← All stories
● Covered by 10 sources · 273 reportsHigh impact170 negative79 neutral

Adobe Patches Critical ColdFusion and Campaign Classic Vulnerabilities Amid Exploits

🔄 Updated 1h ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Adobe patched 13 critical ColdFusion vulnerabilities, with one (CVE-2026-48282) exploited within hours.
  • SAP released 20 security notes, including critical flaws in NetWeaver and Approuter.
  • SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) were exploited for weeks before patches.
  • Joomla extensions iCagenda and Balbooa Forms have actively exploited zero-day RCE flaws.
  • CISA added multiple vulnerabilities to its KEV catalog, mandating federal agency patching.
  • n8n patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m).
  • The n8n flaw allowed authenticated workflow editors to execute OS commands.
  • Security Joes found the n8n vulnerability while probing a February fix for CVE-2026-27577.
  • Affected n8n versions are <2.31.5 and >=2.32.0,<2.32.1.
  • n8n fixed the flaw in versions 2.31.5 and 2.32.1.
  • The n8n vulnerability has a CVSS 4.0 score of 8.7.
  • Exploitation of the n8n flaw requires a valid account with workflow editing permissions.
  • A public exploit for vBulletin CVE-2026-61511 was released on July 27.
  • The vBulletin flaw affects versions 6.2.1 and earlier, and 6.1.6 and earlier.
  • vBulletin released fixed version 6.2.2 on July 1.
  • The vBulletin exploit requires no user interaction or authentication.
  • vBulletin Cloud sites have already been patched against the flaw.
  • Arista patched a maximum-severity command injection vulnerability (CVE-2026-16812) in VeloCloud Orchestrator.
  • The VeloCloud Orchestrator flaw allows unauthenticated remote attackers to compromise the orchestrator and its managed data.
  • The VeloCloud Orchestrator vulnerability has a CVSS score of 10.0.
  • VeloCloud Orchestrator is a centralized management platform for VeloCloud SD-WAN deployments.
  • The flaw allows remote attackers to access privileged functionality intended for internal use.
  • No VCO tenant or operator credentials are needed to exploit the flaw.
  • Arista discovered CVE-2026-16812 externally.
  • The VeloCloud Orchestrator flaw affects on-premises versions.
  • The flaw was addressed in hosted and dedicated VCO versions earlier.
  • Affected VCO versions include 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1.
  • Arista released patches for the VeloCloud Orchestrator vulnerability on Monday.
  • The VeloCloud Orchestrator flaw is an OS injection vulnerability.
  • JetBrains released updates for a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises.
  • The TeamCity flaw allows unauthenticated attackers to execute arbitrary OS commands.
  • The TeamCity vulnerability affects all TeamCity On-Premises versions.
  • The TeamCity flaw was addressed in versions 2025.11.7 and 2026.1.3.
  • TeamCity Cloud instances have already been updated for the flaw.
  • Antoni Tremblay discovered and reported the TeamCity flaw on July 10, 2026.
  • The TeamCity vulnerability has a CVSS score of 9.8.
  • The TeamCity flaw allows unauthenticated remote code execution via the agent polling protocol.
  • Attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
  • The macOS Screen Sharing flaw allows attackers to gain root access and install Monero cryptocurrency miners.
  • The macOS vulnerability affects Macs with port 5900 exposed to the Internet.
  • Apple patched the macOS flaw on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • CISA raised the CVSS score of the macOS flaw from 7.1 to 9.8 on August 14.
  • The Dutch National Cyber Security Centre (NCSC-NL) reported the macOS exploitation on August 12.
  • NCSC-NL first flagged the macOS vulnerability in an advisory on August 7.
  • Public proof-of-concept code is available for the macOS Screen Sharing flaw.
  • Technical details of the macOS bug were presented at Black Hat conference.
  • SAP Commerce Cloud vulnerability CVE-2026-58231 was exploited three days after disclosure.
  • The SAP Commerce Cloud flaw has a CVSS score of 10.
  • SAP released patches for CVE-2026-58231 on August 11.
  • Defused honeypots observed exploitation attempts for the SAP Commerce Cloud flaw on August 14.
  • A public PoC exploit for the SAP Commerce Cloud flaw became available on August 15.
  • The SAP Commerce Cloud vulnerability allows arbitrary code execution and compromise of internal components.
  • Apple improved state management mechanisms to fix the macOS Screen Sharing flaw.
  • GeoServer has a zero-day SQL injection vulnerability (GHSA-mqjf-5f49-2fjh) with a CVSS score of 9.8.
  • The GeoServer flaw was disclosed on August 12, 2026, by @q1uf3ng on X.
  • The GeoServer vulnerability allows RCE in the case of a system administrator database.
  • GeoServer exploitation attempts were observed within hours of public disclosure.
  • GeoServer released versions 3.0.1, 2.28.5, and 2.27.6 to address the flaw.
  • Alfredo Pesoli of Bynario discovered and reported the macOS Screen Sharing flaw.
  • The SAP Commerce Cloud flaw (CVE-2026-58231) is due to insufficient authorization checks and input validation.
  • The SAP Commerce Cloud flaw allows an unauthenticated attacker to abuse a default authentication client.
  • A suspected China-nexus APT is exploiting a Broadcom VMware vCenter flaw (CVE-2026-59310).
  • The VMware vCenter flaw is a directory-traversal vulnerability.
  • Broadcom released a fix for the VMware vCenter flaw on July 29, 2026.
  • The VMware vCenter exploitation campaign has compromised 361 unique IP addresses across 47 countries.
  • QUIRSO attributed the VMware vCenter exploitation to a Chinese-speaking threat actor.
  • The VMware vCenter flaw (CVE-2026-59310) has a CVSS score of 9.8.
  • Exploitation of the VMware vCenter flaw can lead to arbitrary code execution.
  • The VMware vCenter exploitation led to deployment of a backdoor and reverse SSH binary.
  • The VMware vCenter exploitation ultimately led to deployment of Babuk-derived ransomware.
  • CISA added Ray vulnerability CVE-2025-62593 to its KEV catalog on Monday.
  • The Ray vulnerability CVE-2025-62593 has a CVSS score of 9.4.
  • The Ray flaw allows RCE via DNS rebinding attacks in Firefox and Safari.
  • Ray is an open-source, Python-native distributed computing framework.
  • Ray has over 43,500 stars and 7,900 forks on GitHub.
  • Ray maintainers issued an advisory in November 2025 about the flaw.
  • The Ray flaw stems from a lack of authentication on critical endpoints like /api/jobs.
  • Attackers are exploiting MLflow SSRF flaw (CVE-2026-64849) to steal cloud credentials and secrets.
  • MLflow vulnerability CVE-2026-64849 has a CVSS score of 9.3.
  • MLflow flaw CVE-2026-64849 affects versions < 3.15.0.
  • FUXA, an open-source SCADA/HMI software, has a vulnerability (CVE-2026-25895) with a CVSS score of 9.5.
  • FUXA flaw CVE-2026-25895 allows unauthenticated remote attackers to write arbitrary files and achieve RCE.
  • FUXA vulnerability CVE-2026-25895 affects versions <= 1.2.9.
  • Citrix released patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway.
  • The critical Citrix flaw is CVE-2026-19490, with a CVSS score of 9.3.
  • The Citrix flaw affects NetScaler appliances configured as a gateway or an AAA virtual server.
  • The Citrix flaw impacts NetScaler ADC and NetScaler Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS.
  • Citrix fixed the flaw in versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1-37.277.
  • The second Citrix vulnerability is CVE-2026-19489, a high-severity memory overflow issue.
  • CVE-2026-19489 could lead to DoS if SIP ALG is enabled at an LSN group configuration.
  • Secure Private Access Hybrid deployments using NetScaler instances are also affected.
  • Zimbra RCE flaw (CVE-2026-73570) allows unauthenticated attackers to execute OS commands.
  • Zimbra security team released version 10.1.20 on July 20 to patch CVE-2026-73570.
  • The Zimbra flaw is a command injection weakness in the SNMP monitoring component.
  • Shadowserver tracks over 12,100 Zimbra servers exposed online.
  • MLflow is an open-source AI engineering platform for LLMs and agents.
  • MLflow has over 30 million monthly downloads.
  • The MLflow flaw is a DNS-rebinding server-side request forgery (SSRF) bypass.
  • The MLflow flaw allows unauthenticated attackers to access internal services or cloud metadata configurations.
  • Cisco patched 15 vulnerabilities across its products.
  • Cisco Crosswork version 7.2.1-SP fixed four critical CVEs.
  • Cisco Secure Workload versions 4.0.4.16 and 3.10.9.1 fixed five CVEs.
  • The critical Citrix flaw (CVE-2026-19490) allows authentication bypass when SAML Action is configured.
  • Atlassian patched 10 critical and 162 high-severity issues in third-party dependencies.
  • Splunk patched at least 150 vulnerabilities across its products.
  • The Zimbra flaw (CVE-2026-73570) has a CVSS score of 8.9.
  • The Zimbra flaw requires the optional zimbra-snmp package to be installed and SNMP notifications enabled.
  • CERT Polska observed active exploitation of the Zimbra flaw this week.
  • The isolated-vm flaw (GHSA-864f-rcv7-6rh4) affects all versions before and including 7.0.0.
  • The isolated-vm flaw was patched in versions 6.2.0 and 7.0.1.
  • Isolated-vm is a Node.js library for running untrusted JavaScript inside a V8 Isolate.
  • The isolated-vm flaw allows untrusted JavaScript to escape its sandboxed environment.
  • The isolated-vm flaw could lead to host memory corruption.
  • The critical Citrix flaw (CVE-2026-19490) affects SecurAccess ZTNA Hybrid deployments.
  • The Citrix vulnerabilities do not apply to Citrix-managed cloud services or Adaptive Authentication.
  • Cisco patched nine vulnerabilities in Crosswork and Secure Workload.
  • Five Cisco vulnerabilities have a CVSS score of 10.0.
  • Cisco Crosswork flaws include SQL injection (CVE-2026-20030), missing authentication (CVE-2026-20357), and external control of file system (CVE-2026-20358).
  • Cisco Crosswork also has an insufficiently protected credentials flaw (CVE-2026-20359) with a CVSS of 9.9.
  • Cisco Crosswork vulnerabilities affect Release version 7.2.1 and earlier.
  • Cisco Secure Workload has improper neutralization of special elements flaws (CVE-2026-20231) with a CVSS of 9.9.
  • CISA mandated US government agencies patch the Zimbra flaw within three days.
  • Keycloak vulnerability CVE-2026-18963 allows unauthenticated attackers to reset any user's password.
  • Keycloak flaw CVE-2026-18963 has a CVSS score of 9.1.
  • Keycloak flaw CVE-2026-18963 is classified as CWE-640 (weak password recovery mechanism).
  • Keycloak fixed the flaw in versions 26.7.2, 26.4.15, and 26.6.6.
  • The Keycloak flaw has no evidence of exploitation or public exploit as of August 24, 2026.
  • The Keycloak flaw is due to improper state validation in the reset-credentials authentication flow.
  • Spring application framework released updates patching 91 vulnerabilities.
  • Spring framework's critical vulnerability is CVE-2026-59270.
  • CVE-2026-59270 affects Spring Security's embedded UnboundID LDAP server.
  • CVE-2026-59270 allows an attacker to authenticate and modify entries in the in-memory directory.
  • Sonatype found Spring patches impact over 200,000 software components.
  • A Calix GS7 XGS (GS5239XG) residential router vulnerability (CVE-2026-75501) allows remote, unauthenticated attackers to create port-forwarding rules.
  • The Calix flaw bypasses NAT and exposes local network devices.
  • The Calix flaw affects devices running EXOS/6.6.47 firmware.
  • Brian Khan Quintana discovered the Calix flaw and reported it to CERT/CC.
  • Calix is a vendor for Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
  • The affected Calix model GS5239XG is also marketed as the GigaSpire 7u10txg.
  • The Calix GigaSpire 7u10txg combines Wi-Fi 7 with an integrated XGS-PON fiber terminal.
  • The Calix vulnerability is caused by the device exposing "the MiniUPnPd contr".
  • CISA added Oracle WebLogic flaw CVE-2026-21962 to KEV catalog on August 24.
  • Federal agencies must patch Oracle WebLogic flaw CVE-2026-21962 by August 27.
  • Oracle WebLogic flaw CVE-2026-21962 is a remote code execution vulnerability.
  • Oracle WebLogic flaw CVE-2026-21962 affects Oracle HTTP Server and WebLogic Server Proxy plugin.
