Daily Briefing

Cybersecurity & Geopolitics Briefing — Sunday, September 13, 2026

Geopolitical cyber intelligence in 5 minutes
Sunday, September 13, 2026 · 9 stories

This briefing covers 9 cybersecurity and geopolitics stories published around Sunday, September 13, 2026, and 8 disclosed vulnerabilities (CVE-2026-15451, CVE-2026-42016, CVE-2026-90493, CVE-2026-90537 and others). Each entry links to the original reporting.

Share this digest:

U.S. Solicitor General's Supreme Court Mail Ballot Brief Omits Key Legal Arguments (1 minute read)

Solicitor General Sauer's Supreme Court reply brief in the mail ballot case conspicuously avoids arguments analysts expected, signaling a deliberate litigation strategy or internal constraint. The omission may shape how the Court frames federal election authority ahead of a consequential ruling.

Just Security · 10h ago · Read full article →

CVE-2026-90493: Tonec IDM Kernel Driver Exploit Goes Public After Vendor Silence (3 minute read)

A local privilege escalation flaw in Tonec Internet Download Manager's idmwfp.sys kernel driver (CVE-2026-90493, up to v6.42 Build 63) is now publicly exploitable after the vendor ignored disclosure.

CVE Feed (High Severity) · 9h ago · Read full article →

CISA Adds CVE-2026-42016 and 4 More Actively Exploited Flaws to KEV Catalog (1 minute read)

CISA added five actively exploited flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS—including CVE-2026-42016 (CVSS 8.1)—to its Known Exploited Vulnerabilities catalog.

The Hacker News · 20h ago · Read full article →

CVE-2026-90647: Kalkitech ASE2000 IEC 60870-5-104 TLS Flaw Enables Industrial MitM (2 minute read)

A CVSS 9.1 certificate validation bypass in Kalkitech ASE2000 V2 (versions 2.35–2.37) allows network-positioned attackers to intercept IEC 60870-5-104 TLS-protected communications via malformed multi-fault certificates.

CVE Feed (High Severity) · 13h ago · Read full article →

CVE-2026-90560: zstd-jni Out-of-Bounds Read Threatens JVM Stability Across Java Ecosystem (2 minute read)

zstd-jni versions 1.2.0 through 1.5.7-13 allow attackers to trigger out-of-bounds memory reads via ZstdDictDecompress, potentially crashing the JVM (CVE-2026-90560, CVSS 8.8). Broad adoption of zstd-jni across backend Java services amplifies denial-of-service exposure in production environments.

CVE Feed (High Severity) · 18h ago · Read full article →

CVE-2026-90559: snappy-java Out-of-Bounds Write Allows JVM Crash via Compressed Input (2 minute read)

snappy-java through 1.1.10.8 fails to validate destination buffer capacity in Snappy.uncompress(), enabling out-of-bounds writes and JVM termination via crafted compressed data (CVE-2026-90559, CVSS 8.7).

CVE Feed (High Severity) · 18h ago · Read full article →

CVE-2026-90553: vLLM RCE Flaw Executes Malicious Model Code Despite Safety Flag (2 minute read)

vLLM before 0.28.0 ignores the trust_remote_code=False parameter in the LlavaOnevision2 processor loader, allowing attacker-controlled model files to execute arbitrary code with vLLM process privileges (CVE-2026-90553, CVSS 8.5).

CVE Feed (High Severity) · 23h ago · Read full article →

CVE-2026-90537: WWBN AVideo Unauthenticated Authorization Bypass Exposes Scheduler Data (2 minute read)

WWBN AVideo contains a missing authorization flaw in its Scheduler plugin allowing unauthenticated access to email jobs, private content titles, and user email addresses via a predictable daily token (CVE-2026-90537).

CVE Feed (High Severity) · 23h ago · Read full article →

CVE-2026-15451: MemberPress WordPress Plugin Lets Subscribers Escalate to Admin (3 minute read)

MemberPress Corporate Accounts plugin (≤1.5.39) passes raw user data to wp_insert_user without filtering role or ID fields, letting authenticated subscribers escalate privileges to administrator via sub-account creation (CVE-2026-15451).

CVE Feed (High Severity) · 23h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now