Microsoft has disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker that could allow an authorized local attacker to execute arbitrary code. The flaw is classified as a heap-based buffer overflow (CWE-122) and carries a CVSS 3.1 score of 6.7. Microsoft published the vulnerability details on September 8, 2026. The vulnerability exists in Windows BitLocker and results from improper handling of heap memory. A heap-based buffer overflow occurs when data is written beyond an allocated memory region, potentially corrupting adjacent memory and altering program execution. In this case, exploitation requires local access, low attack complexity, high privileges, and no user interaction. The CVSS vector is AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. Despite being described as a remote code execution vulnerability, the attack vector is local rather than network-based. An attacker would therefore need an existing privileged foothold on the system before attempting exploitation. Successful exploitation could affect confidentiality, integrity, and availability, making the flaw particularly relevant to post-compromise scenarios.
Healthcare technology provider Veradigm disclosed a data breach involving a third-party vendor after attackers obtained vendor credentials that provided access to a limited Veradig...
A sophisticated, multi-stage malware campaign has been observed combining fake Google CAPTCHA verification pages, WebDAV infrastructure, malicious Cloudflare Workers and BNB Smart ...
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) Software with CVSS score ...