Pasqualepillitteri.It Tor Network Faces Critical Security Flaws Requiring Immediate Updates
Article Content
- •Tor released critical version 0.4.9.13 on September 23, 2026, with high-severity fixes.
- •The update addresses vulnerabilities affecting all components of the Tor network, including relays and onion services.
- •Users are urged to update immediately, especially those using Tor Browser version 15.0.23, which may lack these fixes.
On September 23, 2026, the Tor Project released version 0.4.9.13 to address high-severity vulnerabilities affecting relays, clients, and onion services. This emergency update follows a prior release on September 8, indicating ongoing security issues. The release notes detail 16 categories of fixes, with 10 vulnerabilities assigned TROVE identifiers, but full technical details are withheld to prevent exploitation. Key issues include potential memory corruption vulnerabilities, which could allow attackers to crash or take control of relays, and flaws that could link browsing activity across sessions, undermining user anonymity. The Tor Project has not confirmed if these vulnerabilities allow remote code execution. Users of the Tor Browser, particularly version 15.0.23, are advised to update to ensure they have the latest security patches. No active exploits have been reported in the wild as of now.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-85491 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2026-93425: Dokploy PaaS Critical RCE Leads to Container Root and Host Compromise TheHackerWire / 1d Telemetry Metric Intelligence Detail CVE Identifier CVE-2026-93425 CVSS Severity 9.9 CRITICAL Affected Target the Dokploy container Vulnerability Class Security Vulnerability Exploit Availability No Public PoC Indexed EPSS Threat Score Awaiting scoring CISA KEV Status Not Listed in CISA KEV Remediation Status Advisory / Mitigation In Review A critical command injection vulnerability, CVE-2026
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…