  • Oracle WebLogic flaw CVE-2026-21962 has been exploited since January 2026.
  • CloudSEK first flagged exploitation attempts for Oracle WebLogic flaw CVE-2026-21962.
  • Over 270 Zimbra Collaboration Suite instances were compromised.
  • Zimbra is used by hundreds of millions of people and organizations.
  • CERT Polska warned security teams to check logs for suspicious activity.
  • CISA added the Zimbra flaw to its KEV catalog following CERT Polska's warning.
  • Marimo patched a high-severity vulnerability (CVE-2026-75149) in its notebook software.
  • The Marimo flaw allowed arbitrary Model Context Protocol (MCP) commands to execute as a local subprocess.
  • The Marimo flaw affects versions prior to 0.23.15.
  • The Marimo flaw allowed code injection before any notebook cells ran.
  • The Marimo flaw has a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8.
  • The Marimo flaw was published on August 19.
  • The Marimo flaw is caused by a crafted notebook supplying an attacker-controlled MCP server command through notebook configuration.
  • Marimo's PEP 723 hardening patch treats notebook metadata as attacker-controlled.
  • CERT/CC disclosed two unpatched Kaltura mwEmbed vulnerabilities, CVE-2026-19913 and CVE-2026-19912.
  • Kaltura mwEmbed flaws allow unauthenticated remote attackers to read files and execute code.
  • Kaltura mwEmbed vulnerabilities stem from unsafe deserialization in mwEmbedLoader.php endpoint.
  • Kaltura mwEmbed vulnerabilities affect individual customer installations and Kaltura's shared CDN infrastructure.
  • CERT/CC was unable to reach Kaltura to coordinate the mwEmbed vulnerabilities.
  • Administrators should restrict or disable external access to mwEmbedLoader.php and enforce an allow-list for ServiceUrl parameter.
  • Ubiquiti patched three maximum-severity vulnerabilities in UniFi Protect, UniFi Talk, and UniFi OS.
  • Ubiquiti UniFi Protect flaw is an authentication bypass (CVE-2026-77551).
  • Ubiquiti UniFi OS has a CRLF injection flaw (CVE-2026-77550) allowing authentication bypass.
  • Ubiquiti UniFi Talk has a command injection flaw (CVE-2026-77554) due to improper input validation.
  • Ubiquiti fixed flaws in UniFi Protect Application 7.2.105+, UniFi Talk Application 5.3.2+, and UniFi OS Server 5.1.21 and earlier.
  • Avada WordPress theme flaw is a chain of six security issues.
  • Avada WordPress theme flaw involves authorization, input-validation, trust-boundary, and file-handling weaknesses.
  • Avada WordPress theme flaw allows full website compromise.
  • Avada WordPress theme flaw was reported by Defiant's Wordfence team.
  • CISA issued an urgent directive for government organizations to patch CVE-2026-8452.
  • The Citrix vulnerability is tracked as CVE-2026-8452.
  • Citrix announced patches for CVE-2026-8452 on June 30.
  • Versions 14.1-72.61 (FIPS), 13.1-63.18, and 13.1-37.272 fix CVE-2026-8452.
  • WatchTowr demonstrated CVE-2026-8452 allows unauthenticated remote code execution.
  • WatchTowr made details and PoC code for CVE-2026-8452 public on August 14.
  • Previdian and Defused observed in-the-wild exploitation of CVE-2026-8452.
  • Attackers dropped a web shell and executed discovery commands via CVE-2026-8452.
  • CISA added six flaws to its KEV catalog on Wednesday.
  • The critical Citrix flaw affects NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers.
  • Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.
  • Next.js has two critical RCE flaws: one in AVIF image processing, another a Windows path traversal.
  • The Windows path traversal flaw is CVE-2026-75604 with a CVSS score of 9.0.
  • The Windows path traversal flaw affects Next.js applications using Pages Router and App Router without Cache Components.
  • The Windows path traversal flaw only affects servers using a Windows filesystem.
  • Next.js fixes are available in versions 15.5.24 and 16.3.3, published August 25, 2026.
  • The AVIF flaw affects Next.js versions 13.4 through 15.5.
  • Vercel-hosted applications are protected from both Next.js vulnerabilities.
  • cPanel patched CVE-2026-65643, allowing authenticated users to achieve root code execution.
  • The cPanel flaw affects domain parking and addon domain functionality.
  • cPanel patched versions 11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, and 11.138.1.7+ (WP Squared).
  • ServiceNow patched three maximum-severity AI Platform vulnerabilities.
  • The ServiceNow flaws include code injection (CVE-2026-18885), privilege escalation (CVE-2026-18886), and SQL injection (CVE-2026-74820).
  • The ServiceNow flaws can be exploited by unauthenticated attackers with low complexity and no user interaction.
  • ServiceNow AI Platform is used by 85% of Fortune 500 companies.
  • VulnCheck discovered two factory implants, SPEAKINGSTONE and DARKLANTERN, in ZBT router firmware.
  • The ZBT router implants are tracked as CVE-2026-74232 and CVE-2026-74233.
  • The ZBT router implants have CVSS 4.0 scores of 9.3 and CVSS 3.1 scores of 9.8.
  • SPEAKINGSTONE sends beacons over UDP port 10000 to a hardcoded C2 server.
  • SPEAKINGSTONE can execute commands, exfiltrate WAN PPPoE credentials, hijack DNS, and open reverse SSH tunnels.
  • ServiceNow published its advisory on August 27, 2026.
  • CVE-2026-18885 is a code injection flaw in the GraphQL Composite Data API.
  • CVE-2026-18886 is an improper access control flaw in the system configuration image upload processor.
  • CVE-2026-74820 is a SQL injection flaw via a dynamic schema ORDER BY clause.
  • CISA added ownCloud vulnerability CVE-2023-49105 to its KEV catalog on Thursday.
  • A Chinese-speaking threat actor exploited ownCloud CVE-2023-49105 to target a Philippine nuclear research body.
  • The ownCloud flaw allows unauthenticated file access via WebDAV API if a username is known and no signing-key is configured.
  • The ownCloud vulnerability CVE-2023-49105 affects core versions 10.6.0 through 10.13.0.
  • ownCloud fixed CVE-2023-49105 in version 10.13.1.
  • Hunt.io identified an open directory on 31.58.209[.]241 staging custom Python scripts and offensive security tooling.
  • The open directory contained exfiltrated data from a Philippine nuclear research body and a marine engineering company.
  • Cosmos EVM flaw (GHSA-7g4w-cg88-2cq2) exploited to drain funds from six blockchains.
  • Cosmos EVM flaw was exploited between August 20 and August 25, 2026.
  • Cosmos Labs was aware of the Cosmos EVM flaw since April 25.
  • Cosmos Labs confirmed the Cosmos EVM flaw affected all chains by August 13.
  • Cosmos EVM flaw affects versions < 0.6.2 and >= 0.7.0 < 0.7.2.
  • Cosmos EVM flaw was fixed in versions v0.6.2 and v0.7.2 on August 19.
  • JetBrains' Cadence cloud development service was compromised.
  • Attackers exploited TeamCity flaw on JetBrains' own unpatched server.
  • The compromised server was api.cadence.jetbrains.com.
  • ServiceNow patched a high-severity sandbox escape vulnerability (CVE-2026-6876) with a CVSS score of 8.7.
  • JFrog Artifactory vulnerability CVE-2026-82329 allows unauthenticated attackers to obtain administrative privileges.
  • JFrog Artifactory updates were released on August 28.
  • JFrog Artifactory updates include versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.
  • WatchTowr observed attackers minting admin tokens via CVE-2026-82329.
  • Langflow vulnerability CVE-2026-0768 has a CVSS score of 9.8.
  • Langflow flaw CVE-2026-0768 is in the code validator of the custom component editor.
  • Langflow flaw CVE-2026-0768 allows arbitrary code execution as root without authentication.
  • Langflow flaw CVE-2026-0768 was reported through ZDI in July 2025.
  • Langflow flaw CVE-2026-0768 was publicly disclosed as a zero-day in January 2026.
  • VulnCheck observed exploitation attempts for Langflow flaw CVE-2026-0768 from Russia.
  • VulnCheck observed over 360 exploitation attempts for Langflow flaw CVE-2026-0768 in the UK.
  • The JFrog Artifactory flaw has a CVSS score of 9.8.
  • The JFrog Artifactory flaw affects versions 7.161.0 through 7.161.19, 7.146.0 through 7.146.36, 7.133.0 through 7.133.28, 7.125.0 through 7.125.19, 7.117.0 through 7.117.27, and 7.111.4 through 7.111.21.
  • The JFrog Artifactory flaw allows an unauthenticated attacker to obtain administrative privileges under default configuration.
  • The JFrog Artifactory flaw is an authentication bypass in JFrog Access.
  • The Langflow flaw allows attackers to steal OpenAI API keys and AWS credentials.
  • Attackers exploiting the Langflow flaw query environment variables and check .ssh access and .bash_history size.
  • SonicWall SMA1000 zero-days are CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8).
  • CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface.
  • CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC).
  • SonicWall observed exploitation of both SMA1000 vulnerabilities chained in attacks.
  • Affected SMA1000 models are 6210, 7210, and 8200v.
  • SMA1000 hotfixes 12.4.3-03526 and 12.5.0-02952 patch the vulnerabilities.
  • SonicWall SMA1000 flaws are CVE-2026-83548 (command injection) and CVE-2026-83549 (command injection).
  • SonicWall SMA1000 CVE-2026-83548 is a pre-authentication SSRF in the Appliance WorkPlace interface.
  • SonicWall SMA1000 CVE-2026-83549 is a command injection in the Appliance Management Console.
  • SonicWall SMA1000 flaws affect models 6210, 7210, and 8200v.
  • Shadowserver tracks over 400 SMA1000 appliances exposed online.
  • Sangoma Switchvox SMB Edition 8.3 has a critical SQL injection vulnerability (CVE-2026-9586).
  • Sangoma Switchvox flaw allows unauthenticated attackers to execute code as PostgreSQL superuser.
  • Sangoma Switchvox flaw affects approximately 4,000 internet-exposed instances, primarily in the U.S.
  • Sangoma Switchvox flaw was patched in version 8.4.0.2 on July 14, 2026.
  • Sangoma Switchvox flaw allows attackers to deploy reverse shells.
  • GeoNetwork has two vulnerabilities (CVE-2026-63219, CVE-2026-58400) that can be chained for RCE.
  • GeoNetwork released fixes in versions 4.4.12 and 4.2.17 on July 8, 2026.
  • GeoNetwork vulnerability details were published on August 31.
  • GeoNetwork flaw CVE-2026-63219 is a missing authorization check on the formatter upload endpoint.
  • GeoNetwork flaw CVE-2026-63219 allows unauthenticated file upload of .xsl or .zip formatter files.
  • SonicWall's William Perry and Adam Babis discovered the SMA1000 vulnerabilities.
  • CVE-2026-83549 is a post-authentication OS command injection.
  • Cleo Harmony has an authentication bypass vulnerability CVE-2026-84115.
  • The Cleo Harmony flaw allows privilege escalation via JWT refresh token manipulation.
  • The Cleo Harmony flaw is in an unknown function in '/api/connections'.
  • Cleo Harmony vulnerability CVE-2026-84115 was addressed in version 5.8.1.11.
  • Rockwell Automation patched over a dozen vulnerabilities across its industrial automation products.
  • Rockwell Automation released patches for four critical and high-severity DoS issues in RSLinx Classic.
  • Rockwell Automation fixed a high-severity RCE issue in FactoryTalk Historian.
  • Rockwell Automation resolved a privilege escalation flaw in FactoryTalk Activation Manager.
  • Rockwell Automation addressed DoS vulnerabilities in 1756-ENBT and Logix controllers.
  • The JFrog Artifactory flaw is present in the default configuration of self-managed instances.
  • The JFrog Artifactory flaw could compromise software supply chains by replacing trusted artifacts with malicious code.
  • Horizon3 discovered 12 flaws in Sangoma Switchvox and reported them on April 10.
  • The Sangoma Switchvox flaw is in the /pa HTTP endpoint.
  • The Sangoma Switchvox flaw allows SQL injection via the PhoneIP field in an XML message.
  • CISA added seven vulnerabilities to its KEV catalog on Wednesday.
  • The KEV catalog additions include flaws in Kludex, Kestra, and Berri LiteLLM products.
  • Cisco warned about two unpatched medium-severity flaws in its Secure Email product.
  • The Secure Email flaws are CVE-2026-20354 and CVE-2026-20355.
  • The Secure Email flaws affect S/MIME decryption functionality.
