Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
Comparing 10 September 2026 with the previous day 9 September 2026.
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
Threat actors are deliberately targeting inadequately monitored perimeter edge devices to gain initial access via these vulnerabilities and deploy post-exploitation tools such as PivotC2.
An integer-overflow vulnerability in Adobe Photoshop's JPEG processing enables remote code execution upon user interaction and is listed in the CISA KEV catalogue.
Integer-overflow vulnerability in DCM file parsing enables remote code execution with user interaction, rated CVSS 7.8 critical severity.
RCE vulnerability in Adobe Photoshop during JPEG-LS image processing requires user interaction (visiting a malicious page or opening a malicious file).
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with malicious PDF files or web pages.
Use of Adobe Acrobat Reader DC requires prompt patch prioritization, as RCE exploitability is present via file-opening vectors.
Adobe Acrobat Reader DC is vulnerable to Use-After-Free RCE in annotation processing; attack requires user interaction (file opening or web visit).
A use-after-free vulnerability in Adobe Acrobat Pro DC enables remote code execution via malicious files or web pages with CVSS 7.8, requiring user interaction.
Use-After-Free vulnerability in PDF annotation functionality enables remote code execution upon opening a malicious PDF or visiting a malicious website; CVSS 7.8 indicates high exploitability.
Use-After-Free vulnerability in annotation functionality enables remote code execution when visiting malicious pages or opening crafted files,relevant for organizations using Acrobat Pro DC in design and document workflows.
A use-after-free vulnerability enables remote code execution in Adobe Acrobat Reader DC with user interaction, presenting direct risk to organizations using this PDF reader.
Type confusion vulnerability in Adobe Acrobat Reader DC enables remote code execution through opening malicious PDFs or visiting prepared web pages.
Integer overflow vulnerability in Adobe Acrobat Pro DC's JPEG parser enables remote code execution when users open a malicious file or visit a malicious page.
An out-of-bounds write vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with a high CVSS score of 7.8.
A Use-After-Free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction (visiting a malicious page or opening a malicious file).
The vulnerability allows attackers to persistently manipulate network proxy settings via malicious add-ins and intercept authenticated Fusion user connections without user awareness.
Authenticated remote code execution in Fortinet FortiSandbox via command injection allows attackers to compromise systems where the product is deployed.
BSI warns of an active, targeted campaign against German institutions focusing on critical infrastructure and government agencies , a sign of elevated cyber risk in the DACH region for suppliers and partners in these sectors.
Low-severity vulnerability (CVSS 3.3) in Adobe Acrobat Reader DC with information disclosure potential through malicious PDF files, requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables information disclosure through malicious PDF or font files.
EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.
A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.
Russian-Ukrainian cyber operations escalate with sophisticated multi-payload delivery chains; security teams in DACH must prepare for similar techniques (WebDAV abuse, stealer distribution).
Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.
The ShieldCrash exploit enables privilege escalation to System privileges on Windows systems with September 2026 patches and has publicly available PoC code.
Chrome 153.0.8010.36/.37 patches one actively exploited medium-severity vulnerability and five critical flaws, including four in WebGL, enabling remote code execution.
BlueMoon kit actively exploits previously unpatched zero-days in Windows and Chrome, requiring immediate defensive readiness.
BSI warning regarding critical remote code execution vulnerability in FortiOS with immediate implications for the company's perimeter security.
A code-execution vulnerability in 7-Zip can be exploited by remote unauthenticated attackers and requires immediate patching.
Critical vulnerability in PAN-OS XML processing enables unauthenticated access to management and dataplane interfaces, with root-level code execution on PA-Series; Panorama affected.
Multiple zero-day vulnerabilities in Chrome are currently being actively exploited, requiring immediate patching across all users.
Unauthenticated attackers can disclose sensitive information via OAuth Device Code Grant flows in Entra ID; threat to identity security and access control.
A high-volume phishing campaign is using invisible Unicode characters (ASCII Smuggling) to evade email filters and conceal financial lure keywords,a technique adapted from AI prompt injection research.
Two critical vulnerabilities in Check Point firewalls enable unauthenticated remote code execution through faulty VPN certificate handling, indicating systemic risks in TLS/PKI validation in enterprise security appliances.
The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.
BSI warns of multiple vulnerabilities in FortiSandbox enabling remote code execution or information disclosure; specific CVE IDs and affected versions are detailed in the BSI advisory.
