Skip to content

IT & Security News Feed

Welcome to the ConfigCorner News & Advisory Feed. Below is the unified chronological stream of verified system releases, vendor security bulletins, and CISA Known Exploited Vulnerability disclosures ordered from newest to oldest.


πŸ—‚οΈ Browse by Ecosystem

Prefer deep-dive walkthroughs and mitigation scripts for a specific platform? Jump directly into dedicated stream archives:


πŸ“… Unified Stream (Newest to Oldest)

Latest MilestoneLINUXπŸ›οΈ Source: Kernel.org & Linus Torvalds

πŸ“… October 03, 2026

🐧 Linux Kernel 7.2.9 Released & Linux 7.3 Enters Final Release Candidate Stabilization

Kernel 7.2.97.3-rc5 TreeHardware Enablement

Kernel maintainers released Linux Kernel 7.2.9 for the stable tree, while Linus Torvalds tagged Linux 7.3-rc5 entering final stabilization before late October general release. Linux 7.1 reached official End of Life (EOL).

Latest AdvisoryCYBERSECURITYπŸ›οΈ Source: CISA KEV & Fortinet PSIRT

πŸ“… October 01, 2026

🚨 Fortinet FortiMail Critical Path Traversal & Null Byte Injection Zero-Day (CVE-2026-104286)

CVSS 9.8 CriticalCISA KEV ListedActive Exploitation

CISA added CVE-2026-104286 in Fortinet FortiMail to the Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can write arbitrary files via path traversal and null byte injection to execute code and hijack enterprise mail servers.

Security AdvisoryCYBERSECURITYπŸ›οΈ Source: CISA KEV & Cisco PSIRT

πŸ“… September 30, 2026

🚨 Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)

CVSS 9.8 CriticalSD-WAN ControllerCISA KEV Listed

Added to CISA KEV on September 30, 2026: An improper URI hex encoding vulnerability allows unauthenticated remote attackers to bypass API authentication gates and take full administrative control over Cisco Catalyst SD-WAN Manager (vManage) controllers.

Latest ReleaseWINDOWSπŸ›οΈ Source: Windows IT Pro Blog

πŸ“… September 29, 2026

πŸͺŸ Windows 11 Version 26H2 Release, JIT Administrator Protection & Server 2025 RDS Hotfixes

Feature Update 26H2Server 2025 RDSJIT Elevation

Microsoft rolled out Windows 11 Version 26H2 with mandatory Just-In-Time Administrator Protection tokens that kill privilege persistence, alongside emergency Server 2025 RDS stability updates.

Previous AdvisoryLINUXπŸ›οΈ Source: Canonical & Ubuntu Discourse

πŸ“… September 28, 2026

🐧 Canonical Unlocks Ubuntu 24.04 to 26.04.1 LTS Upgrade Path & Weekly Kernel Cadence

Ubuntu 26.04.1 LTSSystemd 262Weekly Kernel Stream

Canonical unlocked the direct distribution upgrade path from Ubuntu 24.04 LTS to Ubuntu 26.04.1 LTS, featuring systemd 262, statically linked microVM executors, and weekly enterprise security kernel patch cadences.

Previous AdvisoryCYBERSECURITYπŸ›οΈ Source: CISA KEV & Cloud Software Group

πŸ“… September 27, 2026

🚨 Citrix NetScaler ADC & Gateway Remote Code Execution Zero-Days (CVE-2026-88771 & CVE-2026-88772)

CVSS 9.5 CriticalCISA KEV ListedActive Exploitation

Added to the CISA KEV catalog on September 27, 2026: Critical vulnerabilities affecting NetScaler ADC and Gateway appliances allowing memory corruption in AAA-TM and persistent root web shell implantation.

Previous AdvisoryWINDOWSπŸ›οΈ Source: CISA KEV & Microsoft MSRC

πŸ“… September 25, 2026

πŸͺŸ Microsoft SharePoint Server Authenticated Remote Code Execution (CVE-2026-65660)

CVSS 8.8 HighCISA KEV ListedActive Exploit

Added to CISA KEV on September 25, 2026: An on-premises SharePoint Server code injection defect allowing authenticated users to trigger server-side code execution in the context of the IIS worker process (w3wp.exe).

Previous AdvisoryCYBERSECURITYπŸ›οΈ Source: CISA KEV & MikroTik Security

πŸ“… September 25, 2026

🚨 MikroTik RouterOS Administrative Control Takeover (CVE-2026-67279)

CVSS 6.9 WarningCISA KEV ListedEdge Routers

Added to CISA KEV on September 25, 2026: An improper workflow enforcement flaw in MikroTik RouterOS exploited in chained attacks to alter routing tables and implant rogue WinBox proxy accounts.

Security AdvisoryLINUXπŸ›οΈ Source: Red Hat Product Security

πŸ“… September 19, 2026

🐧 Four Linux Kernel Network-Stack Privilege Escalation Flaws (CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 & CVE-2026-74469)

Important SeverityLocal Privilege EscalationRHEL & OpenShift

Red Hat’s September 19 advisory covers four Linux kernel networking flaws that can allow local privilege escalation when their prerequisites are met. Fix availability varies by product stream; the bulletin was updated September 26. Read the Red Hat advisory.

Security AdvisoryWINDOWSπŸ›οΈ Source: Microsoft MSRC & CISA KEV

πŸ“… September 15, 2026

πŸͺŸ Windows September 2026 Patch Tuesday Zero-Days: ALPC & Update Stack Privilege Escalations (CVE-2026-85880 & CVE-2026-81963)

CVSS 7.8CISA KEV ListedActive Zero-Days

Detailed breakdown of Microsoft’s September 2026 Patch Tuesday addressing actively exploited Elevation of Privilege flaws in the Windows ALPC IPC mechanism and Windows Update Stack file writing procedures.

Distro ReleaseLINUXπŸ›οΈ Source: Debian Security & Release Team

πŸ“… September 12, 2026

🐧 Debian 13.7 β€œTrixie” Point Release Deployed & systemd v262 Signed

Debian 13.7systemd v262Security Servicing

The Debian Project released point update Debian 13.7 delivering cumulative CVE patches and system corrections across stable installation media. Concurrently, systemd v262 was signed and tagged upstream.

Comments