This briefing covers 9 cybersecurity and geopolitics
stories published around Sunday, September 13, 2026,
and 8 disclosed vulnerabilities
(CVE-2026-15451, CVE-2026-42016, CVE-2026-90493, CVE-2026-90537 and others).
Each entry links to the original reporting.
Solicitor General Sauer's Supreme Court reply brief in the mail ballot case conspicuously avoids arguments analysts expected, signaling a deliberate litigation strategy or internal constraint. The omission may shape how the Court frames federal election authority ahead of a consequential ruling.
A local privilege escalation flaw in Tonec Internet Download Manager's idmwfp.sys kernel driver (CVE-2026-90493, up to v6.42 Build 63) is now publicly exploitable after the vendor ignored disclosure.
CISA added five actively exploited flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS—including CVE-2026-42016 (CVSS 8.1)—to its Known Exploited Vulnerabilities catalog.
zstd-jni versions 1.2.0 through 1.5.7-13 allow attackers to trigger out-of-bounds memory reads via ZstdDictDecompress, potentially crashing the JVM (CVE-2026-90560, CVSS 8.8). Broad adoption of zstd-jni across backend Java services amplifies denial-of-service exposure in production environments.
snappy-java through 1.1.10.8 fails to validate destination buffer capacity in Snappy.uncompress(), enabling out-of-bounds writes and JVM termination via crafted compressed data (CVE-2026-90559, CVSS 8.7).
vLLM before 0.28.0 ignores the trust_remote_code=False parameter in the LlavaOnevision2 processor loader, allowing attacker-controlled model files to execute arbitrary code with vLLM process privileges (CVE-2026-90553, CVSS 8.5).
WWBN AVideo contains a missing authorization flaw in its Scheduler plugin allowing unauthenticated access to email jobs, private content titles, and user email addresses via a predictable daily token (CVE-2026-90537).
MemberPress Corporate Accounts plugin (≤1.5.39) passes raw user data to wp_insert_user without filtering role or ID fields, letting authenticated subscribers escalate privileges to administrator via sub-account creation (CVE-2026-15451).