Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CVE-2026-16232: Check Point SmartConsole Zero-Day

CVE-2026-16232 is a critical authentication bypass in the Check Point SmartConsole login process. An unauthenticated attacker who can reach the Management Server IP, and who faces no Trusted Clients restriction, can obtain an application login token and sign in with full administrative rights. That access is enough to change security policy and configuration.

CISA: Ransomware Gangs Now Exploit Critical VMware vCenter Flaw

The U.S. Cybersecurity and Infrastructure Security Agency has warned that ransomware groups are now exploiting a critical VMware vCenter Server bug that Broadcom patched on 29 July 2026. The issue is CVE-2026-59310. It is a directory traversal flaw in the vCenter Syslog server. An attacker who can reach the server on the network does not need a password. Successful use can lead to remote code execution. The published severity score is 9.8.

Telegram Zero-Day: Malicious Sticker Crash Explained

On 6 September 2026, researchers publicly described a Telegram zero-day crash. A group owner said a chat they own became unreachable: opening it crashed official clients on iOS, Android, Desktop and Web. A second researcher posted a short recording of a script sending one specially prepared sticker into a test chat. The harm is availability, not account takeover. If the sticker stays in chat history, the crash can happen again every time someone opens that conversation.

Magento Zero-Day: Unpatched Adobe Commerce RCE Is Backdooring Online Stores

On 4 September 2026, attackers began exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce. Dutch e-commerce security firm Sansec disclosed the issue on 5 September and named it StyleSmuggler. The company said it published early because stores were being compromised in real time.

Falcon Flank: Public Privilege-Escalation Claim Against CrowdStrike Falcon

What security teams need to know about an unverified local elevation-of-privilege proof of concept published against Falcon Sensor, and how to respond without overreacting. On 3 September 2026, an independent researcher publishing as MSNightmare / Chaotic Eclipse / Nightmare Eclipse released a public GitHub repository named FalconFlank. The project is described as a local privilege-escalation proof of concept against CrowdStrike Falcon Sensor on Windows.