Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 122articles · 30d
  • 1+ day agolatest article
  • Aug 17, 2026earliest in window
  • 9%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 83
  • Software 67
  • Computers & Electronics 60
  • Conflict, War & Peace 32
  • Crime & Law 25
  • News 23
  • Software Dev. 22
  • Internet & Telecom 20

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Google News
thehackernews.com > 2026 > 09 > cisa-flags-exploited-cisco-citrix.html

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

4+ day, 1+ hour ago   (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...

thehackernews.com
thehackernews.com > 2026 > 09 > new-cpanel-flaw-lets-hosting-account.html

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

5+ day, 3+ hour ago   (742+ words) cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there,…...

The Hacker News
thehackernews.com > 2026 > 09 > sap-patches-cvss-100-kernel-flaw.html

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

5+ day, 5+ hour ago   (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...

The Hacker News
thehackernews.com > 2026 > 09 > microsoft-patches-record-974-flaws.html

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

5+ day, 7+ hour ago   (602+ words) Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August,…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-n-central-pre-auth-rce-flaw.html

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

5+ day, 7+ hour ago   (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...

The Hacker News
thehackernews.com > 2026 > 09 > freeipa-flaw-chain-lets-anonymous.html

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

6+ day, 37+ min ago   (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...

The Hacker News
thehackernews.com > 2026 > 09 > adobe-patches-magento-zero-day.html

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

6+ day, 2+ hour ago   (281+ words) Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by…...

The Hacker News
thehackernews.com > 2026 > 09 > telerik-ui-padding-oracle-bug-chained.html

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

1+ week, 56+ min ago   (838+ words) A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-issues-fourth-n-central-hotfix.html

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

1+ week, 3+ hour ago   (737+ words) Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…...

thehackernews.com
thehackernews.com > 2026 > 09 > unpatched-magento-and-adobe-commerce.html

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

1+ week, 1+ day ago   (1468+ words) Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September…...