September 15, 2026
- An Apache HTTP Server PoC is public for CVE-2026-42536. The PoC repository demonstrates a heap overflow in mod_xml2enc’s
xml2StartParsehandling of untrusted content; no in-the-wild use is reported. · New Tools & Releases
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents