Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
2026-09-24T19:24:00Z•b79f1ba205505fc769a8cfa19fc9913adb24023a6de6be4f3e339b4f11b92d87
CVE-2026-67279CVE-2026-80521CVE-2026-85046CVE-2026-85880CVE-2026-86060CVE-2026-87491CVE-2026-87902CVE-2026-93616CVE-2026-94127AI securityAndroid malwareClickFixF5 BIG-IPMicrosoft 365MikroTik RouterOSNext.jsTerraformWordPressactive exploitationcontainer escapecredential theftinformation stealermalicious PyPI packagesmalicious npm packagesprivilege escalationremote code executionroot accessspywaresupply-chain compromisezero-day
What happened
The feed reports multiple active and high-impact cybersecurity threats, including exploited zero-days and critical vulnerabilities enabling unauthenticated remote code execution, root access, container escapes, router takeover, and server compromise. It also covers ClickFix social-engineering campaigns, Android spyware, malicious package supply-chain attacks, credential theft, Microsoft 365 account compromise, AI-agent security failures, and alleged data breaches. The most urgent items are active exploitation of WordPress CVE-2026-87902, F5 BIG-IP APM CVE-2026-94127, Chrome/Windows zero-days,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b79f1ba205505fc769a8cfa19fc9913adb24023a6de6be4f3e339b4f11b92d87
- Enrichment time
- 2026-09-24T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.