  • The Secure Email flaws allow attackers to intercept and modify traffic between email gateways.
  • A successful exploit of the Secure Email flaws could allow obtaining plaintext content from encrypted communication.
  • All Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
  • Cisco is not aware of in-the-wild exploitation of the Secure Email flaws.
  • Cisco released patches for critical-severity flaws in IOS XR and Nexus 9000 series switches.
  • Cisco patched a critical vulnerability (CVE-2026-20212) in 10 Silicon One-based Nexus 9000 switches.
  • The Nexus 9000 flaw (CVE-2026-20212) has a CVSS score of 9.8.
  • The Nexus 9000 flaw (CVE-2026-20212) is due to unrestricted IP address binding on TCP ports 43210 and 43211.
  • Exploitation of the Nexus 9000 flaw can crash the S1HAL process and reload the device.
  • HPE patched a critical remote code execution vulnerability (CVE-2026-73749) in ArubaOS-CX.
  • The ArubaOS-CX flaw (CVE-2026-73749) is a buffer overflow.
  • The ArubaOS-CX flaw (CVE-2026-73749) allows unauthenticated remote attackers to execute code with elevated privileges.
  • ArubaOS-CX versions 10.18.0001, 10.17.1021, 10.16.1051, 10.13.1180, and 10.10.1180 and earlier are affected by CVE-2026-73749.
  • ArubaOS-CX fixed CVE-2026-73749 in versions 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, and 10.10.1181+.
  • Broadcom patched two critical vulnerabilities, CVE-2026-59346 and CVE-2026-59347, in VMware Workstation and Fusion.
  • CVE-2026-59346 is an integer overflow (CVSS 9.3) allowing code execution from a VM with VMXNET3 adapter.
  • CVE-2026-59347 is a stack-based buffer overflow (CVSS 8.1) allowing code execution from a VM.
  • The VMware Workstation and Fusion flaws affect versions 25H2 and 26H1.
  • The VMware Workstation and Fusion flaws were fixed in version 26H1u1.
  • Sangoma Switchvox flaw has a CVSS score of 9.3.
  • The Sangoma Switchvox flaw is in an endpoint that processes XML content.
  • Citrix NetScaler flaw CVE-2026-19490 is being actively exploited.
  • Previdian founder Ryan Dewhurst confirmed exploitation of CVE-2026-19490 on Thursday.
  • A NetScaler sensor received requests targeting CVE-2026-19490 on September 3.
  • HPE patched 34 CVEs in ArubaOS-CX.
  • Over 150 flaws were resolved in ArubaOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
  • Nearly two dozen issues are tracked collectively as CVE-2026-73749.
  • The ArubaOS-CX critical flaws are due to improper processing of malformed input to an unnamed service.
  • ArubaOS-CX updates resolved 22 high-severity CVEs leading to DoS, RCE, command execution, script execution, authentication bypass, privilege escalation, and info disclosure.
  • The remaining 11 ArubaOS-CX CVEs are medium-severity access control flaws.
  • Ruby on Rails ActiveStorage vulnerability CVE-2026-66066 was dubbed KindaRails2Shell.
  • The Ruby on Rails flaw affects ActiveStorage in Ruby on Rails 8 and newer.
  • Ethiack was one of the research teams that discovered the Ruby on Rails flaw.
  • Attackers exploit PaperCut flaws (CVE-2026-81578, CVE-2026-82078) to steal credentials from schools and universities.
  • PaperCut flaws involve an authentication bypass and remote code execution chain.
  • Post-exploitation activity includes Windows registry hive collection tools and Metasploit/Meterpreter Java payloads.
  • Attackers created privileged accounts like 'Administrator17' and ran discovery commands.
  • Inbound GET requests from 45.142.193[.]132 targeted /custom/pcp_*.txt and /custom/web/pcp_*.txt files.
  • Broadcom credited @h4urek, @cameudis, and Stan S for discovering CVE-2026-59346.
  • Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab reported CVE-2026-59347.
  • The TeamCity flaw allowed attackers to access AWS credentials and user data.
  • Cadence is a JetBrains-hosted cloud computing service for machine learning workloads.
  • Cadence integrates with PyCharm via an optional plugin.
  • N-able patched a critical RCE flaw (CVE-2026-86218) in its N-central RMM platform.
  • The N-central flaw allows unprivileged attackers to execute code on unpatched systems.
  • N-able released N-central 2026.3 Hotfix 4 to address the vulnerability.
  • Shadowserver tracks nearly 1,500 N-central servers exposed online.
  • Huntress flagged the N-central flaw as a potential zero-day.
  • N-able issued its fourth N-central hotfix in five weeks.
  • The N-central flaw (CVE-2026-86218) has a CVSS 4.0 score of 10.0.
  • The N-central flaw is a static code injection weakness (CWE-96).
  • The N-central flaw affects all on-premises N-central builds prior to 2026.3.1.14.
  • N-able's communications disagree on whether the N-central flaw has been exploited in the wild.
  • N-central Hotfix 4 (2026.3.1.14) was shipped in the early hours of September 6 (UTC).
  • N-able had published Hotfix 3 (2026.3.1.13) eight hours earlier for unrelated flaws.
  • Hosted N-central (NCOD) instances have already been patched for the flaw.
  • TantoSec released a public exploit for Telerik UI for ASP.NET AJAX vulnerabilities.
  • The Telerik UI exploit targets a specific non-default configuration.
  • Progress Software fixed the Telerik UI flaws in version 2026.2.708 (2026 Q2 SP1) on July 8.
  • Progress Software published CVEs and an advisory for Telerik UI flaws on July 22.
  • TantoSec's Marcio Almeida released a command-line tool, telerik-rau-exploit, for the Telerik UI flaws.
  • The Telerik UI exploit includes two mixed-mode DLL payloads.
  • N-able patched two severe N-central flaws (CVE-2026-86206, CVE-2026-86207) allowing authentication bypass and full platform access.
  • N-able patched CVE-2026-86218 after patching CVE-2026-86206 and CVE-2026-86207.
  • N-able observed scans for CVE-2026-86218 from IP range 23.234.64.0/18.
  • N-able advises administrators to check for newly created user accounts.
  • The SAP flaw CVE-2026-44756 is a memory corruption issue in Extended Passport Processing (EPP).
  • The SAP flaw CVE-2026-44756 is dubbed OVERPASS by Onapsis.
  • The SAP flaw CVE-2026-44756 allows unauthenticated attackers to execute arbitrary system commands and access sensitive data.
  • The SAP flaw CVE-2026-44756 impacts various SAP products.
  • The SAP flaw CVE-2026-44756 is triggered when a new user session is opened from client to server.
  • The SAP flaw CVE-2026-44756 can be exploited over SAP Internet Communication Manager (ICM).
  • More than 10,000 internet-facing SAP systems are potentially exposed to the CVE-2026-44756 flaw.
  • CISA added N-able N-central flaw CVE-2026-86218 to its KEV catalog on Tuesday.
  • Federal agencies must patch N-able N-central flaw CVE-2026-86218 by September 11, 2026.
  • N-able N-central Hotfix 4 was released on September 5, 2026.
  • Huntress began investigating a compromise of a customer's N-central environment on September 4, 2026.
  • The SAP flaw CVE-2026-44756 stems from missing boundary validation during EPP data deserialization.
  • The SAP flaw CVE-2026-44756 is triggered by processing externally supplied length fields.
  • The SAP flaw CVE-2026-44756 allows attackers to run OS commands with SAP administrative privileges.
  • The SAP flaw CVE-2026-44756 can lead to total compromise of SAP business data and processes.
  • The SAP flaw CVE-2026-44756 can be exploited by sending crafted network requests with a malformed EPP header.
  • The SAP flaw CVE-2026-44756 can cause abnormal program termination.
  • The SAP flaw CVE-2026-44756 resides in the SAP kernel.
  • cPanel patched CVE-2026-67401, allowing authenticated hosting accounts with mail privileges to run code as root.
  • The cPanel flaw CVE-2026-67401 allows creating files on the server through EmailTrack.
  • The cPanel flaw CVE-2026-67401 affects all supported versions of cPanel and WHM.
  • cPanel published the advisory for CVE-2026-67401 on September 8.
  • The cPanel flaw CVE-2026-67401 is an SQL injection issue in EmailTrack.
  • The cPanel flaw CVE-2026-67401 allows an attacker to gain full administrative access to the server.
  • The cPanel flaw CVE-2026-67401 allows an attacker to compromise all hosted accounts.
  • Ivanti patched critical and high-severity vulnerabilities in Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM).
  • Ivanti Neurons for ITSM received fixes for eight bugs, six critical and two high-severity.
  • CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 are critical missing authorization issues in Neurons for ITSM.
  • CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745 are critical deserialization of untrusted data weaknesses in Neurons for ITSM.
  • CVE-2026-12651 and CVE-2026-12648 are high-severity deserialization of untrusted data defects in Neurons for ITSM.
  • CVE-2026-12744 and CVE-2026-12745 in Neurons for ITSM can be exploited without authentication.
  • Neurons for ITSM vulnerabilities were addressed in September 2026 security updates for versions 2025.2, 2025.3, 2025.4, and 2026.1.
  • Neurons for ITSM version 2026.2, scheduled for September 21, will include the fixes.
  • Fortinet patched 10 vulnerabilities across its products.
  • Fortinet critical flaw CVE-2026-84390 (CVSS 9.6) affects FortiMonitorOnSight web portal.
  • CVE-2026-84390 allows remote, unauthenticated attackers to bypass authentication via a forged JWT.
  • Fortinet critical flaw CVE-2026-84388 (CVSS 9.1) affects Privileged Access Agent Chrome extension.
  • CVE-2026-84388 allows remote, unauthenticated attackers to proxy user's browser traffic.
  • FortiPAM must be upgraded to 1.9.1 or 1.8.4, and Chrome extension to 8.0.1.123+ for CVE-2026-84388.
  • Fortinet also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and FortiOS/FortiProxy Agentless ZTNA portal.
  • Fortinet RCE flaw CVE-2025-25249 (CVSS 7.4) is a heap-based buffer overflow.
  • Fortinet RCE flaw CVE-2025-25249 was patched in January in FortiOS and FortiSwitchManager.
  • SOCRadar reported hackers exploiting Fortinet flaw CVE-2025-25249 to deploy PivotC2 RAT.
  • PivotC2 RAT is a FortiGate post-exploitation tool providing interactive shell access.
  • SOCRadar believes PivotC2 was developed using AI and used in attacks since July 2026.
  • Fortinet flaw CVE-2025-25249 exploitation infected 178 devices, mainly targeting US entities.
  • WatchGuard Firebox RCE flaw CVE-2025-14733 is being exploited by ransomware groups.
  • WatchGuard Firebox flaw CVE-2025-14733 is an out-of-bounds write.
  • WatchGuard Firebox flaw CVE-2025-14733 affects Fireware OS 11.x, 12.x, and 2025.1 through 2025.1.3.
  • WatchGuard Firebox flaw CVE-2025-14733 was patched in December.
  • WatchGuard Firebox flaw CVE-2025-14733 is vulnerable if configured to use IKEv2 VPN.
  • Shadowserver found over 115,000 unpatched Firebox firewalls exposed online in December.
  • Nearly 9,000 WatchGuard Firebox instances remain unsecured after nine months.
  • Cisco and CISA warned about active exploitation of CVE-2026-20079 on Wednesday.
  • CVE-2026-20079 allows attackers to run malicious scripts on vulnerable devices.
  • Cisco patched CVE-2026-20079 in early March.
  • Cisco updated its advisory for CVE-2026-20079 with IoCs in late July.
  • Cisco updated its advisory for CVE-2026-20079 on September 9.
  • CISA added CVE-2026-20079 to its KEV catalog, mandating federal agencies patch by September 12.
  • CISA added CVE-2026-19490 to its KEV catalog, mandating federal agencies patch within three days.
  • Citrix patched CVE-2026-19490 on August 19.
  • Rapid7 warned that CVE-2026-19490 could be exploited remotely without authentication.
  • Rapid7 expected threat actors to exploit CVE-2026-19490 shortly after patching.
  • Check Point patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products.
  • The Check Point flaws affect Security Gateways and Security Management Servers.
  • Check Point disclosed the flaws and began delivering fixes on September 9.
  • Check Point discovered the flaws internally and has no indication of exploitation.
  • CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation.
  • CVE-2026-85103 is a heap-based buffer overflow during ASN.1 structure decoding of a VPN certificate.
  • Cisco Talos reported two Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, were exploited by three threat clusters.
  • The threat clusters include ransomware affiliates and state-sponsored actors.
