
Multiple Critical Cybersecurity Vulnerabilities Reported Across Major Security and Enterprise Platforms
Johannes Ullrich from the SANS Internet Storm Center reports on September 4th, 2026 about multiple cybersecurity developments. Nightmare Clips released three new exploits targeting anti-malware products: Falcon Flank against CrowdStrike, Heart Preacher against Kaspersky, and Pretty Prague against Avast, all exploiting privilege escalation vulnerabilities that arise from these products running with elevated privileges while parsing complex file structures. Plex issued an advisory urging immediate updates to version 1.43.3 for servers and 1.115 for desktop, though no CVE numbers or vulnerability details were provided, with particular concern for NAS devices that may require manual updates. Cisco released advisories for iOS XR covering seven vulnerabilities including one with a CVSS score of 9.8 involving remote code execution potential, plus an update for secure email appliances addressing a medium-severity denial of service vulnerability in the S/MIME feature. Horizon 3 reported active exploitation of vulnerabilities in Switchvox, an enterprise VoIP management system from Sangoma, discovered after researchers found issues following previous FreePBX vulnerabilities.