Oracle’s September patches put Fusion Middleware back in the hot seat
CSO Online 16.09.2026 15:54
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication.
Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics.
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News 16.09.2026 15:50
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine 16.09.2026 15:00
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News 16.09.2026 11:15
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild.
The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw.
"In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
The Hacker News 16.09.2026 11:08
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.
The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions –
Acronis Backup plugin for cPanel & WHM (Linux
Google warnt: Gefährliche Modem-Lücke in Pixel-Smartphones unter Beschuss
Golem 16.09.2026 10:40
Die neuen Updates für Google-Pixel-Geräte schließen Hunderte von Sicherheitslücken. Eine ist besonders gefährlich und wird bereits ausgenutzt. (Sicherheitslücke, Google)
Oracle patcht mehr als 650 Sicherheitslücken
Heise Security 16.09.2026 10:19
Das Oracle Critical Security Patch Update bringt Softwareflicken für mehr als 650 Lücken. Darunter sind diverse mit kritischem Risiko.
IBM MQ: In mehreren Fällen kann Schadcode auf Systeme gelangen
Heise Security 16.09.2026 09:39
In aktuellen Versionen von IBMs Middleware MQ haben die Entwickler mehrere Schwachstellen geschlossen. Bislang gibt es keine dokumentierten Attacken.
DDROP: Adapterstecker hebelt Confidential Computing aus
Heise Security 16.09.2026 08:24
IT-Forscher hebeln RAM-Verschlüsselung für Confidential Computing mittels Adapterstecker aus. DDROP greift aktuelles DDR5 an.
Angreifer attackieren Acronis Backup für cPanel/WHM und Plesk
Heise Security 16.09.2026 07:37
Aufgrund von laufenden Attacken müssen Admins Acronis Backup für cPanel/WHM und Plesk aktualisieren.
Spaniens Datenschutzaufsicht: Erster Cyberangriff mithilfe eines KI-Agenten
Heise Security 16.09.2026 05:56
In Spanien wurde ein Cyberangriff gemeldet, bei dem ein KI-Agent Daten verändern und Rechnungen einsehen konnte. Das sei von neuer Qualität.
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News 16.09.2026 05:48
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.
"This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said.
The WordPress security company said it has blocked over
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News 16.09.2026 05:18
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.
The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw.
"JWT authentication