  • Attackers used the FMC flaws to deploy web shells, steal credentials, create reverse shells and proxies.
  • Attackers deployed Qilin ransomware and Cyclops Blink malware via the FMC flaws.
  • Cisco is tracking the threat clusters as UAT-12197, UAT-11823, and UAT-11988.
  • CVE-2026-20316 is a static credential vulnerability with a CVSS score of 5.3.
  • The critical Cisco FMC flaw CVE-2026-20079 has a CVSS score of 10.0.
  • The Cisco FMC flaw CVE-2026-20316 allows an unauthenticated remote attacker to log in with a low-privilege account.
  • UAT-12197 deployed JSP-based web shells and a Java Archive (JAR)-based command executor.
  • Attackers chained JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016.
  • Wiz observed JFrog Artifactory attacks between August 15 and September 8.
  • CVE-2026-42018 makes Artifactory hand an internal anonymous-user token to an unauthenticated caller.
  • CVE-2026-42016 allows a low-privilege token to be swapped for an administrator-scoped token.
  • Check Point flaws CVE-2026-85102 and CVE-2026-85103 have a CVSS score of 9.8.
  • CVE-2026-85102 affects Security Gateway and Spark Firewall using Site to Site VPN or Remote Access VPN.
  • CVE-2026-85103 impacts Security Management Server, Security Gateway, and Spark Firewall.
  • Security updates for Check Point flaws were released for versions R82.10, R82, and R81.20.
  • Check Point recommends manually defining VPN rules as a mitigation for the flaws.
  • The mitigation does not apply to locally managed Spark Firewall instances.
  • Attackers deploy a Rust-based backdoor on JFrog Artifactory self-hosted servers.
  • The JFrog Artifactory flaws allow attackers to execute arbitrary commands and steal configuration data.
  • Attackers establish persistence on JFrog Artifactory servers.
  • Wiz confirmed exploitation of JFrog Artifactory flaws across multiple environments.
  • Attackers obtain a JSON Web Token (JWT) for an internal anonymous user via CVE-2026-42018.
  • Attackers increase permissions to admin level by exploiting CVE-2026-42016.
  • Attackers created an administrator account in less than five minutes in some JFrog Artifactory attacks.
  • NCSC-NL warns of imminent exploitation of Check Point VPN flaws.
  • Check Point VPN flaws affect R81.10.x and R82.00.x versions.
  • CISA added ConnectWise ScreenConnect flaw CVE-2026-84869 to its KEV catalog.
  • ConnectWise ScreenConnect flaw CVE-2026-84869 has a CVSS score of 9.9.
  • ConnectWise ScreenConnect flaw CVE-2026-84869 allows unauthorized file transfer and execution.
  • CISA added MikroTik RouterOS flaw CVE-2026-67277 to its KEV catalog.
  • MikroTik RouterOS flaw CVE-2026-67277 has a CVSS score of 8.8.
  • CVE-2026-42018 was patched on August 12.
  • CVE-2026-42016 was patched on July 27.
  • Docker Sandboxes for macOS has a critical vulnerability (CVE-2026-77179).
  • The Docker Sandboxes flaw allows malicious guest code to read and modify macOS host files.
  • The Docker Sandboxes flaw affects versions 0.28.0 up to 0.42.0 on macOS.
  • Docker fixed the Sandboxes flaw in version 0.42.0 on September 7.
  • Check Point Security Management and Log Servers have a critical vulnerability (CVE-2026-91843).
  • The Check Point flaw allows unauthenticated attackers to execute code as root.
  • The Check Point flaw is a stack overflow in the login process, triggered by a long username.
  • The Check Point flaw has a CVSS score of 9.8.
  • The Check Point flaw is exploitable only through the Trusted Clients setting.
  • Check Point released a fix for the flaw via its LivePatch update channel on September 16, 2026.
  • Kaspersky and Tanium patched severe product vulnerabilities.
  • Tanium fixed two high-severity SQL injection flaws in Tanium Asset.
  • Orkes Conductor vulnerability CVE-2026-58138 is actively exploited.
  • Orkes Conductor flaw CVE-2026-58138 allows RCE via malicious JavaScript or Python expressions.
  • Orkes Conductor flaw CVE-2026-58138 has a CVSS score of 9.8.
  • Orkes Conductor flaw CVE-2026-58138 is exploited via inline workflow definitions to the workflow API endpoint.
  • Orkes Conductor flaw CVE-2026-58138 exploits GraalVM context configured with HostAccess.ALL.
  • Orkes Conductor flaw CVE-2026-58138 allows code to reflect into Java runtime and execute OS commands.
  • Orkes Conductor flaw CVE-2026-58138 has been exploited for at least a month.
  • Orkes Conductor does not enforce authentication by default.
  • Check Point flaw CVE-2026-91843 affects Security Management Server deployments.
  • Check Point flaw CVE-2026-91843 allows unprivileged attackers to gain root RCE.
  • Check Point flaw CVE-2026-91843 has low complexity and requires no user interaction.
  • Check Point provided temporary mitigation measures for CVE-2026-91843.
  • Check Point flaw CVE-2026-91843 is not actively exploited.
  • Check Point security teams can identify CVE-2026-91843 attacks by looking for "Admin" in logs.
  • CISA added three Linux kernel vulnerabilities to its KEV catalog on Friday.
  • The Linux kernel flaws are CVE-2025-39682 (memory disclosure/DoS), CVE-2026-53266 (DoS/privilege escalation), and CVE-2025-39964 (DoS/data integrity).
  • Red Hat issued high-priority advisories for the Linux kernel vulnerabilities.
  • Orkes Conductor flaw CVE-2026-58138 has a CVSS v4 score of 9.3.
  • Orkes Conductor flaw CVE-2026-58138 affects versions 3.21.21 before 3.30.2.
  • Orkes Conductor flaw CVE-2026-58138 is exploited by submitting inline workflow definitions to the workflow API endpoint.
  • Orkes Conductor flaw CVE-2026-58138 uses INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke system commands.
  • SolarWinds patched a high-severity RCE flaw (CVE-2026-28326) in Access Rights Manager (ARM).
  • The SolarWinds ARM flaw has a CVSS score of 8.8.
  • The SolarWinds ARM flaw affects all versions of Access Rights Manager 2026.2 and prior.
  • The SolarWinds ARM flaw is due to a hard-coded static key.
  • SolarWinds fixed the ARM flaw in version 2026.2.1.
  • Kai Huang of Armadin Security discovered and reported the SolarWinds ARM flaw.
  • SolarWinds previously fixed a critical SAML authentication bypass flaw (CVE-2026-28323) in Web Help Desk (WHD).
  • SolarWinds also fixed a DoS vulnerability (CVE-2026-28299) with a CVSS score of 8.2.
  • Linux kernel flaw CVE-2025-39682 has a CVSS score of 9.8.
  • Linux kernel flaw CVE-2025-39682 is a critical zero-length record handling issue in the TLS receive path.
  • Linux kernel flaw CVE-2025-39682 allows a local attacker to cause DoS or memory disclosure.
  • Linux kernel flaw CVE-2025-39964 has a CVSS score of 7.8.
  • Cisco warned of an actively exploited maximum-severity authentication bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE).
  • The Cisco ISE vulnerability (CVE-2026-76460) has a CVSS score of 10.0.
  • The Cisco ISE flaw (CVE-2026-76460) is due to insufficient authentication control on an API endpoint.
  • Exploiting the Cisco ISE flaw (CVE-2026-76460) allows an unauthenticated, remote attacker to bypass the web-based management interface.
  • Linux kernel flaw CVE-2025-39964 existed for 14 years.
  • CISA mandates federal agencies apply security updates and mitigations for Linux kernel flaws by end of today.
  • CISA mandates federal agencies conduct forensic triage on affected Linux kernel assets.
  • Public exploits are available for two of the Linux kernel flaws.
  • Linux kernel flaw CVE-2025-39964 is a race condition in AF_ALG cryptographic socket interface.
  • Linux kernel flaw CVE-2026-53266 is an out-of-bounds write in ebtables SNAT implementation.
  • Linux kernel flaw CVE-2025-39682 is a TLS receive-path logic flaw.
  • CISA added Zyxel GS1900 series switch vulnerability CVE-2026-7273 to its KEV catalog on Monday.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 has a CVSS score of 8.8.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 is a stack-based buffer overflow.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 allows LAN-based, unauthenticated attackers to execute OS commands via crafted HTTP requests.
  • Zyxel released an advisory for CVE-2026-7273 in June 2026.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 was fixed in versions 2.90(AAHH.2)C0, 2.90(AAHI.2)C0, 2.90(AAZI.2)C0, 2.90(AAHJ.2)C0, 2.90(AAHL.2)C0, and 2.90(AAHK.2)C0.
  • CISA mandated federal agencies patch Zyxel GS1900 series switch vulnerability CVE-2026-7273 by Thursday.
  • Zyxel released security updates for CVE-2026-7273 on June 16.
  • Veeam Agent for Windows has a local privilege escalation flaw (CVE-2026-32996).
  • Veeam Agent for Windows flaw CVE-2026-32996 allows attackers to gain SYSTEM-level control.
  • A Chinese threat actor exploited Zyxel GS1900 series switch vulnerability CVE-2026-7273 to exfiltrate sensitive information from devices in 48 countries.
  • The Zyxel GS1900 series switch exploitation used a heavily obfuscated Python script.
  • The Zyxel GS1900 series switch exploitation exfiltrated hashed root credentials, configuration details, and networking information.
  • The Zyxel GS1900 series switch exploitation targeted firmware versions 2.10-2.90 of the GS1900-24.
  • 564 compromised Zyxel GS1900 series switches had factory default credentials.
  • Arista announced a new critical vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator.
  • CVE-2026-93952 affects VCO deployments configured for certificate-based authentication.
  • CVE-2026-93952 can lead to full compromise of the orchestrator and managed Edge devices.
  • Fixed releases for CVE-2026-93952 are out for VCO 5.2 and 6.4 release trains.
  • D-Link warned of a critical zero-day stack-based buffer overflow vulnerability in DIR-822A routers.
  • The D-Link flaw is in the DHCP server component and can be exploited without authentication.
  • The D-Link flaw allows attackers to send crafted DHCP packets to trigger an overflow.
  • A public proof-of-concept exploit exists for the D-Link DIR-822A router flaw.
  • Check Point patched a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server.
  • The Check Point flaw allows unauthenticated attackers to upload and execute arbitrary scripts.
  • The Check Point flaw affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
  • Check Point addressed CVE-2026-93616 in R82.20 Security Hotfix.
  • CISA and FBI urged software companies to remove path traversal weaknesses.
  • Bifrost, an open-source AI gateway, has a critical vulnerability (CVE-2026-90898) allowing unauthenticated command execution.
  • The Bifrost flaw affects versions before 2.1.0 when management authentication is disabled by default.
  • The Bifrost flaw has a CVSS score of 9.8.
  • The Bifrost flaw was discovered by Yuval Moravchick of JFrog Security Research.
  • The Bifrost flaw allows attackers to register a stdio-type MCP client via a single unauthenticated POST request.
  • The Bifrost flaw allows access to API keys for over 20 LLM providers.
  • The official Bifrost Docker image binds the management API to 0.0.0.0, making it externally reachable.
  • Check Point's CVE-2026-93616 was exploited in targeted attacks on July 23.
  • Check Point released a fix for CVE-2026-93616 on September 22.
  • Attackers have been trying to exploit Check Point's VPN flaw CVE-2026-85102 since September 12.
  • Exploitation attempts for CVE-2026-85102 targeted customers of Spark, Check Point's firewall line for small businesses.
  • Check Point released R82.20 Security Hotfix (TAR) for CVE-2026-93616.
  • Check Point included fixes for CVE-2026-93616 in Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192).
  • Check Point advises limiting access to Management Server behind a security gateway or firewall as mitigation for CVE-2026-93616.
  • Check Point advises limiting access to port TCP/19009 to trusted IP addresses as mitigation for CVE-2026-93616.
  • Standard LivePatch updates do not apply to CVE-2026-93616.
  • F5 patched a critical zero-day vulnerability in BIG-IP APM.
  • The F5 BIG-IP APM flaw is CVE-2026-94127 with a CVSS score of 9.8 (v3.1) and 9.3 (v4.0).
  • The F5 BIG-IP APM flaw is a heap-based buffer overflow.
  • The F5 BIG-IP APM flaw affects versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3.
  • The F5 BIG-IP APM flaw is exploitable when an APM access policy and OAuth profile are configured on a virtual server.
