Sunday 13 September

Good evening,
Brisbane.

Queensland alert: 10/09:00 EST Marine Wind Warning Summary for Queensland

Updated 1m ago
Brisbane now20°Partly cloudy
Active alerts1warning
Top moverMETA+6.55%
Critical CVEs19tracked
Brisbane now

Partly cloudy

20°
Feels 18°H 20° · L 14°
92% rainUV 517 km/h
Next 24 hours
3 pm20°4% rain
7 pm17°0% rain
11 pm14°0% rain
3 am13°0% rain
7 am14°0% rain
11 am20°30% rain
Next 3 days
FriRain12° / 21°
SatRain13° / 21°
SunRain13° / 22°

The morning wire — news & briefings

LocalBrisbane & Queensland
7
Local · Lead story

Brisbane Roar Sign Lily Punch for 2026/27 A-League Women Season

Brisbane Roar·
View 3 more local stories
WorldInternational desk
8
World · Lead story

Iran referred to UN Security Council for nuclear non-compliance

Tehran condemns the resolution, blaming US and Israeli strikes on its nuclear facilities for disrupting inspections.

BBC World·
View 4 more world stories
CyberThreat reporting
8
Cyber · Lead story

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

BleepingComputer·
View 4 more cyber stories
TechnologyTechnology & AI
8
Technology · Lead story

UK needs new laws for AI in healthcare, says watchdog

The technology will soon be routinely used within the NHS, MHRA chief Lawrence Tallon tells the BBC.

BBC Technology·
View 4 more technology stories

Security desk — threats & advisories

Vulnerability intelligence

Priority CVEs

Known exploitation, severity and likelihood — ranked for action.

CVE-2026-86218N Able N Central
KEV10.0 critical

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

EPSS 0.7%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-82078Papercut Mf
KEV9.4 critical

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

EPSS 1.7%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-81578Papercut Mf
KEV8.8 high

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

EPSS 1.6%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-86152Affected application
10.0 critical

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

EPSS 1.9%
View 16 more priority CVEs
CVE-2026-18658Affected application
9.8 critical

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.

EPSS 0.4%
CVE-2026-84143Mozilla Firefox
9.8 critical

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

EPSS 0.4%
CVE-2026-84141Mozilla Firefox
9.8 critical

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

EPSS 0.3%
CVE-2026-84142Mozilla Firefox
9.8 critical

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

EPSS 0.3%
CVE-2026-84135Mozilla Firefox Mobile
9.8 critical

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

EPSS 0.3%
CVE-2026-84140Mozilla Firefox
9.8 critical

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

EPSS 0.2%
CVE-2026-86151Affected application
9.4 critical

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

EPSS 2.0%
9.3 critical

SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.

EPSS 1.5%
CVE-2026-86184Lara Dashboard
9.3 critical

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.

EPSS 0.6%
CVE-2026-85428MOOS core-moos through 10.4.0
9.3 critical

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

EPSS 0.5%
9.3 critical

AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.

EPSS 0.5%
CVE-2026-85438MOOS-IvP through 24.8.1
9.3 critical

MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution.

EPSS 0.5%
CVE-2026-85661Affected application
9.3 critical

excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.

EPSS 0.4%
9.3 critical

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

EPSS 0.4%
CVE-2026-86189WWBN AVideo
9.3 critical

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.

EPSS 0.4%
CVE-2026-85688TEN Framework 0.11.71
9.3 critical

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.

EPSS 0.4%
Uses NVD data but is not endorsed or certified by the NVD. KEV: CISA · EPSS: FIRST.org
Windows watch

Microsoft Windows CVEs

Windows CVEs from the current patch cycle, plus recent actively exploited entries from CISA.

CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock
KEVunknown

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

EPSS 6.2%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-81963Microsoft Windows
KEVunknown

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

EPSS 0.6%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CVE-2026-85880Microsoft Windows
KEVunknown

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

EPSS 0.6%
Recommended action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Uses NVD data but is not endorsed or certified by the NVD. KEV: CISA · EPSS: FIRST.org
Queensland

Warnings & disruptions

Market motion — indexes & movers

^GSPCS&P 500
7,636.36-0.48%
7.8k7.7k7.6k
31 Aug7 days9 Sept
^IXICNasdaq Composite
26,253.34-0.64%
26.6k26.3k26.0k
31 Aug7 days9 Sept
^AXJOS&P/ASX 200
A$8,774-1.54%
9,0708,9068,743
2 Sept7 days10 Sept
US movers · 7 days
NVDANVIDIA
223.67-0.91%
235225215
31 Aug7 days9 Sept
TSLATesla
367.81-0.10%
384366347
31 Aug7 days9 Sept
AAPLApple
315.34-0.28%
331320310
31 Aug7 days9 Sept
MSFTMicrosoft
491.65-0.47%
516503490
31 Aug7 days9 Sept
GOOGLAlphabet
330.65-2.28%
345336328
31 Aug7 days9 Sept
AMZNAmazon
252.4-1.78%
264258251
31 Aug7 days9 Sept
METAMeta Platforms
653.69+6.55%
658607556
31 Aug7 days9 Sept
AMDAdvanced Micro Devices
521.1+3.04%
527484441
31 Aug7 days9 Sept
TSMTaiwan Semiconductor
435.36-0.83%
444426408
31 Aug7 days9 Sept
ARMARM Holdings
264.23+1.03%
275250225
31 Aug7 days9 Sept
ASX ETFs · 7 days
VASVanguard Australian Shares Index ETF
A$110-1.49%
113111109
2 Sept7 days10 Sept
VDHGVanguard Diversified High Growth Index ETF
A$76-0.84%
77.1076.4075.70
2 Sept7 days10 Sept
WBCWestpac Banking
A$34-1.61%
35.2534.4733.69
2 Sept7 days10 Sept
XROXero
A$69-3.42%
84.2376.6269.01
2 Sept7 days10 Sept
WTCWiseTech Global
A$34-1.56%
38.9236.3133.71
2 Sept7 days10 Sept
NXTNEXTDC
A$12-3.67%
13.1212.7012.28
2 Sept7 days10 Sept
Delayed indicators for context only · Not financial advice · US data: Alpha Vantage (Yahoo Finance fallback) · ASX data: Yahoo Finance

Conditions — daily signals

Today in context

Daily signals

Australian dollarUS$0.722Latest reference rate
BitcoinA$108,512Down 0.5% in 24h
Public holidayNoRegular Queensland business day
Daylight5:51 am–5:38 pmSunrise to sunset
System

Source status

18 sources updated successfully.

View all source timestamps
BBC World BBC Technology BleepingComputer Yahoo Finance Bureau of Meteorology MIT Technology Review CISA Open-Meteo Brisbane & Queensland News Krebs on Security The Hacker News Alpha Vantage CoinGecko Frankfurter NVD CISA KEV FIRST EPSS Nager.Date

End of brief. Context shifts — original sources remain the authority.