2026-09-19
This weekWeb3 security community alerts and advisories in the last 48 hours
In the past 48 hours, the Web3 security community has been actively addressing several critical vulnerabilities across multiple platforms. Notably, SAP products faced severe CVEs that could enable arb…
RESEARCH: Web3 security community alerts and advisories in the last 48 hours
RESEARCH: Web3 Security Community Alerts and Advisories (Last 48 Hours)
Summary
In the past 48 hours, the Web3 security community has been actively addressing several critical vulnerabilities across multiple platforms. Notably, SAP products faced severe CVEs that could enable arbitrary code execution and data manipulation, urging immediate patching. Meanwhile, n8n, an open-source workflow automation tool, disclosed three high-severity vulnerabilities (CVE-2025-68613, CVE-2026-21877, and CVE-2026-21858) allowing unauthenticated remote code execution and unauthorized file access, with CISA marking some as known exploited. Additionally, job postings for senior Web3 product designers highlight the industry's demand for experienced designers to enhance DeFi and fintech/Web3 interfaces.
Key Developments
- September 9, 2026 — SAP released security updates addressing multiple vulnerabilities (CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768) affecting various SAP products. These vulnerabilities have high CVSS scores (ranging from 9.0 to 10.0), posing significant risks to confidentiality, integrity, and availability. Users are advised to update immediately. Critical Vulnerabilities in SAP Products | Cyber Security Agency of Singapore
- September 11, 2026 — CISA added one known exploited vulnerability to its catalog, indicating active exploitation in the wild. CISA Adds One Known Exploited Vulnerability to Catalog
- September 14, 2026 — CISA updated advisories, adding three known exploited vulnerabilities to their catalog, emphasizing ongoing threats. CISA Adds Three Known Exploited Vulnerabilities to Catalog
- September 15, 2026 — CISA added two more known exploited vulnerabilities to the catalog, reinforcing vigilance among stakeholders. CISA Adds Two Known Exploited Vulnerabilities to Catalog
- January 15, 2026 — WA Cyber Security Advisory highlighted multiple critical vulnerabilities in n8n (CVE-2025-68613, CVE-2026-21877, CVE-2026-21858), with CVSS scores of 9.9 to 10.0, classified as Critical. CISA added some to the Known Exploited Vulnerability catalog. N8N Multiple Critical Vulnerabilities - 20260115001 - WA Cyber
- Various Dates — Job postings for Senior Web3 Product Designers emerged, underscoring the demand for experienced designers in DeFi and fintech/Web3 sectors. Senior Web3 Product Designer - Behance and Web3 Designer - Behance
Sources
- Critical Vulnerabilities in SAP Products | Cyber Security Agency of Singapore
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Adds Three Known Exploited Vulnerabilities to Catalog
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- N8N Multiple Critical Vulnerabilities - 20260115001 - WA Cyber
- Senior Web3 Product Designer - Behance
- Web3 Designer - Behance