  • The F5 BIG-IP APM flaw is exploitable when APM functions as an OAuth authorization server.
  • The F5 BIG-IP APM flaw affects BIG-IP systems in Appliance mode.
  • The F5 BIG-IP APM flaw is a data plane issue.
  • Arista released patches for VCO versions 5.2.3.16 and 6.4.2.8.
  • The Arista VCO flaw is an improper input validation issue.
  • CISA added CVE-2026-93952 to its KEV catalog.
  • The Arista VCO flaw allows remote attackers to access privileged internal VCO host functionality without authentication.
  • Exploitation of the Arista VCO flaw requires access to the public portion of the VeloCloud Edge authentication certificate.
  • The Arista VCO flaw requires network access to the VCO web interface.
  • CVE-2026-80521 is a use-after-free flaw in Linux kernel's AF_UNIX socket subsystem.
  • The Linux kernel AF_UNIX socket flaw allows container escape and root access on the host.
  • The Linux kernel AF_UNIX socket flaw was fixed upstream on August 6.
  • Ubuntu has not patched its 26.04, 24.04, and 22.04 LTS releases for CVE-2026-80521.
  • DepthFirst released exploit code targeting Ubuntu 26.04 for CVE-2026-80521.
  • The Linux kernel AF_UNIX socket flaw affects newer kernel packages for AWS, Azure, and GCP workloads.
  • The Linux kernel AF_UNIX socket flaw is in the kernel's garbage collector for AF_UNIX sockets.
  • The Linux kernel AF_UNIX socket flaw can be reached from inside a container.
  • InfraTrust Pulse report indicates a rise in attacks targeting network management systems.
  • InfraTrust tracked 158 new security advisories across 17 vendors between August 25 and September 17.
  • InfraTrust tracked 1,699 vulnerabilities in its latest report.
  • 42 of the tracked advisories were rated critical.
  • Eight of the tracked advisories had a maximum CVSS score of 10.0.
  • 71 of the tracked advisories could be exploited remotely without authentication.
  • MikroTik RouterOS SSH vulnerabilities CVE-2026-67279 and CVE-2026-86060 are chained for full administrative control.
  • The MikroTrick chain combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug (CVE-2026-86060).
  • Exploitation of MikroTrick was observed in logs before September 3.
  • MikroTik shipped patches for MikroTrick in RouterOS versions 6.49.21, 7.23.4, and 7.24.2.
  • CVE-2026-67279 breaks the SSH authentication sequence by sending SSH_MSG_USERAUTH_SUCCESS prematurely.
  • Check Point confirmed active exploitation of CVE-2026-85102 and CVE-2026-93616.
  • CISA added CVE-2026-85102 and CVE-2026-93616 to its KEV catalog.
  • Federal agencies must patch CVE-2026-85102 and CVE-2026-93616 by September 25, 2026.
  • CVE-2026-85102 is a pre-authentication RCE in VPN certificate-handling.
  • CVE-2026-93616 is a pre-authentication path traversal flaw in the Management web service.
  • CVE-2026-93616 allows script execution and Java class loading.
  • NCSC-NL alerted about the Security Gateway issue on September 10.
  • Exploitation attempts for CVE-2026-85102 started on September 12.
  • Attackers used VPNs and proxies to hide their location during exploitation.
  • Attackers used certificates with the subject CN=vpn,OU=users,O=gl.
  • SolarWinds patched two critical RCE flaws (CVE-2026-28324, CVE-2026-28325) in Observability Self-Hosted.
  • SolarWinds Observability Self-Hosted flaws affect versions up to 2026.2.2.
  • SolarWinds Observability Self-Hosted flaws were addressed in version 2026.2.3.
  • CVE-2026-28324 is an insufficient integrity check issue with a CVSS score of 9.8.
  • CVE-2026-28325 is a deserialization of untrusted data weakness with a CVSS score of 8.8.
  • Ransomware gangs are exploiting the TeamCity flaw CVE-2026-63077.
  • CISA added TeamCity flaw CVE-2026-63077 to its KEV catalog on August 5.
  • Roundcube Webmail has a high-severity SQL injection vulnerability (CVE-2026-48842).
  • The Roundcube flaw allows unauthenticated attackers to bypass authentication and execute malicious database commands.
  • The Roundcube flaw impacts thousands of services using the client.
  • The Roundcube flaw was patched in May.
  • The Roundcube flaw is in the virtuser_query built-in plugin.
  • Roundcube versions 1.6.16 and 1.7.1 address the vulnerability.
  • Shadowserver tracks over 523,000 Roundcube instances exposed online.
  • CISA added WSO2 flaw CVE-2026-5430 to its KEV catalog.
  • CISA added Adobe Commerce flaw CVE-2026-71362 to its KEV catalog.
  • WSO2 flaw CVE-2026-5430 has a CVSS score of 9.8.
  • WSO2 flaw CVE-2026-5430 is a path traversal vulnerability.
  • WSO2 flaw CVE-2026-5430 affects API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
  • Adobe Commerce flaw CVE-2026-71362 has a CVSS score of 9.1.
  • Adobe Commerce flaw CVE-2026-71362 is an incorrect authorization vulnerability.
  • Adobe Commerce flaw CVE-2026-71362 allows attackers to gain elevated access to sensitive resources.
  • watchTowr observed in-the-wild exploitation of WSO2 flaw CVE-2026-5430 since September 13, 2026.
  • Sansec detected and blocked exploitation attempts for Adobe Commerce flaw CVE-2026-71362 in August 2026.
  • Adobe Commerce flaw CVE-2026-71362 allows attackers to switch a customer session to another customer account.
  • Roundcube flaw CVE-2026-48842 has a CVSS score of 8.1.
  • Roundcube flaw CVE-2026-48842 uses preg_replace() filter with backslash escaping.
  • Roundcube flaw CVE-2026-48842 allows bypassing protection using crafted queries with backslash sequences.
  • Roundcube flaw CVE-2026-48842 results in quote characters concatenated into an SQL string.
  • Canadian Centre for Cyber Security warned about Roundcube flaw exploitation.
  • Avast Antivirus flaw CVE-2025-13032 is a double-fetch vulnerability in its kernel driver.
  • Avast Antivirus flaw CVE-2025-13032 allows arbitrary kernel read/write and SYSTEM privilege escalation.
  • Avast Antivirus flaw CVE-2025-13032 was exploited on Windows 11.
  • Avast Antivirus flaw CVE-2025-13032 exploits a controlled paged pool overflow.
  • Avast Antivirus flaw CVE-2025-13032 corrupts the RegBuffers array of the IORing object.
  • Avast Antivirus flaw CVE-2025-13032 uses heap spray strategy and kernel address leak via MDL introspection.
  • Avast Antivirus flaw CVE-2025-13032 requires repairs to avoid blue screen on teardown.
  • Roundcube flaw CVE-2026-48842 affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
  • SentinelOne stated the Roundcube flaw could expose mail account credentials and stored messages.
  • Shadowserver Foundation flagged 10 vulnerable Roundcube hosts as of September 23, 2026.
  • UNC6240 (ShinyHunters) renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273.
  • UNC6240 expanded global targeting across multiple sectors.
  • UNC6240 bypassed WAF rules by URL-encoding a character in the request path.
  • Oracle PeopleSoft flaw CVE-2026-35273 has a CVSS score of 9.8.
  • Oracle PeopleSoft flaw CVE-2026-35273 was first exploited as a zero-day against academic institutions.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 deployed MeshCentral agent for persistence.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 involved lateral movement over SSH.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 ran a shell script to connect to other internal PeopleSoft machines.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 stole data.
  • Mandiant notified over 100 global organizations about Oracle PeopleSoft flaw CVE-2026-35273.
  • ShinyHunters uses URL-encoding to bypass WAF rules for Oracle PeopleSoft CVE-2026-35273.
  • Google's Mandiant and Threat Intelligence Group (GTIG) reported the WAF bypass technique.
  • Oracle fixed the PeopleSoft zero-day CVE-2026-35273 on June 11.
  • BleepingComputer first reported ShinyHunters targeting Oracle PeopleSoft servers on June 10.
  • Two new unpatched zero-day RCE flaws in Citrix NetScaler ADC/Gateway are actively exploited.
  • Citrix has not confirmed the new flaws or published a fix.
  • Some administrators took appliances offline due to the new Citrix flaws.
  • The new Citrix flaws are distinct from CVE-2026-19490.
  • WatchTowr reported the new Citrix flaws on September 26.
  • Citrix confirmed two NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772, are actively exploited.
  • Citrix released security updates for CVE-2026-88771 and CVE-2026-88772.
  • The NetScaler zero-days affect NetScaler ADC and NetScaler Gateway appliances.
  • Citrix administrators reported IT suppliers and security teams advised shutting down NetScaler appliances.
  • CISA ordered U.S. government agencies to patch Citrix flaws CVE-2026-88771 and CVE-2026-88772 by Wednesday.
  • NCSC-NL warned Dutch organizations about critical NetScaler zero-days allowing shellcode placement in memory.
  • Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 on Sunday.
  • CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments with default configurations.
  • CVE-2026-88772 requires DTLS to be enabled, which is default on VPN virtual servers.
  • Citrix advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
  • CVE-2026-88771 has a CVSS score of 9.5.
  • CVE-2026-88772 has a CVSS score of 9.5.
  • CVE-2026-88772 is a memory overflow.
  • Citrix made indicators of compromise (IoCs) available.
  • CVE-2026-88771 is an improper input validation flaw.
  • CVE-2026-88772 is an improper restriction of operations within memory buffer flaw.
  • CVE-2026-88772 can cause denial-of-service.
  • Citrix fixed the flaws in versions 14.1-73.37 and 13.1-64.23.
  • Citrix released patches for 8 vulnerabilities in NetScaler ADC and NetScaler Gateway.
  • CISA ordered federal agencies to patch Citrix flaws CVE-2026-88771 and CVE-2026-88772 by Wednesday.
  • The UK and Netherlands also issued urgent warnings about the Citrix NetScaler zero-days.
  • Citrix confirmed eight new vulnerabilities in NetScaler ADC and Gateway devices.
  • CISA mandated federal agencies conduct forensic triage on affected NetScaler products.
  • Wiz.io disclosed the three Artifactory vulnerabilities.
  • Mandiant and Google Threat Intelligence Group identified active exploitation of Citrix flaws.
  • Exploitation of CVE-2026-88772 bypasses authentication and triggers unhandled termination of NetScaler Packet Processing Engine.
  • Attackers use custom PHP web shells like WHIPSHOT, disguising C&C payloads in HTTP headers.
  • Attackers use a Python tunneler, SLAPSHOT, to proxy traffic into internal networks.
  • Exploitation campaign has been ongoing since at least early September.
  • Government, financial, education, legal, and professional services sectors in North America and Europe were impacted.
  • Attackers deployed custom web shells and tunneling malware via Citrix NetScaler CVE-2026-88772.
  • Attackers gained root access and stole credentials via Citrix NetScaler CVE-2026-88772.
  • The Citrix NetScaler exploitation impacted government, financial, education, legal, and professional services sectors.
  • Citrix NetScaler zero-days are dubbed "PitScaler" by some researchers.
  • NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field.
  • The DTLS header simultaneously claims the complete message is 120 bytes long.
  • OpenSSL patched 14 vulnerabilities, including one high-severity flaw (CVE-2026-84782).
  • CVE-2026-84782 allows a remote peer to obtain heap memory fragments or crash applications using Datagram TLS (DTLS).
  • CVE-2026-84782 is triggered during the DTLS handshake when OpenSSL retransmits a message while sending another is stalled.
  • CVE-2026-84782 can cause leftover heap data to be sent to the other party in plaintext.
  • CVE-2026-84782 has a CVSS score of 8.2.
  • OpenSSL fixed a medium-severity vulnerability (CVE-2026-84783) allowing a remote, unauthenticated peer to crash a multi-threaded TLS client.
  • WolfSSL patched roughly a dozen vulnerabilities, including high-severity flaws.
  • TeamViewer urged users to update client and host software due to multiple high-severity vulnerabilities.
  • TeamViewer flaw CVE-2026-92370 is a remote session access control bypass.
  • TeamViewer flaw CVE-2026-92370 affects Full Client and Host software for Windows, Linux, and macOS.
  • TeamViewer flaw CVE-2026-92370 allows unauthorized actions leading to remote code execution.
  • TeamViewer also patched CVE-2026-19743 (path traversal), CVE-2026-92368 (heap-based buffer overflow), CVE-2026-92369 (TOCTOU race condition), and CVE-2026-92371 (improper path validation).
