Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

2026-09-24T19:24:00Z•b79f1ba205505fc769a8cfa19fc9913adb24023a6de6be4f3e339b4f11b92d87
CVE-2026-67279CVE-2026-80521CVE-2026-85046CVE-2026-85880CVE-2026-86060CVE-2026-87491CVE-2026-87902CVE-2026-93616CVE-2026-94127AI securityAndroid malwareClickFixF5 BIG-IPMicrosoft 365MikroTik RouterOSNext.jsTerraformWordPressactive exploitationcontainer escapecredential theftinformation stealermalicious PyPI packagesmalicious npm packagesprivilege escalationremote code executionroot accessspywaresupply-chain compromisezero-day

What happened

The feed reports multiple active and high-impact cybersecurity threats, including exploited zero-days and critical vulnerabilities enabling unauthenticated remote code execution, root access, container escapes, router takeover, and server compromise. It also covers ClickFix social-engineering campaigns, Android spyware, malicious package supply-chain attacks, credential theft, Microsoft 365 account compromise, AI-agent security failures, and alleged data breaches. The most urgent items are active exploitation of WordPress CVE-2026-87902, F5 BIG-IP APM CVE-2026-94127, Chrome/Windows zero-days,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b79f1ba205505fc769a8cfa19fc9913adb24023a6de6be4f3e339b4f11b92d87
Enrichment time
2026-09-24T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.