IT & Security News Feed
Welcome to the ConfigCorner News & Advisory Feed. Below is the unified chronological stream of verified system releases, vendor security bulletins, and CISA Known Exploited Vulnerability disclosures ordered from newest to oldest.
ποΈ Browse by Ecosystem
Prefer deep-dive walkthroughs and mitigation scripts for a specific platform? Jump directly into dedicated stream archives:
π Unified Stream (Newest to Oldest)
π October 03, 2026
π§ Linux Kernel 7.2.9 Released & Linux 7.3 Enters Final Release Candidate Stabilization
Kernel maintainers released Linux Kernel 7.2.9 for the stable tree, while Linus Torvalds tagged Linux 7.3-rc5 entering final stabilization before late October general release. Linux 7.1 reached official End of Life (EOL).
π October 01, 2026
π¨ Fortinet FortiMail Critical Path Traversal & Null Byte Injection Zero-Day (CVE-2026-104286)
CISA added CVE-2026-104286 in Fortinet FortiMail to the Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can write arbitrary files via path traversal and null byte injection to execute code and hijack enterprise mail servers.
π September 30, 2026
π¨ Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)
Added to CISA KEV on September 30, 2026: An improper URI hex encoding vulnerability allows unauthenticated remote attackers to bypass API authentication gates and take full administrative control over Cisco Catalyst SD-WAN Manager (vManage) controllers.
π September 29, 2026
πͺ Windows 11 Version 26H2 Release, JIT Administrator Protection & Server 2025 RDS Hotfixes
Microsoft rolled out Windows 11 Version 26H2 with mandatory Just-In-Time Administrator Protection tokens that kill privilege persistence, alongside emergency Server 2025 RDS stability updates.
π September 28, 2026
π§ Canonical Unlocks Ubuntu 24.04 to 26.04.1 LTS Upgrade Path & Weekly Kernel Cadence
Canonical unlocked the direct distribution upgrade path from Ubuntu 24.04 LTS to Ubuntu 26.04.1 LTS, featuring systemd 262, statically linked microVM executors, and weekly enterprise security kernel patch cadences.
π September 27, 2026
π¨ Citrix NetScaler ADC & Gateway Remote Code Execution Zero-Days (CVE-2026-88771 & CVE-2026-88772)
Added to the CISA KEV catalog on September 27, 2026: Critical vulnerabilities affecting NetScaler ADC and Gateway appliances allowing memory corruption in AAA-TM and persistent root web shell implantation.
π September 25, 2026
πͺ Microsoft SharePoint Server Authenticated Remote Code Execution (CVE-2026-65660)
Added to CISA KEV on September 25, 2026: An on-premises SharePoint Server code injection defect allowing authenticated users to trigger server-side code execution in the context of the IIS worker process (w3wp.exe).
π September 25, 2026
π¨ MikroTik RouterOS Administrative Control Takeover (CVE-2026-67279)
Added to CISA KEV on September 25, 2026: An improper workflow enforcement flaw in MikroTik RouterOS exploited in chained attacks to alter routing tables and implant rogue WinBox proxy accounts.
π September 19, 2026
π§ Four Linux Kernel Network-Stack Privilege Escalation Flaws (CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 & CVE-2026-74469)
Red Hatβs September 19 advisory covers four Linux kernel networking flaws that can allow local privilege escalation when their prerequisites are met. Fix availability varies by product stream; the bulletin was updated September 26. Read the Red Hat advisory.
π September 15, 2026
πͺ Windows September 2026 Patch Tuesday Zero-Days: ALPC & Update Stack Privilege Escalations (CVE-2026-85880 & CVE-2026-81963)
Detailed breakdown of Microsoftβs September 2026 Patch Tuesday addressing actively exploited Elevation of Privilege flaws in the Windows ALPC IPC mechanism and Windows Update Stack file writing procedures.
π September 12, 2026
π§ Debian 13.7 βTrixieβ Point Release Deployed & systemd v262 Signed
The Debian Project released point update Debian 13.7 delivering cumulative CVE patches and system corrections across stable installation media. Concurrently, systemd v262 was signed and tagged upstream.