<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel><title>FlawFind Security Blog</title><link>https://blog.flawfind.ai/</link><description>Recent attacks, exploited vulnerabilities and what to do about them.</description><language>en</language><atom:link href="https://blog.flawfind.ai/feed.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Tue, 15 Sep 2026 21:37:35 +0000</lastBuildDate><item><title>Acronis warns of actively exploited flaw in its cPanel backup plugin</title><link>https://blog.flawfind.ai/posts/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin-6e529cd8.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin-6e529cd8.html</guid><pubDate>Tue, 15 Sep 2026 21:37:35 +0000</pubDate><description>Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]</description><category>news</category></item><item><title>KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens</title><link>https://blog.flawfind.ai/posts/kremlin-banking-malware-hijacks-chrome-and-edge-to-steal-credentials-and-session-216666e1.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/kremlin-banking-malware-hijacks-chrome-and-edge-to-steal-credentials-and-session-216666e1.html</guid><pubDate>Tue, 15 Sep 2026 18:54:14 +0000</pubDate><description>Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and</description><category>news</category></item><item><title>Cisco Secure Email Gateway SQL Injection Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-76461-2b7216c4.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-76461-2b7216c4.html</guid><pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate><description>Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-85706-eb189f1e.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-85706-eb189f1e.html</guid><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><description>GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-84869-40a7c3bd.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-84869-40a7c3bd.html</guid><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><description>ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>JFrog Artifactory Improper Authentication Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-42018-a96cb7b6.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-42018-a96cb7b6.html</guid><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><description>JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>JFrog Artifactory Incorrect Authorization Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-42016-2bb90eb6.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-42016-2bb90eb6.html</guid><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><description>JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-86060-0bc21b9a.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-86060-0bc21b9a.html</guid><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><description>MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>MikroTik RouterOS Missing Authentication for Critical Function Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-67277-beffcad9.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-67277-beffcad9.html</guid><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><description>MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability</title><link>https://blog.flawfind.ai/posts/cve-2026-19490-1c70af4d.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/cve-2026-19490-1c70af4d.html</guid><pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate><description>Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.</description><category>known-exploited</category><category>cisa-kev</category></item><item><title>Microsoft Plugs Nearly 1,000 Security Holes</title><link>https://blog.flawfind.ai/posts/microsoft-plugs-nearly-1-000-security-holes-bf5c69a9.html</link><guid isPermaLink="true">https://blog.flawfind.ai/posts/microsoft-plugs-nearly-1-000-security-holes-bf5c69a9.html</guid><pubDate>Tue, 08 Sep 2026 21:44:22 +0000</pubDate><description>Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.</description><category>news</category></item></channel>
</rss>
