This day 02:09 06:10 10:01 14:01 18:02 22:02
⚠ exploit status: CVE-2026-67277 · KEV
Info  2026-09-10 22:02Z · last 4h · 7 findings · glm-5.2:cloud

Threat Brief — 2026-09-10 — Android dual-threat malware, Excel breakage

Executive summary: A new Android malware strain combining ransomware and spyware capabilities has surfaced, encrypting files while simultaneously exfiltrating data and harassing victims. Microsoft's September update troubles continue: Excel's latest security patch breaks copy-and-paste operations, compounding the already-reported RDS breakage. CISA has formally added a MikroTik RouterOS authentication bypass to its Known Exploited Vulnerabilities catalog, a development since the flaw was first reported as actively exploited last week.

Top items

Themes

September update quality issues are stacking up. Microsoft's September 2026 patch batch continues to produce operational breakage beyond the security fixes themselves: RDS connectivity failures on Windows Server (first reported 2026-09-10), Excel copy-and-paste disruption, and previously reported desktop-settings resets from KB5120998. Organisations applying these patches should test broadly and prepare rollback options.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db