Skip to content
Security

Patch now: 11 actively exploited flaws in common business gear (Sep 4, 2026 – Sep 16, 2026)

Actively exploited flaws in equipment small offices run, and where to get each fix.

Matthew Eveland

2 minute read

Security: Laptop Computer
Photo: Startup Stock Photos (CC0-1.0) via Openverse

These flaws are being used in real attacks right now, in equipment and software that small offices commonly run. If you have any of them, install the vendor’s fix this week.

  • Google Pixel — Google Pixel Improper Authorization Vulnerability (CVE-2026-58704), added Sep 16, 2026. Vendor advisory.
  • Cisco Identity Services Engine — Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460), added Sep 16, 2026. Vendor advisory.
  • Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerability (CVE-2026-76461), added Sep 14, 2026. Vendor advisory.
  • Citrix NetScaler — Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-19490), added Sep 9, 2026. Vendor advisory.
  • Fortinet Multiple Products — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability (CVE-2025-25249), added Sep 9, 2026. Vendor advisory.
  • Google Chromium V8 — Google Chromium V8 Out of Bounds Write Vulnerability (CVE-2026-87491), added Sep 9, 2026. Vendor advisory.
  • Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-20079), added Sep 9, 2026. Vendor advisory.
  • Adobe Commerce and Magento — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVE-2026-75650), added Sep 8, 2026. Vendor advisory.
  • Microsoft Windows — Microsoft Windows Link Following Vulnerability (CVE-2026-81963), added Sep 8, 2026. Vendor advisory.
  • Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability (CVE-2026-85880), added Sep 8, 2026. Vendor advisory.
  • Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046), added Sep 4, 2026. Vendor advisory.
Advertisement — 3DPrintStack

3DPrintStack

Stop losing money on underpriced jobs

Filament tracking, print queue, real cost per print, and a P&L that shows which jobs actually pay.

One plan · $20/month · 14-day free trial

Start the free trial

Written by

Matthew Eveland

Matthew Eveland writes SMB Tech News, a weekly read on the security, software and scam news that actually reaches small businesses.

Security