Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

2026-09-15T08:51:36Z•b4b357aa95fb79a82aa08b7350e5757016a9707dac4bb5f2cf8fe05eab3add43
CVE-2026-42016CVE-2026-85706AI-assisted cyberattacksCISA KEVCheck Point VPNConnectWise ScreenConnectGitLabJFrog ArtifactoryTelegram DesktopVPN breachactive exploitationdata theftgovernment systemsmalwarepath traversalstored XSSunauthenticated accessvulnerabilities

What happened

Security Affairs reporting covers actively exploited and high-impact vulnerabilities, including a critical unauthenticated GitLab path traversal (CVE-2026-85706), JFrog Artifactory, ConnectWise ScreenConnect, and Check Point VPN flaws, plus a Telegram Desktop stored XSS issue affecting exported chat HTML. Additional items discuss a Japanese government VPN breach, malware activity, and the accelerating role of frontier AI in cyberattacks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b4b357aa95fb79a82aa08b7350e5757016a9707dac4bb5f2cf8fe05eab3add43
Enrichment time
2026-09-15T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.