The BSI warning documents multiple vulnerabilities in UnifiOS without specific CVE numbers; the scope and severity suggest a coordinated disclosure or ongoing patch cycle.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud applications (Substance 3D, XD, Illustrator) with potential for code execution and information disclosure.
BSI alert on multiple Chrome vulnerabilities without specific CVE numbers or patch date,likely aggregate security notice for regular patch cycle.
Attackers use voice phishing on personal devices to gain Microsoft 365 access and then abuse the Graph API for large-scale data exfiltration, threatening conventional BYOD policies.
Threat actors are leveraging AI-powered techniques to craft highly convincing spoofed emails impersonating internal executives, enabling large-scale campaigns distributing over one million fraudulent messages.
Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.
A disgruntled security researcher is actively publishing exploitable zero-day exploits against Windows Defender as patch bypasses, regularly circumventing the protective effect of security updates.
Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.
Microsoft September 2026 patches cause Remote Desktop Services outages , a critical remote access component requiring immediate compatibility assessment.
No changes in this category.
No changes in this category.
CISA has added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog and prioritizes this security issue under BOD-26-04 guidance, setting a remediation deadline of 2026-09-12.
Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.
A critical flaw in SharePoint's JWT token validation logic allows attackers to bypass authentication without valid cryptographic signatures.
Unsafe .NET type instantiation in Business Connectivity Services enables remote code execution with SharePoint service account privileges; developed as a Pwn2Own entry and affects all supported SharePoint versions.
Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.
A CVSS-10.0 vulnerability in SAP Extended Passport Processing enables complete remote code execution without authentication and requires immediate patch implementation for all SAP instances.
The vulnerability enables unauthenticated access to AD accounts by exploiting RFC 4513-compliant LDAP implementations that accept anonymous binds.
A patch for CVE-2026-69414 (ShieldBreak) has not fully remediated the issue; the researcher demonstrated with ShieldCrash that the vulnerability can still be triggered under specific conditions and arbitrary files can be read with SYSTEM privileges.
Multiple state-sponsored APT groups, including China-aligned APT31, are deploying a newly discovered exploit kit (BlueMoon) that chains multiple Windows and Chrome vulnerabilities to compromise targets in Western countries.
Coordinated exploitation of a chain of zero-day vulnerabilities by Chinese espionage groups signals elevated threat to Western infrastructure and supply chains, with ongoing and expanding activity.
The Rhysida attack on Berlin reveals systematic security gaps in the defensive architecture of critical German infrastructure that serves as a warning signal for other DACH organizations.
CAV3RN exploits Google Apps Script and DNS-based channels for C2 communication, demonstrating how modern APT groups abuse legitimate cloud services to obfuscate threat activity.
AI-driven automation lowers the entry barrier for resource-constrained attackers to achieve nation-state-equivalent capabilities in vulnerability discovery and malware development, fundamentally escalating threat posture across all sectors.
Multiple China-linked state-sponsored hacking groups actively exploiting the same Chrome zero-day suggests coordinated or centrally-directed cyber-espionage against Western infrastructure.
Two of the 974 CVEs are already being actively exploited and have highest priority, while the remaining 114 critical vulnerabilities are distributed through bundled update packages per product.
This is a patch roundup aggregating 974 independent CVEs without describing a specific active attack campaign; however, the two actively exploited zero-days require immediate patching to limit exposure.
A zero-day in Microsoft Defender enables local privilege escalation to SYSTEM rights and represents a serious threat to organizations relying on Defender as a protection layer.
Both zero-days are local privilege-escalation vulnerabilities that can escalate existing low-privilege code execution to SYSTEM rights , typically relevant as a second stage in exploit chains or post-compromise scenarios.
The critical vulnerabilities allow unauthenticated attackers to bypass authentication using forged JWTs and proxy user browser traffic if users visit malicious websites,a direct risk to privileged access management.
The vulnerability enables unauthenticated remote attackers to achieve kernel-level code execution via specially crafted HTTP/1.x requests over TLS connections.
An out-of-bounds write vulnerability in VMware ESXi VMXNET3 driver enables local attackers to escalate privileges on guest virtual machines; demonstrated at Pwn2Own 2026.
Critical authentication bypass vulnerability (CVSS 10.0) is actively exploited by ransomware operators (UAT-11988) who gain initial access via static credentials and abuse legitimate tooling for reconnaissance and lateral movement.
RCE vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code; exploit details reveal XML-based Business Data Catalog manipulation as the attack vector.
The vulnerability enables arbitrary code execution outside the browser sandbox via a crafted HTML page, suggesting potential active exploitation.
