
AI-driven automation lowers the entry barrier for resource-constrained attackers to achieve nation-state-equivalent capabilities in vulnerability discovery and malware development, fundamentally escalating threat posture across all sectors.
Critical
NEW Multiple China-linked APT groups (specific names not provided in source) C3
Multiple China-linked state-sponsored hacking groups actively exploiting the same Chrome zero-day suggests coordinated or centrally-directed cyber-espionage against Western infrastructure.
Two of the 974 CVEs are already being actively exploited and have highest priority, while the remaining 114 critical vulnerabilities are distributed through bundled update packages per product.
This is a patch roundup aggregating 974 independent CVEs without describing a specific active attack campaign; however, the two actively exploited zero-days require immediate patching to limit exposure.
A zero-day in Microsoft Defender enables local privilege escalation to SYSTEM rights and represents a serious threat to organizations relying on Defender as a protection layer.
Both zero-days are local privilege-escalation vulnerabilities that can escalate existing low-privilege code execution to SYSTEM rights , typically relevant as a second stage in exploit chains or post-compromise scenarios.
The critical vulnerabilities allow unauthenticated attackers to bypass authentication using forged JWTs and proxy user browser traffic if users visit malicious websites,a direct risk to privileged access management.
The vulnerability enables unauthenticated remote attackers to achieve kernel-level code execution via specially crafted HTTP/1.x requests over TLS connections.
An out-of-bounds write vulnerability in VMware ESXi VMXNET3 driver enables local attackers to escalate privileges on guest virtual machines; demonstrated at Pwn2Own 2026.
Critical authentication bypass vulnerability (CVSS 10.0) is actively exploited by ransomware operators (UAT-11988) who gain initial access via static credentials and abuse legitimate tooling for reconnaissance and lateral movement.
RCE vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code; exploit details reveal XML-based Business Data Catalog manipulation as the attack vector.
A sandbox bypass in Chrome WebGL enables attackers to execute code outside the browser sandbox, increasing the risk of full system compromise via crafted web pages.
The vulnerability enables arbitrary code execution outside the sandbox by an adjacent attacker using crafted network traffic , a significant risk for Chrome-based systems.
Adobe Commerce vulnerability is already under active exploitation; Experience Manager contributes significantly to patch burden with 107 vulnerabilities patched.
The BSI warning indicates multiple critical vulnerabilities in the Azure/Entra identity platform affecting authentication, authorization, and code execution,a core infrastructure for Microsoft 365 environments.
BSI alert on critical SAP vulnerabilities across multiple products; specific CVE numbers and affected versions are required for prioritized patch planning.
A local privilege escalation flaw in Windows WMI Providers requires prior code execution access and threatens environments with locally accessible systems.
Critical security vulnerability in widely-used PDF reader enabling remote code execution upon user interaction; risk to technical documentation handling in manufacturing environments.
This is a BSI advisory on multiple GNU libc vulnerabilities without specific CVE identification; the 'UPDATE' designation suggests a follow-up notification and requires verification of specifically affected versions in the production environment.
BSI warning on multiple critical GNU libc vulnerabilities without specific CVE disclosure suggests coordinated release or ongoing patch cycle , urgency depends on patch status.
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
BSI warning of multiple critical vulnerabilities in VMware virtualization products with direct impact on hypervisor and vCenter infrastructure used by European organizations.
BSI warns of multiple vulnerabilities in Firefox/Thunderbird enabling code execution and sandbox escape; exploitation possible through opening malicious files or websites.
A V8 flaw (CVE-2026-85046) is already being actively exploited in the wild, enabling arbitrary code execution within the Chrome sandbox via crafted HTML pages.
The vulnerability enables code execution within Chrome's sandbox via crafted HTML content , the risk lies in browser-based attack vectors requiring only visit to a malicious webpage, with sandbox mitigation as the primary containment layer.
A use-after-free vulnerability in the Aura component allows a remote attacker to execute code outside the browser sandbox, bypassing Chrome's isolation mechanisms.
Use-after-free vulnerability in Chrome's platform code enables remote code execution within the sandbox; patching to version 153.0.8010.36 or later is required.
The vulnerability requires renderer process compromise combined with social engineering, which significantly limits practical exploitation in enterprise environments, but enables full code execution outside the browser sandbox if successfully exploited.
The vulnerability allows an attacker with control over the renderer process to execute code outside the Chrome sandbox, enabling full system compromise.
