2026-09-17
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilitiesCVE-2026-91752
CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2
GNU libextractor before version 1.15 contains a stack-based buffer overflow in the OLE2 plugin, specifically in the process_star_office function that allocates stack memory based on attacker-controlled data. CVE-2026-91752 affects the library's handling of malicious OLE2 stream input.
Why it matters: Organizations and developers using GNU libextractor versions prior to 1.15 to process potentially untrusted OLE2 files face remote code execution risk and should upgrade immediately.
- ransomware
Canada: Nipigon hospital hit by ransomware attack
Nipigon District Memorial Hospital in Canada reported a cyber security incident involving ransomware that affected its information technology systems. The hospital indicated that some patient services may be disrupted as it responds to the attack.
Why it matters: Healthcare providers and their patients face service disruptions and data exposure risk; practitioners should monitor for indicators of compromise from this incident and review incident response readiness.