A sandbox bypass in Chrome WebGL enables attackers to execute code outside the browser sandbox, increasing the risk of full system compromise via crafted web pages.
The vulnerability enables arbitrary code execution outside the sandbox by an adjacent attacker using crafted network traffic , a significant risk for Chrome-based systems.
Adobe Commerce vulnerability is already under active exploitation; Experience Manager contributes significantly to patch burden with 107 vulnerabilities patched.
The BSI warning indicates multiple critical vulnerabilities in the Azure/Entra identity platform affecting authentication, authorization, and code execution,a core infrastructure for Microsoft 365 environments.
BSI alert on critical SAP vulnerabilities across multiple products; specific CVE numbers and affected versions are required for prioritized patch planning.
A local privilege escalation flaw in Windows WMI Providers requires prior code execution access and threatens environments with locally accessible systems.
Local privilege escalation vulnerability in Windows WMI requires initial code execution, affects all Windows Server versions in the IT infrastructure.
Critical security vulnerability in widely-used PDF reader enabling remote code execution upon user interaction; risk to technical documentation handling in manufacturing environments.
This is a BSI advisory on multiple GNU libc vulnerabilities without specific CVE identification; the 'UPDATE' designation suggests a follow-up notification and requires verification of specifically affected versions in the production environment.
BSI warning on multiple critical GNU libc vulnerabilities without specific CVE disclosure suggests coordinated release or ongoing patch cycle , urgency depends on patch status.
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
BSI warning of multiple critical vulnerabilities in VMware virtualization products with direct impact on hypervisor and vCenter infrastructure used by European organizations.
BSI warns of multiple vulnerabilities in Firefox/Thunderbird enabling code execution and sandbox escape; exploitation possible through opening malicious files or websites.
A V8 flaw (CVE-2026-85046) is already being actively exploited in the wild, enabling arbitrary code execution within the Chrome sandbox via crafted HTML pages.
The vulnerability enables code execution within Chrome's sandbox via crafted HTML content , the risk lies in browser-based attack vectors requiring only visit to a malicious webpage, with sandbox mitigation as the primary containment layer.
A use-after-free vulnerability in the Aura component allows a remote attacker to execute code outside the browser sandbox, bypassing Chrome's isolation mechanisms.
Use-after-free vulnerability in Chrome's platform code enables remote code execution within the sandbox; patching to version 153.0.8010.36 or later is required.
The vulnerability requires renderer process compromise combined with social engineering, which significantly limits practical exploitation in enterprise environments, but enables full code execution outside the browser sandbox if successfully exploited.
The vulnerability allows an attacker with control over the renderer process to execute code outside the Chrome sandbox, enabling full system compromise.
The vulnerability enables sandbox escape and arbitrary code execution via a crafted HTML page, but requires active user interaction and is not documented as actively exploited.
A sandbox bypass in Chrome DevTools enables arbitrary code execution via crafted HTML pages without user interaction.
The vulnerability allows an attacker who has already compromised the renderer process to bypass the same-origin policy and breach web security boundaries.
A sandbox-escape vulnerability in Chromium ANGLE allows attackers to execute arbitrary code outside the browser sandbox, posing critical risk to end users.
A security vulnerability in Chrome's WebUI allows an attacker who has already compromised the renderer process to bypass the sandbox and execute arbitrary code , but this requires a previously compromised renderer as a prerequisite.
The vulnerability enables sandbox escape, potentially granting attackers access to the underlying operating system rather than being confined to isolated browser processes.
The vulnerability enables sandbox escape and local code execution without remote access; a local attacker (e.g. via compromised software or physical access) can thereby control the system outside the Chrome sandbox.
The vulnerability allows an attacker with access to the renderer process to execute code outside the sandbox , a classic sandbox escape that compromises Chrome's security architecture.
Type confusion in Chrome's Rust implementation enables sandbox escape and remote code execution through crafted HTML pages.
The vulnerability allows local attackers with existing access to the Windows system to execute arbitrary code outside the browser sandbox through an improper search path in the CredentialProvider component.
This vulnerability requires a prior successful renderer process compromise as a prerequisite and is thus more of a follow-up step in a multi-stage attack than a direct initial compromise vector.
Use-after-free in V8 enables sandbox bypass with arbitrary code execution,not merely local privilege escalation, but complete browser compromise through remote attack via crafted HTML.
The vulnerability enables sandbox escape and potentially system access on endpoints running Chrome , relevant for phishing campaigns using crafted HTML pages.