  • TeamViewer flaws allow local attackers to gain code execution or escalate privileges to NT AUTHORITY/SYSTEM or root.
  • TeamViewer recommends updating to version 15.82.
  • WatchGuard patched 15 vulnerabilities in Fireware OS.
  • WatchGuard Fireware OS critical RCE flaw CVE-2026-86131 has a CVSS score of 9.2.
  • WatchGuard Fireware OS flaw CVE-2026-86131 is a code injection issue in BOVPN over TLS client configurations.
  • WatchGuard Fireware OS flaw CVE-2026-86131 allows a remote attacker controlling the VPN server to execute commands with root privileges.
  • WatchGuard Fireware OS flaw CVE-2026-86131 was resolved in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
  • WatchGuard also fixed 13 high-severity vulnerabilities in Fireware OS.
  • WatchGuard fixed two critical RCE flaws (CVE-2026-101891, CVE-2026-86102) in Access Points.
  • Cisco released security updates for a critical zero-day (CVE-2026-76504) in Catalyst SD-WAN Manager.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 allows unauthenticated remote access due to improper handling of URI encoding.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 affects all deployments regardless of system configuration.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 has a CVSS score of 9.8.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 was found in API session-based authentication management.
  • Cisco PSIRT became aware of active exploitation of CVE-2026-76504 in September 2026.
  • The admin user in Cisco Catalyst SD-WAN Manager holds the netadmin role by default.
  • CISA warned of MikroTik RouterOS flaw CVE-2026-84411.
  • MikroTik RouterOS flaw CVE-2026-84411 is a pre-authentication integer underflow in web-management HTTP request handling.
  • MikroTik RouterOS flaw CVE-2026-84411 allows unauthenticated attackers to achieve arbitrary code execution as root or cause DoS with a single crafted request.
  • MikroTik RouterOS flaw CVE-2026-84411 affects versions below 7.24.
  • MikroTik recommends updating to RouterOS version 7.23 or later to mitigate CVE-2026-84411.
  • Microsoft Security Research team observed exploitation of Zimbra flaw CVE-2026-73570.
  • Zimbra flaw CVE-2026-73570 exploitation involved a specially crafted SMTP request.
  • Zimbra flaw CVE-2026-73570 exploitation led to deployment of JSP web shells, reverse shells, privilege escalation, and persistent remote-access tooling.
  • Zimbra flaw CVE-2026-73570 exploitation allowed access to email and collection of authentication and mailbox data.
  • Microsoft reported attackers exploiting Zimbra flaw CVE-2026-73570 to steal email backups.
  • Zimbra maintainer Synacor issued a patch on July 20, but disclosed the vulnerability three weeks later.
  • Shadowserver found 274 Zimbra Collaboration Suite instances compromised.
  • Zimbra server count fluctuated from 19,000 to 12,000 after the patch.
  • Microsoft detected two scanning tools probing for vulnerable Zimbra endpoints from July 28 to August 7.
  • Attackers exploit CVE-2026-88771 to install web shells and exfiltrate configuration data.
  • LevelBlue's THOR team analyzed exploitation activity across multiple customer environments.
  • Malicious NetScaler authentication events contain attacker-controlled usernames to weaponize CVE-2026-88771.
  • Attacker-controlled authentication data contains variations of 'pitboss' and 'NSPPE' strings.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is due to improper handling of URI encoding in an HTTP request.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 was resolved in versions 26.2.1, 26.1.2.1, and 20.18.4.1.
  • CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 to its KEV catalog on Wednesday.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is a hex encoding vulnerability.
  • Cisco provided IoCs for CVE-2026-76504 to check for impact.
  • Microsoft reported exploitation of Zimbra flaw CVE-2026-73570.
  • Zimbra flaw CVE-2026-73570 is due to improper sanitization of untrusted input during SNMP notification processing.
  • Zimbra flaw CVE-2026-73570 allows RCE with Zimbra user privileges.
  • Fortinet warned of a critical FortiMail vulnerability (CVE-2026-104286) with a CVSS score of 9.8.
  • The FortiMail flaw allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests.
  • The FortiMail flaw affects versions 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9.
  • Fortinet's Gwendal Guégniaud discovered the FortiMail vulnerability internally.
  • Debian released security advisory DSA-6528-1 addressing over 100 Linux kernel CVEs.
  • CISA added FortiMail flaw CVE-2026-104286 to its KEV catalog on Thursday.
  • Federal agencies must patch FortiMail flaw CVE-2026-104286 by October 4, 2026.
  • FortiMail flaw CVE-2026-104286 is a path traversal (CWE-22) and NULL byte neutralization (CWE-158) vulnerability.
  • FortiMail versions 8.0.0-8.0.1 should upgrade to 8.0.2 or above.
  • FortiMail versions 7.6.0-7.6.6 should upgrade to 7.6.7 or above.
  • FortiMail versions 7.4.0-7.4.8 should upgrade to 7.4.9 or above.
  • FortiMail versions 7.2.0-7.2.9 should upgrade to branch 7.4 or above.
  • Fortinet has not yet released patches for CVE-2026-104286.
  • Fortinet advises disabling IBE feature support or limiting access to the FortiMail management interface as workarounds for CVE-2026-104286.
  • Fortinet published indicators of compromise (IoCs) for CVE-2026-104286.

Critical Vulnerabilities Patched

Adobe has released security patches addressing critical vulnerabilities in its ColdFusion and Campaign Classic software. Among these are six flaws in ColdFusion and one in Campaign Classic, all having the highest CVSS severity score of 10.0. These vulnerabilities can lead to arbitrary code execution, posing significant risks to systems if not promptly patched.

Active Exploitation

One of the vulnerabilities, identified as CVE-2026-48282, is currently being exploited by hackers. This flaw allows attackers to remotely execute code on unpatched systems, making its immediate remediation crucial. Adobe and security organizations like CISA have stressed the need for users to update their systems as soon as possible.

Security Agency Alerts

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, signaling the active exploitation of this vulnerability in the wild. This inclusion underscores the critical nature of the flaw and the priority for system administrators to apply the updates provided by Adobe.

Importance for Users

Patching these flaws is imperative to protect against potential security breaches. Administrators of systems using ColdFusion and Campaign Classic should prioritize these updates to mitigate risks associated with the vulnerabilities, thus ensuring the security and integrity of their applications and data.

Updates

🕒 2026-10-02 · new reporting from SecurityWeek
  • Fortinet has not yet released patches for CVE-2026-104286.
  • Fortinet advises disabling IBE feature support or limiting access to the FortiMail management interface as workarounds for CVE-2026-104286.
  • Fortinet published indicators of compromise (IoCs) for CVE-2026-104286.
🕒 2026-10-02 · new reporting from The Hacker News
  • CISA added FortiMail flaw CVE-2026-104286 to its KEV catalog on Thursday.
  • Federal agencies must patch FortiMail flaw CVE-2026-104286 by October 4, 2026.
  • FortiMail flaw CVE-2026-104286 is a path traversal (CWE-22) and NULL byte neutralization (CWE-158) vulnerability.
  • FortiMail versions 8.0.0-8.0.1 should upgrade to 8.0.2 or above.
  • FortiMail versions 7.6.0-7.6.6 should upgrade to 7.6.7 or above.
  • FortiMail versions 7.4.0-7.4.8 should upgrade to 7.4.9 or above.
  • FortiMail versions 7.2.0-7.2.9 should upgrade to branch 7.4 or above.
🕒 2026-10-02 · new reporting from BleepingComputer, Hacker News Front Page
  • Fortinet warned of a critical FortiMail vulnerability (CVE-2026-104286) with a CVSS score of 9.8.
  • The FortiMail flaw allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests.
  • The FortiMail flaw affects versions 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9.
  • Fortinet's Gwendal Guégniaud discovered the FortiMail vulnerability internally.
  • Debian released security advisory DSA-6528-1 addressing over 100 Linux kernel CVEs.
🕒 2026-10-01 · new reporting from SecurityWeek
  • Microsoft reported exploitation of Zimbra flaw CVE-2026-73570.
  • Zimbra flaw CVE-2026-73570 is due to improper sanitization of untrusted input during SNMP notification processing.
  • Zimbra flaw CVE-2026-73570 allows RCE with Zimbra user privileges.
🕒 2026-10-01 · new reporting from The Hacker News
  • CISA added Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 to its KEV catalog on Wednesday.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is a hex encoding vulnerability.
  • Cisco provided IoCs for CVE-2026-76504 to check for impact.
🕒 2026-10-01 · new reporting from SecurityWeek
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 is due to improper handling of URI encoding in an HTTP request.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 was resolved in versions 26.2.1, 26.1.2.1, and 20.18.4.1.
🕒 2026-10-01 · new reporting from The Hacker News
  • Attackers exploit CVE-2026-88771 to install web shells and exfiltrate configuration data.
  • LevelBlue's THOR team analyzed exploitation activity across multiple customer environments.
  • Malicious NetScaler authentication events contain attacker-controlled usernames to weaponize CVE-2026-88771.
  • Attacker-controlled authentication data contains variations of 'pitboss' and 'NSPPE' strings.
🕒 2026-10-01 · new reporting from Ars Technica
  • Microsoft reported attackers exploiting Zimbra flaw CVE-2026-73570 to steal email backups.
  • Zimbra maintainer Synacor issued a patch on July 20, but disclosed the vulnerability three weeks later.
  • Shadowserver found 274 Zimbra Collaboration Suite instances compromised.
  • Zimbra server count fluctuated from 19,000 to 12,000 after the patch.
  • Microsoft detected two scanning tools probing for vulnerable Zimbra endpoints from July 28 to August 7.
🕒 2026-09-30 · new reporting from BleepingComputer, The Hacker News
  • CISA warned of MikroTik RouterOS flaw CVE-2026-84411.
  • MikroTik RouterOS flaw CVE-2026-84411 is a pre-authentication integer underflow in web-management HTTP request handling.
  • MikroTik RouterOS flaw CVE-2026-84411 allows unauthenticated attackers to achieve arbitrary code execution as root or cause DoS with a single crafted request.
  • MikroTik RouterOS flaw CVE-2026-84411 affects versions below 7.24.
  • MikroTik recommends updating to RouterOS version 7.23 or later to mitigate CVE-2026-84411.
  • Microsoft Security Research team observed exploitation of Zimbra flaw CVE-2026-73570.
  • Zimbra flaw CVE-2026-73570 exploitation involved a specially crafted SMTP request.
  • Zimbra flaw CVE-2026-73570 exploitation led to deployment of JSP web shells, reverse shells, privilege escalation, and persistent remote-access tooling.
  • Zimbra flaw CVE-2026-73570 exploitation allowed access to email and collection of authentication and mailbox data.
🕒 2026-09-30 · new reporting from SecurityWeek, BleepingComputer, The Hacker News
  • WatchGuard patched 15 vulnerabilities in Fireware OS.
  • WatchGuard Fireware OS critical RCE flaw CVE-2026-86131 has a CVSS score of 9.2.
  • WatchGuard Fireware OS flaw CVE-2026-86131 is a code injection issue in BOVPN over TLS client configurations.
  • WatchGuard Fireware OS flaw CVE-2026-86131 allows a remote attacker controlling the VPN server to execute commands with root privileges.
  • WatchGuard Fireware OS flaw CVE-2026-86131 was resolved in versions 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21.
  • WatchGuard also fixed 13 high-severity vulnerabilities in Fireware OS.
  • WatchGuard fixed two critical RCE flaws (CVE-2026-101891, CVE-2026-86102) in Access Points.
  • Cisco released security updates for a critical zero-day (CVE-2026-76504) in Catalyst SD-WAN Manager.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 allows unauthenticated remote access due to improper handling of URI encoding.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 affects all deployments regardless of system configuration.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 allows unauthenticated attackers to access vulnerable systems remotely with admin privileges.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 has a CVSS score of 9.8.
  • Cisco Catalyst SD-WAN Manager flaw CVE-2026-76504 was found in API session-based authentication management.
  • Cisco PSIRT became aware of active exploitation of CVE-2026-76504 in September 2026.
  • The admin user in Cisco Catalyst SD-WAN Manager holds the netadmin role by default.
🕒 2026-09-30 · new reporting from The Hacker News, BleepingComputer
  • TeamViewer urged users to update client and host software due to multiple high-severity vulnerabilities.
  • TeamViewer flaw CVE-2026-92370 is a remote session access control bypass.
  • TeamViewer flaw CVE-2026-92370 affects Full Client and Host software for Windows, Linux, and macOS.
  • TeamViewer flaw CVE-2026-92370 allows unauthorized actions leading to remote code execution.
