Skip to main content

OpenAI Codex Sandbox Escapes "Heapjack" and "Overpatch" Allow Unsandboxed Command Execution

Scope: OpenAI Codex Desktop (Prior to Build 26.818.21641) and Codex CLI (Prior to Version

CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities, Federal Deadline Today (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)

Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers

GitLab CE and EE Repository Commits API Path Traversal Allows Unauthenticated Arbitrary File Read (CVE-2026-85706)

Scope: GitLab Community Edition and Enterprise Edition Self-Managed Installations (GitLab.

Google Pixel September 2026 Update Patches Modem Privilege Escalation Under Targeted Exploitation and 46 Critical Flaws (CVE-2026-58704)

Scope: Google Pixel Devices (All Models Running Security Patch Level Earlier Than 2026-09-

Cisco Secure Email Gateway Unauthenticated Root Command Execution via Email Parsing Zero-Day (CVE-2026-76461)

Scope: Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) — Virtual

Microsoft Exchange Server Unauthenticated Network Remote Code Execution via Double-Free Vulnerability (CVE-2026-55007)

Scope: Microsoft Exchange Server (All Supported On-Premises Versions Prior to September 20

Gitea Self-Hosted Git Service Unauthenticated RCE Actively Exploited to Deploy Cryptocurrency Miners (CVE-2026-60004)

Scope: Gitea Versions 1.17 through 1.27.0 (All Versions Prior to 1.27.1)

Subscribe to Advisories