The vulnerability enables sandbox escape via incorrect filesystem reference resolution and requires active social engineering; however, there is no evidence of active exploitation in the wild.
A vulnerability in Chrome's LocalNetworkAccess mechanism allows an attacker with renderer process access to bypass system resource access restrictions via a crafted HTML page.
A type confusion bug in the V8 engine enables memory reading within the Chrome sandbox without full sandbox escape; this represents an active attack vector against browser users.
The vulnerability allows attackers with network access to bypass Chrome's sandbox and execute arbitrary code on affected systems , a significant risk for all browser users.
The vulnerability allows an attacker with control over the renderer process to execute code outside Chrome's sandbox, bypassing browser-based exploit mitigations.
A double-free vulnerability in Chromium's PDF engine enables remote code execution within the browser sandbox via crafted PDF files,a direct attack vector exploitable through social engineering.
A use-after-free vulnerability in the V8 JavaScript engine enables attackers to achieve remote code execution within the Chrome sandbox via crafted HTML pages.
An out-of-bounds read vulnerability in the ANGLE graphics engine enables memory access outside the browser sandbox and could expose memory contents; the vulnerability is rated High severity and requires timely update to Chrome 153.0.8010.36 or later.
The vulnerability allows an attacker with renderer process access to execute code outside the Chrome sandbox , a sandbox escape that could lead to arbitrary system-level code execution if successfully exploited.
Active exploitation in the wild or campaign context is not described in the alert; this is a standard vulnerability announcement without additional strategic context.
A sandbox-escape vulnerability in Chrome extensions enables remote code execution with elevated privileges beyond normal capability, significantly increasing infection risk from malicious web content.
The vulnerability requires prior compromise of the renderer process, elevating risk through multi-stage exploits in real-world attack scenarios.
This is a sandbox-escape vulnerability in the ANGLE rendering engine that allows attackers to execute code outside Chrome's sandbox, thereby breaking the browser's process isolation.
The vulnerability enables sandbox escape via XML type confusion, potentially allowing code execution with elevated privileges upon successful exploitation.
This is a standard security patch notification with no evidence of active exploitation or specific campaigns; the vulnerability requires renderer compromise as a prerequisite.
A sandbox-escape vulnerability enables code execution outside the Chrome sandbox, but requires prior renderer process compromise and social engineering.
The vulnerability enables sandbox escape via crafted HTML pages, allowing attackers to gain system access with Chrome process privileges , beyond typical browser exploits.
The vulnerability requires an already-compromised renderer process and could bypass the Chrome sandbox , a two-stage attack on Windows systems.
An out-of-bounds read vulnerability in Chrome's WebGL engine enables an attacker to bypass the sandbox and execute arbitrary code outside the sandbox context,a critical risk for endpoints running Chrome.
Sandbox-escape capability enables code execution outside Chrome sandbox; standard CVE advisory with no indication of active exploitation.
The alert points to insufficient patch compliance in German enterprise networks rather than revealing a new specific vulnerability.
TerminalFix variant of ClickFix targets Windows Terminal/PowerShell to increase successful execution of multi-line commands and enable direct network access via reverse tunnel.
Organized social engineering campaign uses external Microsoft Teams accounts to impersonate IT help desk personnel for credential theft; 150+ employees across 10+ companies targeted between January and April 2026.
BSI warns of multiple undocumented vulnerabilities in Chrome and Edge without specific CVE identifiers; exact scope and impact remain initially unclear.
BSI warning on multiple Chrome vulnerabilities without specific CVE identifiers; generic browser-security alert for the DACH region.
The BSI alert provides no specific CVE number and no version information , details are needed to determine affected versions and patch status.
BSI alerts to multiple vulnerabilities in Adobe Creative Cloud (Bridge and Format Plugins) enabling arbitrary code execution with privilege escalation , patching or mitigation strategy should be prioritized given widespread deployment in design operations.
ZDI-26-607 enables information disclosure in Microsoft Office via HTML injection and requires user interaction; CVSS 7.6 with potential escalation depending on exploitation chain.
ZDI-published vulnerability enables privilege escalation from LOCAL SERVICE to higher privileges on Windows systems; requires prior code execution in the LOCAL SERVICE context.
BSI warns of multiple vulnerabilities in Chrome and Edge enabling active exploitation via malicious websites,standard browser protection for employees required.
The malware uses in-memory injection to evade disk-based scanning , an indicator of targeted attacks against organisations with security monitoring.
BSI warning on multiple vulnerabilities in Adobe Acrobat and Reader without specific CVE identifiers; patch status and availability must be obtained from the vendor.
