Skip to main content

Microsoft Defender "ShieldCrash" Zero-Day Bypasses September 2026 Patch, SYSTEM File Read Confirmed on All Windows Versions

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

ConnectWise ScreenConnect Authentication Bypass Under Active Exploitation Grants Full Remote Control of Managed Endpoints (CVE-2026-77924)

Scope: ConnectWise ScreenConnect (All Versions Prior to Latest Patched Release)

MikroTik RouterOS "MikroTrick" Authentication Bypass Chain Seizes Devices Without Credentials (CVE-2026-67277 / CVE-2026-86060)

Scope: MikroTik RouterOS (All Versions Affected by Both CVEs, Prior to Latest Stable Relea

Google Chrome V8 Type Confusion Zero-Day Under Active Exploitation Added to CISA KEV (CVE-2026-85046)

Scope: Google Chrome Prior to Version 152.0.7977.82 and All Chromium-Based Browsers Includ

Windows Update Stack and ALPC Actively Exploited Zero-Days from Record September 2026 Patch Tuesday (CVE-2026-81963 / CVE-2026-85880)

Scope: Windows 10, Windows 11, Windows Server 2019, 2022, and 2025 (All Supported Versions

Progress LoadMaster Command Injection Under Active Mass Exploitation from 792 Attack IPs (CVE-2026-8037)

Scope: Progress LoadMaster (All Versions Prior to GA 7.2.63.2 and LTSF 7.2.54.18)

Microsoft Defender ShieldBreak CISA KEV Deadline Today as Lazarus Group Exploitation Confirmed (CVE-2026-69414)

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

Subscribe to Advisories