The vulnerability enables sandbox escape and arbitrary code execution via a crafted HTML page, but requires active user interaction and is not documented as actively exploited.
The vulnerability allows an attacker who has already compromised the renderer process to bypass the same-origin policy and breach web security boundaries.
A sandbox-escape vulnerability in Chromium ANGLE allows attackers to execute arbitrary code outside the browser sandbox, posing critical risk to end users.
A security vulnerability in Chrome's WebUI allows an attacker who has already compromised the renderer process to bypass the sandbox and execute arbitrary code , but this requires a previously compromised renderer as a prerequisite.
The vulnerability enables sandbox escape, potentially granting attackers access to the underlying operating system rather than being confined to isolated browser processes.
The vulnerability enables sandbox escape and local code execution without remote access; a local attacker (e.g. via compromised software or physical access) can thereby control the system outside the Chrome sandbox.
The vulnerability allows an attacker with access to the renderer process to execute code outside the sandbox , a classic sandbox escape that compromises Chrome's security architecture.
The vulnerability allows local attackers with existing access to the Windows system to execute arbitrary code outside the browser sandbox through an improper search path in the CredentialProvider component.
This vulnerability requires a prior successful renderer process compromise as a prerequisite and is thus more of a follow-up step in a multi-stage attack than a direct initial compromise vector.
Use-after-free in V8 enables sandbox bypass with arbitrary code execution,not merely local privilege escalation, but complete browser compromise through remote attack via crafted HTML.
The vulnerability enables sandbox escape and potentially system access on endpoints running Chrome , relevant for phishing campaigns using crafted HTML pages.
The vulnerability enables sandbox escape via incorrect filesystem reference resolution and requires active social engineering; however, there is no evidence of active exploitation in the wild.
A vulnerability in Chrome's LocalNetworkAccess mechanism allows an attacker with renderer process access to bypass system resource access restrictions via a crafted HTML page.
A type confusion bug in the V8 engine enables memory reading within the Chrome sandbox without full sandbox escape; this represents an active attack vector against browser users.
The vulnerability allows attackers with network access to bypass Chrome's sandbox and execute arbitrary code on affected systems , a significant risk for all browser users.
The vulnerability allows an attacker with control over the renderer process to execute code outside Chrome's sandbox, bypassing browser-based exploit mitigations.
A double-free vulnerability in Chromium's PDF engine enables remote code execution within the browser sandbox via crafted PDF files,a direct attack vector exploitable through social engineering.
A use-after-free vulnerability in the V8 JavaScript engine enables attackers to achieve remote code execution within the Chrome sandbox via crafted HTML pages.
An out-of-bounds read vulnerability in the ANGLE graphics engine enables memory access outside the browser sandbox and could expose memory contents; the vulnerability is rated High severity and requires timely update to Chrome 153.0.8010.36 or later.
The vulnerability allows an attacker with renderer process access to execute code outside the Chrome sandbox , a sandbox escape that could lead to arbitrary system-level code execution if successfully exploited.
Active exploitation in the wild or campaign context is not described in the alert; this is a standard vulnerability announcement without additional strategic context.
A sandbox-escape vulnerability in Chrome extensions enables remote code execution with elevated privileges beyond normal capability, significantly increasing infection risk from malicious web content.
This is a sandbox-escape vulnerability in the ANGLE rendering engine that allows attackers to execute code outside Chrome's sandbox, thereby breaking the browser's process isolation.
The vulnerability enables sandbox escape via XML type confusion, potentially allowing code execution with elevated privileges upon successful exploitation.
This is a standard security patch notification with no evidence of active exploitation or specific campaigns; the vulnerability requires renderer compromise as a prerequisite.
A sandbox-escape vulnerability enables code execution outside the Chrome sandbox, but requires prior renderer process compromise and social engineering.
The vulnerability enables sandbox escape via crafted HTML pages, allowing attackers to gain system access with Chrome process privileges , beyond typical browser exploits.
An out-of-bounds read vulnerability in Chrome's WebGL engine enables an attacker to bypass the sandbox and execute arbitrary code outside the sandbox context,a critical risk for endpoints running Chrome.
TerminalFix variant of ClickFix targets Windows Terminal/PowerShell to increase successful execution of multi-line commands and enable direct network access via reverse tunnel.
Organized social engineering campaign uses external Microsoft Teams accounts to impersonate IT help desk personnel for credential theft; 150+ employees across 10+ companies targeted between January and April 2026.
BSI warns of multiple undocumented vulnerabilities in Chrome and Edge without specific CVE identifiers; exact scope and impact remain initially unclear.