BSI warning regarding multiple Microsoft Office vulnerabilities with potential for privilege escalation and code execution; specific CVE details and patch status require consultation of the full BSI advisory.
BSI warning on multiple OpenSSL vulnerabilities with broad impact on encryption, authentication, and availability , requires verification of deployed OpenSSL versions in the infrastructure.
The 'Spring Ring' operation uses vishing techniques specifically targeting Microsoft Teams users to enable remote access and malware distribution,not just email phishing, but direct VoIP-based social engineering against collaboration platforms.
The article is a patch announcement for multiple independent ICS vendors without description of an active attack scenario or targeted campaign.
BSI warning on multiple unnamed vulnerabilities in FortiOS/FortiProxy with DoS and information disclosure potential , specific CVE numbers and CVSS scores are missing, making patch prioritization difficult.
An authenticated remote vulnerability in FortiManager enables the bypass of security controls, endangering the central management layer of Fortinet infrastructures.
BSI warning on multiple Chrome vulnerabilities without specific CVE numbers or active exploitation mentioned; standard patch management requirement.
Threat actors impersonate IT support via Microsoft Teams to obtain remote access, then use PowerShell and portable Node.js runtimes to stage persistent C2 implants , an operational threat for manufacturers with remote support infrastructure.
BSI warns of multiple local Intel processor vulnerabilities enabling privilege escalation and data compromise , affects server and endpoint infrastructure running Intel CPUs.
BSI vulnerability warning for Firefox/Thunderbird without specific CVE details; update advisory without active campaign or strategic dimension.
An actively exploited V8 flaw enables code execution within Chrome's sandbox, which could facilitate escalation to system level.
Google has documented multiple Chrome zero-days in active attacks, including iterator invalidation in CSSFontFeatureValuesMap and out-of-bounds write in Skia , indicating targeted browser-based attack campaigns against unidentified threat actors.
CVE-2026-87491 is actively being exploited in the wild and presents an immediate threat requiring urgent patching.
Active campaign uses counterfeit software-download websites to distribute malicious installers that write Defender exclusions and disable Windows Update; primarily affects China-based operations, but tactics are transferable to Western environments.
A newly disclosed zero-day in Microsoft Defender (ShieldBreak) bypasses a July patch for privilege escalation and is actively discussed; organizations with Defender deployment should prioritize security updates immediately.
An authorization flaw in Chrome allows attackers to extract sensitive information via crafted HTML pages, with no active exploitation in the wild currently reported.
The vulnerability enables CSRF attacks against web applications if users interact with manipulated HTML via the browser; primarily affects cloud-based services deployed in the organization.
An information leak vulnerability in Chrome allows remote attackers to obtain sensitive data via crafted HTML pages , relevant for organizations using Chrome without additional browser isolation or content-security policies.
The vulnerability enables arbitrary code execution within the Chrome sandbox via crafted HTML pages, but currently shows no documented active exploitation.
The vulnerability requires already-compromised renderer processes and is exploited via crafted PDF files, suggesting targeted attacks following initial compromise.
The vulnerability requires active social engineering manipulation via a crafted HTML page and affects only users who click on malicious links, therefore posing low risk for well-trained users.
The vulnerability requires active social-engineering manipulation via a crafted HTML page and is rated Low-Severity; operational priority is low, but regular Chrome updates should be enforced.
An authorization bypass vulnerability in Chrome allows attackers to circumvent system access restrictions via crafted HTML pages, posing a risk to employees with privileged access.
This is a standard patch announcement with no indication of active exploitation or campaign context; the notice repeats NVD information without additional security insights.
A Low-Severity vulnerability in Chrome that requires prior renderer-process compromise and can only be exploited via crafted network traffic , a routine browser security update with no strategic implication.
The vulnerability allows attackers to bypass the Same-Origin Policy via crafted HTML pages and gain access to privileged pages, posing a significant risk to enterprise users.
The vulnerability allows a remote attacker to potentially exfiltrate sensitive information via crafted network traffic, going beyond typical input validation issues.
A vulnerability in the renderer process allows an attacker with a compromised renderer to access cross-origin data via crafted HTML; however, prior renderer compromise is a prerequisite.
The article is a generalized warning report lacking specific CVE numbers, active campaign names, or technical details on exploit methods; the website primarily loads cookie consent dialogs rather than substantive content.
BSI advisory on local kernel DoS vulnerabilities without specific CVE numbers or PoC status , requires verification of affected kernel versions.