  • TeamViewer also patched CVE-2026-19743 (path traversal), CVE-2026-92368 (heap-based buffer overflow), CVE-2026-92369 (TOCTOU race condition), and CVE-2026-92371 (improper path validation).
  • TeamViewer flaws allow local attackers to gain code execution or escalate privileges to NT AUTHORITY/SYSTEM or root.
  • TeamViewer recommends updating to version 15.82.
🕒 2026-09-30 · new reporting from The Hacker News, SecurityWeek
  • NetScaler implicitly trusts the declared fragment size in the DTLS handshake header's fragment_length field.
  • The DTLS header simultaneously claims the complete message is 120 bytes long.
  • OpenSSL patched 14 vulnerabilities, including one high-severity flaw (CVE-2026-84782).
  • CVE-2026-84782 allows a remote peer to obtain heap memory fragments or crash applications using Datagram TLS (DTLS).
  • CVE-2026-84782 is triggered during the DTLS handshake when OpenSSL retransmits a message while sending another is stalled.
  • CVE-2026-84782 can cause leftover heap data to be sent to the other party in plaintext.
  • CVE-2026-84782 has a CVSS score of 8.2.
  • OpenSSL fixed a medium-severity vulnerability (CVE-2026-84783) allowing a remote, unauthenticated peer to crash a multi-threaded TLS client.
  • WolfSSL patched roughly a dozen vulnerabilities, including high-severity flaws.
🕒 2026-09-29 · new reporting from BleepingComputer
  • Attackers deployed custom web shells and tunneling malware via Citrix NetScaler CVE-2026-88772.
  • Attackers gained root access and stole credentials via Citrix NetScaler CVE-2026-88772.
  • The Citrix NetScaler exploitation impacted government, financial, education, legal, and professional services sectors.
  • Citrix NetScaler zero-days are dubbed "PitScaler" by some researchers.
🕒 2026-09-29 · new reporting from Google Cloud Blog
  • Mandiant and Google Threat Intelligence Group identified active exploitation of Citrix flaws.
  • Exploitation of CVE-2026-88772 bypasses authentication and triggers unhandled termination of NetScaler Packet Processing Engine.
  • Attackers use custom PHP web shells like WHIPSHOT, disguising C&C payloads in HTTP headers.
  • Attackers use a Python tunneler, SLAPSHOT, to proxy traffic into internal networks.
  • Exploitation campaign has been ongoing since at least early September.
  • Government, financial, education, legal, and professional services sectors in North America and Europe were impacted.
🕒 2026-09-28 · new reporting from InfoQ
  • Wiz.io disclosed the three Artifactory vulnerabilities.
🕒 2026-09-28 · new reporting from The Record
  • The UK and Netherlands also issued urgent warnings about the Citrix NetScaler zero-days.
  • Citrix confirmed eight new vulnerabilities in NetScaler ADC and Gateway devices.
  • CISA mandated federal agencies conduct forensic triage on affected NetScaler products.
🕒 2026-09-28 · new reporting from The Hacker News
  • Citrix released patches for 8 vulnerabilities in NetScaler ADC and NetScaler Gateway.
  • CISA ordered federal agencies to patch Citrix flaws CVE-2026-88771 and CVE-2026-88772 by Wednesday.
🕒 2026-09-28 · new reporting from The Hacker News
  • CVE-2026-88771 is an improper input validation flaw.
  • CVE-2026-88772 is an improper restriction of operations within memory buffer flaw.
  • CVE-2026-88772 can cause denial-of-service.
  • Citrix fixed the flaws in versions 14.1-73.37 and 13.1-64.23.
🕒 2026-09-28 · new reporting from SecurityWeek
  • Citrix advisory covers eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway.
  • CVE-2026-88771 has a CVSS score of 9.5.
  • CVE-2026-88772 has a CVSS score of 9.5.
  • CVE-2026-88772 is a memory overflow.
  • Citrix made indicators of compromise (IoCs) available.
🕒 2026-09-28 · new reporting from BleepingComputer
  • CISA ordered U.S. government agencies to patch Citrix flaws CVE-2026-88771 and CVE-2026-88772 by Wednesday.
  • NCSC-NL warned Dutch organizations about critical NetScaler zero-days allowing shellcode placement in memory.
  • Citrix confirmed active exploitation of CVE-2026-88771 and CVE-2026-88772 on Sunday.
  • CVE-2026-88771 affects all NetScaler ADC and NetScaler Gateway deployments with default configurations.
  • CVE-2026-88772 requires DTLS to be enabled, which is default on VPN virtual servers.
🕒 2026-09-27 · new reporting from BleepingComputer
  • Citrix confirmed two NetScaler RCE zero-days, CVE-2026-88771 and CVE-2026-88772, are actively exploited.
  • Citrix released security updates for CVE-2026-88771 and CVE-2026-88772.
  • The NetScaler zero-days affect NetScaler ADC and NetScaler Gateway appliances.
  • Citrix administrators reported IT suppliers and security teams advised shutting down NetScaler appliances.
🕒 2026-09-27 · new reporting from The Hacker News
  • Two new unpatched zero-day RCE flaws in Citrix NetScaler ADC/Gateway are actively exploited.
  • Citrix has not confirmed the new flaws or published a fix.
  • Some administrators took appliances offline due to the new Citrix flaws.
  • The new Citrix flaws are distinct from CVE-2026-19490.
  • WatchTowr reported the new Citrix flaws on September 26.
🕒 2026-09-26 · new reporting from BleepingComputer
  • ShinyHunters uses URL-encoding to bypass WAF rules for Oracle PeopleSoft CVE-2026-35273.
  • Google's Mandiant and Threat Intelligence Group (GTIG) reported the WAF bypass technique.
  • Oracle fixed the PeopleSoft zero-day CVE-2026-35273 on June 11.
  • BleepingComputer first reported ShinyHunters targeting Oracle PeopleSoft servers on June 10.
🕒 2026-09-26 · new reporting from The Hacker News
  • Oracle PeopleSoft flaw CVE-2026-35273 has a CVSS score of 9.8.
  • Oracle PeopleSoft flaw CVE-2026-35273 was first exploited as a zero-day against academic institutions.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 deployed MeshCentral agent for persistence.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 involved lateral movement over SSH.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 ran a shell script to connect to other internal PeopleSoft machines.
  • Exploitation of Oracle PeopleSoft flaw CVE-2026-35273 stole data.
  • Mandiant notified over 100 global organizations about Oracle PeopleSoft flaw CVE-2026-35273.
🕒 2026-09-26 · new reporting from Google Cloud Blog
  • UNC6240 (ShinyHunters) renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273.
  • UNC6240 expanded global targeting across multiple sectors.
  • UNC6240 bypassed WAF rules by URL-encoding a character in the request path.
🕒 2026-09-25 · new reporting from The Hacker News
  • Roundcube flaw CVE-2026-48842 affects versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
  • SentinelOne stated the Roundcube flaw could expose mail account credentials and stored messages.
  • Shadowserver Foundation flagged 10 vulnerable Roundcube hosts as of September 23, 2026.
🕒 2026-09-25 · new reporting from SecurityWeek, Hacker News Front Page
  • Roundcube flaw CVE-2026-48842 has a CVSS score of 8.1.
  • Roundcube flaw CVE-2026-48842 uses preg_replace() filter with backslash escaping.
  • Roundcube flaw CVE-2026-48842 allows bypassing protection using crafted queries with backslash sequences.
  • Roundcube flaw CVE-2026-48842 results in quote characters concatenated into an SQL string.
  • Canadian Centre for Cyber Security warned about Roundcube flaw exploitation.
  • Avast Antivirus flaw CVE-2025-13032 is a double-fetch vulnerability in its kernel driver.
  • Avast Antivirus flaw CVE-2025-13032 allows arbitrary kernel read/write and SYSTEM privilege escalation.
  • Avast Antivirus flaw CVE-2025-13032 was exploited on Windows 11.
  • Avast Antivirus flaw CVE-2025-13032 exploits a controlled paged pool overflow.
  • Avast Antivirus flaw CVE-2025-13032 corrupts the RegBuffers array of the IORing object.
  • Avast Antivirus flaw CVE-2025-13032 uses heap spray strategy and kernel address leak via MDL introspection.
  • Avast Antivirus flaw CVE-2025-13032 requires repairs to avoid blue screen on teardown.
🕒 2026-09-25 · new reporting from The Hacker News
  • CISA added WSO2 flaw CVE-2026-5430 to its KEV catalog.
  • CISA added Adobe Commerce flaw CVE-2026-71362 to its KEV catalog.
  • WSO2 flaw CVE-2026-5430 has a CVSS score of 9.8.
  • WSO2 flaw CVE-2026-5430 is a path traversal vulnerability.
  • WSO2 flaw CVE-2026-5430 affects API Control Plane, API Manager, Traffic Manager, and Universal Gateway.
  • Adobe Commerce flaw CVE-2026-71362 has a CVSS score of 9.1.
  • Adobe Commerce flaw CVE-2026-71362 is an incorrect authorization vulnerability.
  • Adobe Commerce flaw CVE-2026-71362 allows attackers to gain elevated access to sensitive resources.
  • watchTowr observed in-the-wild exploitation of WSO2 flaw CVE-2026-5430 since September 13, 2026.
  • Sansec detected and blocked exploitation attempts for Adobe Commerce flaw CVE-2026-71362 in August 2026.
  • Adobe Commerce flaw CVE-2026-71362 allows attackers to switch a customer session to another customer account.
🕒 2026-09-24 · new reporting from BleepingComputer
  • Roundcube Webmail has a high-severity SQL injection vulnerability (CVE-2026-48842).
  • The Roundcube flaw allows unauthenticated attackers to bypass authentication and execute malicious database commands.
  • The Roundcube flaw impacts thousands of services using the client.
  • The Roundcube flaw was patched in May.
  • The Roundcube flaw is in the virtuser_query built-in plugin.
  • Roundcube versions 1.6.16 and 1.7.1 address the vulnerability.
  • Shadowserver tracks over 523,000 Roundcube instances exposed online.
🕒 2026-09-24 · new reporting from SecurityWeek, BleepingComputer
  • SolarWinds patched two critical RCE flaws (CVE-2026-28324, CVE-2026-28325) in Observability Self-Hosted.
  • SolarWinds Observability Self-Hosted flaws affect versions up to 2026.2.2.
  • SolarWinds Observability Self-Hosted flaws were addressed in version 2026.2.3.
  • CVE-2026-28324 is an insufficient integrity check issue with a CVSS score of 9.8.
  • CVE-2026-28325 is a deserialization of untrusted data weakness with a CVSS score of 8.8.
  • Ransomware gangs are exploiting the TeamCity flaw CVE-2026-63077.
  • CISA added TeamCity flaw CVE-2026-63077 to its KEV catalog on August 5.
🕒 2026-09-23 · new reporting from BleepingComputer
  • Check Point confirmed active exploitation of CVE-2026-85102 and CVE-2026-93616.
  • CISA added CVE-2026-85102 and CVE-2026-93616 to its KEV catalog.
  • Federal agencies must patch CVE-2026-85102 and CVE-2026-93616 by September 25, 2026.
  • CVE-2026-85102 is a pre-authentication RCE in VPN certificate-handling.
  • CVE-2026-93616 is a pre-authentication path traversal flaw in the Management web service.
  • CVE-2026-93616 allows script execution and Java class loading.
  • NCSC-NL alerted about the Security Gateway issue on September 10.
  • Exploitation attempts for CVE-2026-85102 started on September 12.
  • Attackers used VPNs and proxies to hide their location during exploitation.
  • Attackers used certificates with the subject CN=vpn,OU=users,O=gl.
🕒 2026-09-23 · new reporting from The Hacker News
  • MikroTik RouterOS SSH vulnerabilities CVE-2026-67279 and CVE-2026-86060 are chained for full administrative control.
  • The MikroTrick chain combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug (CVE-2026-86060).
  • Exploitation of MikroTrick was observed in logs before September 3.
  • MikroTik shipped patches for MikroTrick in RouterOS versions 6.49.21, 7.23.4, and 7.24.2.
  • CVE-2026-67279 breaks the SSH authentication sequence by sending SSH_MSG_USERAUTH_SUCCESS prematurely.
🕒 2026-09-23 · new reporting from The Hacker News, BleepingComputer
  • CVE-2026-80521 is a use-after-free flaw in Linux kernel's AF_UNIX socket subsystem.
  • The Linux kernel AF_UNIX socket flaw allows container escape and root access on the host.
  • The Linux kernel AF_UNIX socket flaw was fixed upstream on August 6.
