Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
Comparing 10 September 2026 with the previous day 3 September 2026.
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
Threat actors are deliberately targeting inadequately monitored perimeter edge devices to gain initial access via these vulnerabilities and deploy post-exploitation tools such as PivotC2.
An integer-overflow vulnerability in Adobe Photoshop's JPEG processing enables remote code execution upon user interaction and is listed in the CISA KEV catalogue.
Integer-overflow vulnerability in DCM file parsing enables remote code execution with user interaction, rated CVSS 7.8 critical severity.
RCE vulnerability in Adobe Photoshop during JPEG-LS image processing requires user interaction (visiting a malicious page or opening a malicious file).
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with malicious PDF files or web pages.
Use of Adobe Acrobat Reader DC requires prompt patch prioritization, as RCE exploitability is present via file-opening vectors.
Adobe Acrobat Reader DC is vulnerable to Use-After-Free RCE in annotation processing; attack requires user interaction (file opening or web visit).
A use-after-free vulnerability in Adobe Acrobat Pro DC enables remote code execution via malicious files or web pages with CVSS 7.8, requiring user interaction.
Use-After-Free vulnerability in PDF annotation functionality enables remote code execution upon opening a malicious PDF or visiting a malicious website; CVSS 7.8 indicates high exploitability.
Use-After-Free vulnerability in annotation functionality enables remote code execution when visiting malicious pages or opening crafted files,relevant for organizations using Acrobat Pro DC in design and document workflows.
A use-after-free vulnerability enables remote code execution in Adobe Acrobat Reader DC with user interaction, presenting direct risk to organizations using this PDF reader.
Type confusion vulnerability in Adobe Acrobat Reader DC enables remote code execution through opening malicious PDFs or visiting prepared web pages.
Integer overflow vulnerability in Adobe Acrobat Pro DC's JPEG parser enables remote code execution when users open a malicious file or visit a malicious page.
An out-of-bounds write vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with a high CVSS score of 7.8.
A Use-After-Free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction (visiting a malicious page or opening a malicious file).
The vulnerability allows attackers to persistently manipulate network proxy settings via malicious add-ins and intercept authenticated Fusion user connections without user awareness.
Authenticated remote code execution in Fortinet FortiSandbox via command injection allows attackers to compromise systems where the product is deployed.
BSI warns of an active, targeted campaign against German institutions focusing on critical infrastructure and government agencies , a sign of elevated cyber risk in the DACH region for suppliers and partners in these sectors.
Low-severity vulnerability (CVSS 3.3) in Adobe Acrobat Reader DC with information disclosure potential through malicious PDF files, requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables information disclosure through malicious PDF or font files.
EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.
A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.
Russian-Ukrainian cyber operations escalate with sophisticated multi-payload delivery chains; security teams in DACH must prepare for similar techniques (WebDAV abuse, stealer distribution).
Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.
The ShieldCrash exploit enables privilege escalation to System privileges on Windows systems with September 2026 patches and has publicly available PoC code.
Chrome 153.0.8010.36/.37 patches one actively exploited medium-severity vulnerability and five critical flaws, including four in WebGL, enabling remote code execution.
BlueMoon kit actively exploits previously unpatched zero-days in Windows and Chrome, requiring immediate defensive readiness.
BSI warning regarding critical remote code execution vulnerability in FortiOS with immediate implications for the company's perimeter security.
A code-execution vulnerability in 7-Zip can be exploited by remote unauthenticated attackers and requires immediate patching.
Critical vulnerability in PAN-OS XML processing enables unauthenticated access to management and dataplane interfaces, with root-level code execution on PA-Series; Panorama affected.
Multiple zero-day vulnerabilities in Chrome are currently being actively exploited, requiring immediate patching across all users.
Unauthenticated attackers can disclose sensitive information via OAuth Device Code Grant flows in Entra ID; threat to identity security and access control.
A high-volume phishing campaign is using invisible Unicode characters (ASCII Smuggling) to evade email filters and conceal financial lure keywords,a technique adapted from AI prompt injection research.
Two critical vulnerabilities in Check Point firewalls enable unauthenticated remote code execution through faulty VPN certificate handling, indicating systemic risks in TLS/PKI validation in enterprise security appliances.
The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.
BSI warns of multiple vulnerabilities in FortiSandbox enabling remote code execution or information disclosure; specific CVE IDs and affected versions are detailed in the BSI advisory.
The BSI warning documents multiple vulnerabilities in UnifiOS without specific CVE numbers; the scope and severity suggest a coordinated disclosure or ongoing patch cycle.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud applications (Substance 3D, XD, Illustrator) with potential for code execution and information disclosure.
BSI alert on multiple Chrome vulnerabilities without specific CVE numbers or patch date,likely aggregate security notice for regular patch cycle.
Attackers use voice phishing on personal devices to gain Microsoft 365 access and then abuse the Graph API for large-scale data exfiltration, threatening conventional BYOD policies.
Threat actors are leveraging AI-powered techniques to craft highly convincing spoofed emails impersonating internal executives, enabling large-scale campaigns distributing over one million fraudulent messages.
Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.
A disgruntled security researcher is actively publishing exploitable zero-day exploits against Windows Defender as patch bypasses, regularly circumventing the protective effect of security updates.
Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.
Microsoft September 2026 patches cause Remote Desktop Services outages , a critical remote access component requiring immediate compatibility assessment.
No changes in this category.
No changes in this category.
No changes in this category.