
Identity & accessEXPLAINER · 3 MIN READ
macOS Accounts CVE-2026-43749: how path handling can lead to root
Apple fixed a directory-path parsing issue in the Accounts component. The advisory reports potential root privileges for an app, while leaving the precise path-handling failure unpublished.
Sep 9, 2026 ↗

Threat awarenessEXPLAINER · 3 MIN READ
WebKit CVE-2026-64728: an iframe sandbox flaw, explained
Apple repaired how WebKit enforces an embedded document’s permissions. The fix concerns iframe policy, which is different from a browser process escaping into the operating system.
Sep 9, 2026 ↗

Threat awarenessEXPLAINER · 4 MIN READ
Apple’s M5 MIE bypass: what the researchers demonstrated
Calif combined two macOS bugs to gain root on an M5 Mac while MIE remained enabled. Apple patched them in macOS 26.6. Here’s what the result says about memory tagging.
Sep 9, 2026 ↗

Defense & recoveryEXPLAINER · 3 MIN READ
GitLab CVE-2026-19478: protecting project data behind the GraphQL API
GitLab disclosed a critical flaw that could let an unauthenticated user alter or delete project and user data under certain conditions. Self-managed instances need update and recovery checks.
Sep 9, 2026 ↗

Defense & recoveryEXPLAINER · 3 MIN READ
Cisco IOS XR: why seven CVEs do not necessarily mean seven bugs
Cisco groups several IOS XR findings under seven CVE identifiers. That affects how you read the severity data—and why a base software version is not enough to confirm the fixes.
Sep 9, 2026 ↗

Threat awarenessEXPLAINER · 3 MIN READ
Adobe’s September Acrobat fixes: what happens when you open a PDF
The update addresses memory corruption and authorization flaws across Acrobat’s update tracks. Check the reader people use and the protections applied to outside documents.
Sep 9, 2026 ↗

Threat awarenessEXPLAINER · 3 MIN READ
Firefox’s September update: use-after-free bugs and sandbox escapes
Mozilla’s fixes cover Firefox 155 and two ESR branches. The advisories explain the risks, but checking the right update still starts with knowing which channel is installed.
Sep 9, 2026 ↗

Identity & accessEXPLAINER · 3 MIN READ
SharePoint CVE-2026-69465: when a signed-in user has too much access
Microsoft’s missing-authorization fix needs more than a package install. Review the affected SharePoint edition, Workflow Manager prerequisite and upgrade status across the farm.
Sep 9, 2026 ↗

Threat awarenessEXPLAINER · 3 MIN READ
Apple ImageIO CVE-2026-65346: the risk inside image decoding
Apple fixed an integer overflow in ImageIO. Here’s how image-size calculations can go wrong, what Apple has disclosed and why the operating-system update matters.
Sep 9, 2026 ↗