CISA added CVE-2026-53362 to its KEV catalog, warning of active privilege escalation exploits targeting the Linux Kernel IPv6 networking subsystem across major enterprise distros.
A zero-day exploit dubbed ShieldCrash bypasses Microsoft Defender’s latest patches, weaponizing a TOCTOU race condition in the engine to read files as SYSTEM.
Microsoft’s September 2026 rollup addresses 973 CVEs, including two elevation-of-privilege bugs — in the Windows Update Stack and ALPC — confirmed under active attack.