BSI alerts to multiple vulnerabilities in Adobe Creative Cloud (Bridge and Format Plugins) enabling arbitrary code execution with privilege escalation , patching or mitigation strategy should be prioritized given widespread deployment in design operations.
ZDI-26-607 enables information disclosure in Microsoft Office via HTML injection and requires user interaction; CVSS 7.6 with potential escalation depending on exploitation chain.
ZDI-published vulnerability enables privilege escalation from LOCAL SERVICE to higher privileges on Windows systems; requires prior code execution in the LOCAL SERVICE context.
BSI warns of multiple vulnerabilities in Chrome and Edge enabling active exploitation via malicious websites,standard browser protection for employees required.
BSI warning on multiple vulnerabilities in Adobe Acrobat and Reader without specific CVE identifiers; patch status and availability must be obtained from the vendor.
BSI warning regarding multiple Microsoft Office vulnerabilities with potential for privilege escalation and code execution; specific CVE details and patch status require consultation of the full BSI advisory.
BSI warning on multiple OpenSSL vulnerabilities with broad impact on encryption, authentication, and availability , requires verification of deployed OpenSSL versions in the infrastructure.
The 'Spring Ring' operation uses vishing techniques specifically targeting Microsoft Teams users to enable remote access and malware distribution,not just email phishing, but direct VoIP-based social engineering against collaboration platforms.
BSI warning on multiple unnamed vulnerabilities in FortiOS/FortiProxy with DoS and information disclosure potential , specific CVE numbers and CVSS scores are missing, making patch prioritization difficult.
An authenticated remote vulnerability in FortiManager enables the bypass of security controls, endangering the central management layer of Fortinet infrastructures.
Threat actors impersonate IT support via Microsoft Teams to obtain remote access, then use PowerShell and portable Node.js runtimes to stage persistent C2 implants , an operational threat for manufacturers with remote support infrastructure.
BSI warns of multiple local Intel processor vulnerabilities enabling privilege escalation and data compromise , affects server and endpoint infrastructure running Intel CPUs.
Google has documented multiple Chrome zero-days in active attacks, including iterator invalidation in CSSFontFeatureValuesMap and out-of-bounds write in Skia , indicating targeted browser-based attack campaigns against unidentified threat actors.
Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.
A newly disclosed zero-day in Microsoft Defender (ShieldBreak) bypasses a July patch for privilege escalation and is actively discussed; organizations with Defender deployment should prioritize security updates immediately.
An authorization flaw in Chrome allows attackers to extract sensitive information via crafted HTML pages, with no active exploitation in the wild currently reported.
The vulnerability enables CSRF attacks against web applications if users interact with manipulated HTML via the browser; primarily affects cloud-based services deployed in the organization.
An information leak vulnerability in Chrome allows remote attackers to obtain sensitive data via crafted HTML pages , relevant for organizations using Chrome without additional browser isolation or content-security policies.
The vulnerability enables arbitrary code execution within the Chrome sandbox via crafted HTML pages, but currently shows no documented active exploitation.
The vulnerability requires already-compromised renderer processes and is exploited via crafted PDF files, suggesting targeted attacks following initial compromise.
The vulnerability requires active social engineering manipulation via a crafted HTML page and affects only users who click on malicious links, therefore posing low risk for well-trained users.
The vulnerability requires active social-engineering manipulation via a crafted HTML page and is rated Low-Severity; operational priority is low, but regular Chrome updates should be enforced.
An authorization bypass vulnerability in Chrome allows attackers to circumvent system access restrictions via crafted HTML pages, posing a risk to employees with privileged access.
This is a standard patch announcement with no indication of active exploitation or campaign context; the notice repeats NVD information without additional security insights.
A Low-Severity vulnerability in Chrome that requires prior renderer-process compromise and can only be exploited via crafted network traffic , a routine browser security update with no strategic implication.
The vulnerability allows attackers to bypass the Same-Origin Policy via crafted HTML pages and gain access to privileged pages, posing a significant risk to enterprise users.
The vulnerability allows a remote attacker to potentially exfiltrate sensitive information via crafted network traffic, going beyond typical input validation issues.
A vulnerability in the renderer process allows an attacker with a compromised renderer to access cross-origin data via crafted HTML; however, prior renderer compromise is a prerequisite.
The article is a generalized warning report lacking specific CVE numbers, active campaign names, or technical details on exploit methods; the website primarily loads cookie consent dialogs rather than substantive content.