PULSE
FEED
vulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Kalir Brief · Item17 September 2026 · 22:12 UTC
BRIEFOtherhighP58

Chromium RCE 0-day full-chain exploit for Android 14-16 offered

Google Chromium / Android

Detected17 September 2026 · 22:12 UTC
Why it matters

A seller claims a fresh full-chain Chromium RCE affecting Android 14 through 16, advertised as 0-day class and suitable for drive-by exploitation. If genuine, it endangers any Android user, including government and enterprise mobile fleets common across the region. No date or price is shown, so treat it as unverified but high priority for patching and browser hardening.

MetadataRECORD
CategoryOther
Severityhigh
Priority score58
Detected17 September 2026 · 22:12 UTC
Related items6
Other44
Se vende exploit 0day de escalada de privilegios en Windows 11A user is selling a claimed Windows 11 local privilege escalation 0day, posted within the last day. If real, it enables post-exploitation elevation on fully patched Windows hosts, raising risk across any Windows estate. Unverified 0day claims on forums are frequently scams or repackaged known bugs, so validate before alerting.
4d
Other45
AnkaTeam hackea el sitio del club español Villarreal CFThe Turkish hacking group AnkaTeam claims to have compromised Villarreal CF, a Spanish La Liga football club, as part of a defacement and data-theft campaign. Sports organizations hold fan personal data, ticketing and payment information, plus partner credentials that can be abused for fraud and downstream attacks. The public claim raises reputational risk and warrants verification of any leaked data.
5d
Other35
El Villarreal CF habría sido hackeado por AnkaTeamA TurkHackTeam post claims the Spanish football club Villarreal CF was hacked by the 'AnkaTeam' group, likely a defacement/leak claim. While not critical infrastructure, a named Spanish entity being targeted is worth a quick check for leaked fan/customer data or defacement evidence. Impact and authenticity are unverified, so treat as low-confidence.
5d
Other58
Divulgación de 0day RCE para Apache OFBizA forum user published what is claimed to be a 0day remote code execution proof-of-concept for Apache OFBiz, an open-source ERP/CRM used by enterprises and public bodies. If legitimate, unpatched and internet-exposed OFBiz instances are at immediate risk of full server compromise. Defenders running OFBiz should isolate exposed instances and hunt for exploitation attempts.
7d
Other60
Exploit zero-day de RCE para Apache OFBiz a la ventaA zero-day remote code execution exploit targeting Apache OFBiz is being sold on BreachForums. OFBiz underpins ERP and e-commerce operations at many enterprises, so a working RCE enables full server compromise and data theft. Organizations running OFBiz should prioritise patching and network monitoring.
7d
Other78
Exploit público para RCE crítica en Oracle WebLogic Proxy Plug-in (CVE-2026-21962)A working exploit for a critical remote code execution vulnerability in Oracle WebLogic Proxy Plug-in (CVE-2026-21962) was published on a Russian underground forum. WebLogic is widely deployed in enterprise and government environments, including Latin America, making this a potential initial access vector. Organizations should validate exposure and apply the vendor patch immediately.
22d