Exploited in the wild LocalAI CL-CRI-1171 ransomware VMware vCenter Palo Alto Networks
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
CVE Tools coverage
This ThreatsDay roundup reports ransomware exploitation of VMware vCenter flaw CVE-2026-59310, while Cisco Talos-linked reporting covers attacks involving Cisco Secure FMC vulnerabilities CVE-2026-20079 and CVE-2026-20316. Palo Alto Networks and Oasis Security also detailed campaigns abusing malware distribution channels and exposed LocalAI deployments, including root-level command execution and credential theft. Oracle released its September 2026 Critical Security Patch Update for more than 800 vulnerabilities, none identified as actively exploited.