  • Ubuntu has not patched its 26.04, 24.04, and 22.04 LTS releases for CVE-2026-80521.
  • DepthFirst released exploit code targeting Ubuntu 26.04 for CVE-2026-80521.
  • The Linux kernel AF_UNIX socket flaw affects newer kernel packages for AWS, Azure, and GCP workloads.
  • The Linux kernel AF_UNIX socket flaw is in the kernel's garbage collector for AF_UNIX sockets.
  • The Linux kernel AF_UNIX socket flaw can be reached from inside a container.
  • InfraTrust Pulse report indicates a rise in attacks targeting network management systems.
  • InfraTrust tracked 158 new security advisories across 17 vendors between August 25 and September 17.
  • InfraTrust tracked 1,699 vulnerabilities in its latest report.
  • 42 of the tracked advisories were rated critical.
  • Eight of the tracked advisories had a maximum CVSS score of 10.0.
  • 71 of the tracked advisories could be exploited remotely without authentication.
🕒 2026-09-23 · new reporting from BleepingComputer
  • CISA added CVE-2026-93952 to its KEV catalog.
  • The Arista VCO flaw allows remote attackers to access privileged internal VCO host functionality without authentication.
  • Exploitation of the Arista VCO flaw requires access to the public portion of the VeloCloud Edge authentication certificate.
  • The Arista VCO flaw requires network access to the VCO web interface.
🕒 2026-09-23 · new reporting from BleepingComputer, SecurityWeek, The Hacker News
  • F5 patched a critical zero-day vulnerability in BIG-IP APM.
  • The F5 BIG-IP APM flaw is CVE-2026-94127 with a CVSS score of 9.8 (v3.1) and 9.3 (v4.0).
  • The F5 BIG-IP APM flaw is a heap-based buffer overflow.
  • The F5 BIG-IP APM flaw affects versions 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3.
  • The F5 BIG-IP APM flaw is exploitable when an APM access policy and OAuth profile are configured on a virtual server.
  • The F5 BIG-IP APM flaw is exploitable when APM functions as an OAuth authorization server.
  • The F5 BIG-IP APM flaw affects BIG-IP systems in Appliance mode.
  • The F5 BIG-IP APM flaw is a data plane issue.
  • Arista released patches for VCO versions 5.2.3.16 and 6.4.2.8.
  • The Arista VCO flaw is an improper input validation issue.
🕒 2026-09-23 · new reporting from SecurityWeek
  • Check Point released R82.20 Security Hotfix (TAR) for CVE-2026-93616.
  • Check Point included fixes for CVE-2026-93616 in Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192).
  • Check Point advises limiting access to Management Server behind a security gateway or firewall as mitigation for CVE-2026-93616.
  • Check Point advises limiting access to port TCP/19009 to trusted IP addresses as mitigation for CVE-2026-93616.
  • Standard LivePatch updates do not apply to CVE-2026-93616.
🕒 2026-09-22 · new reporting from The Hacker News
  • Check Point's CVE-2026-93616 was exploited in targeted attacks on July 23.
  • Check Point released a fix for CVE-2026-93616 on September 22.
  • Attackers have been trying to exploit Check Point's VPN flaw CVE-2026-85102 since September 12.
  • Exploitation attempts for CVE-2026-85102 targeted customers of Spark, Check Point's firewall line for small businesses.
🕒 2026-09-22 · new reporting from BleepingComputer, The Hacker News
  • Check Point patched a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server.
  • The Check Point flaw allows unauthenticated attackers to upload and execute arbitrary scripts.
  • The Check Point flaw affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
  • Check Point addressed CVE-2026-93616 in R82.20 Security Hotfix.
  • CISA and FBI urged software companies to remove path traversal weaknesses.
  • Bifrost, an open-source AI gateway, has a critical vulnerability (CVE-2026-90898) allowing unauthenticated command execution.
  • The Bifrost flaw affects versions before 2.1.0 when management authentication is disabled by default.
  • The Bifrost flaw has a CVSS score of 9.8.
  • The Bifrost flaw was discovered by Yuval Moravchick of JFrog Security Research.
  • The Bifrost flaw allows attackers to register a stdio-type MCP client via a single unauthenticated POST request.
  • The Bifrost flaw allows access to API keys for over 20 LLM providers.
  • The official Bifrost Docker image binds the management API to 0.0.0.0, making it externally reachable.
🕒 2026-09-22 · new reporting from The Hacker News, BleepingComputer
  • Arista announced a new critical vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator.
  • CVE-2026-93952 affects VCO deployments configured for certificate-based authentication.
  • CVE-2026-93952 can lead to full compromise of the orchestrator and managed Edge devices.
  • Fixed releases for CVE-2026-93952 are out for VCO 5.2 and 6.4 release trains.
  • D-Link warned of a critical zero-day stack-based buffer overflow vulnerability in DIR-822A routers.
  • The D-Link flaw is in the DHCP server component and can be exploited without authentication.
  • The D-Link flaw allows attackers to send crafted DHCP packets to trigger an overflow.
  • A public proof-of-concept exploit exists for the D-Link DIR-822A router flaw.
🕒 2026-09-22 · new reporting from SecurityWeek
  • A Chinese threat actor exploited Zyxel GS1900 series switch vulnerability CVE-2026-7273 to exfiltrate sensitive information from devices in 48 countries.
  • The Zyxel GS1900 series switch exploitation used a heavily obfuscated Python script.
  • The Zyxel GS1900 series switch exploitation exfiltrated hashed root credentials, configuration details, and networking information.
  • The Zyxel GS1900 series switch exploitation targeted firmware versions 2.10-2.90 of the GS1900-24.
  • 564 compromised Zyxel GS1900 series switches had factory default credentials.
🕒 2026-09-22 · new reporting from The Hacker News, BleepingComputer
  • CISA added Zyxel GS1900 series switch vulnerability CVE-2026-7273 to its KEV catalog on Monday.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 has a CVSS score of 8.8.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 is a stack-based buffer overflow.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 allows LAN-based, unauthenticated attackers to execute OS commands via crafted HTTP requests.
  • Zyxel released an advisory for CVE-2026-7273 in June 2026.
  • Zyxel GS1900 series switch vulnerability CVE-2026-7273 was fixed in versions 2.90(AAHH.2)C0, 2.90(AAHI.2)C0, 2.90(AAZI.2)C0, 2.90(AAHJ.2)C0, 2.90(AAHL.2)C0, and 2.90(AAHK.2)C0.
  • CISA mandated federal agencies patch Zyxel GS1900 series switch vulnerability CVE-2026-7273 by Thursday.
  • Zyxel released security updates for CVE-2026-7273 on June 16.
  • Veeam Agent for Windows has a local privilege escalation flaw (CVE-2026-32996).
  • Veeam Agent for Windows flaw CVE-2026-32996 allows attackers to gain SYSTEM-level control.
🕒 2026-09-21 · new reporting from BleepingComputer
  • Linux kernel flaw CVE-2025-39964 existed for 14 years.
  • CISA mandates federal agencies apply security updates and mitigations for Linux kernel flaws by end of today.
  • CISA mandates federal agencies conduct forensic triage on affected Linux kernel assets.
  • Public exploits are available for two of the Linux kernel flaws.
  • Linux kernel flaw CVE-2025-39964 is a race condition in AF_ALG cryptographic socket interface.
  • Linux kernel flaw CVE-2026-53266 is an out-of-bounds write in ebtables SNAT implementation.
  • Linux kernel flaw CVE-2025-39682 is a TLS receive-path logic flaw.
🕒 2026-09-21 · new reporting from The Hacker News
  • Cisco warned of an actively exploited maximum-severity authentication bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE).
  • The Cisco ISE vulnerability (CVE-2026-76460) has a CVSS score of 10.0.
  • The Cisco ISE flaw (CVE-2026-76460) is due to insufficient authentication control on an API endpoint.
  • Exploiting the Cisco ISE flaw (CVE-2026-76460) allows an unauthenticated, remote attacker to bypass the web-based management interface.
🕒 2026-09-21 · new reporting from SecurityWeek
  • Linux kernel flaw CVE-2025-39682 has a CVSS score of 9.8.
  • Linux kernel flaw CVE-2025-39682 is a critical zero-length record handling issue in the TLS receive path.
  • Linux kernel flaw CVE-2025-39682 allows a local attacker to cause DoS or memory disclosure.
  • Linux kernel flaw CVE-2025-39964 has a CVSS score of 7.8.
🕒 2026-09-19 · new reporting from The Hacker News
  • SolarWinds patched a high-severity RCE flaw (CVE-2026-28326) in Access Rights Manager (ARM).
  • The SolarWinds ARM flaw has a CVSS score of 8.8.
  • The SolarWinds ARM flaw affects all versions of Access Rights Manager 2026.2 and prior.
  • The SolarWinds ARM flaw is due to a hard-coded static key.
  • SolarWinds fixed the ARM flaw in version 2026.2.1.
  • Kai Huang of Armadin Security discovered and reported the SolarWinds ARM flaw.
  • SolarWinds previously fixed a critical SAML authentication bypass flaw (CVE-2026-28323) in Web Help Desk (WHD).
  • SolarWinds also fixed a DoS vulnerability (CVE-2026-28299) with a CVSS score of 8.2.
🕒 2026-09-19 · new reporting from The Hacker News
  • CISA added three Linux kernel vulnerabilities to its KEV catalog on Friday.
  • The Linux kernel flaws are CVE-2025-39682 (memory disclosure/DoS), CVE-2026-53266 (DoS/privilege escalation), and CVE-2025-39964 (DoS/data integrity).
  • Red Hat issued high-priority advisories for the Linux kernel vulnerabilities.
  • Orkes Conductor flaw CVE-2026-58138 has a CVSS v4 score of 9.3.
  • Orkes Conductor flaw CVE-2026-58138 affects versions 3.21.21 before 3.30.2.
  • Orkes Conductor flaw CVE-2026-58138 is exploited by submitting inline workflow definitions to the workflow API endpoint.
  • Orkes Conductor flaw CVE-2026-58138 uses INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke system commands.
🕒 2026-09-18 · new reporting from BleepingComputer
  • Check Point flaw CVE-2026-91843 affects Security Management Server deployments.
  • Check Point flaw CVE-2026-91843 allows unprivileged attackers to gain root RCE.
  • Check Point flaw CVE-2026-91843 has low complexity and requires no user interaction.
  • Check Point provided temporary mitigation measures for CVE-2026-91843.
  • Check Point flaw CVE-2026-91843 is not actively exploited.
  • Check Point security teams can identify CVE-2026-91843 attacks by looking for "Admin" in logs.
🕒 2026-09-18 · new reporting from SecurityWeek
  • Kaspersky and Tanium patched severe product vulnerabilities.
  • Tanium fixed two high-severity SQL injection flaws in Tanium Asset.
  • Orkes Conductor vulnerability CVE-2026-58138 is actively exploited.
  • Orkes Conductor flaw CVE-2026-58138 allows RCE via malicious JavaScript or Python expressions.
  • Orkes Conductor flaw CVE-2026-58138 has a CVSS score of 9.8.
  • Orkes Conductor flaw CVE-2026-58138 is exploited via inline workflow definitions to the workflow API endpoint.
  • Orkes Conductor flaw CVE-2026-58138 exploits GraalVM context configured with HostAccess.ALL.
  • Orkes Conductor flaw CVE-2026-58138 allows code to reflect into Java runtime and execute OS commands.
  • Orkes Conductor flaw CVE-2026-58138 has been exploited for at least a month.
  • Orkes Conductor does not enforce authentication by default.
🕒 2026-09-18 · new reporting from The Hacker News
  • Docker Sandboxes for macOS has a critical vulnerability (CVE-2026-77179).
  • The Docker Sandboxes flaw allows malicious guest code to read and modify macOS host files.
  • The Docker Sandboxes flaw affects versions 0.28.0 up to 0.42.0 on macOS.
  • Docker fixed the Sandboxes flaw in version 0.42.0 on September 7.
  • Check Point Security Management and Log Servers have a critical vulnerability (CVE-2026-91843).
  • The Check Point flaw allows unauthenticated attackers to execute code as root.
  • The Check Point flaw is a stack overflow in the login process, triggered by a long username.
  • The Check Point flaw has a CVSS score of 9.8.
  • The Check Point flaw is exploitable only through the Trusted Clients setting.
  • Check Point released a fix for the flaw via its LivePatch update channel on September 16, 2026.
🕒 2026-09-14 · new reporting from SecurityWeek
  • CVE-2026-42018 was patched on August 12.
  • CVE-2026-42016 was patched on July 27.
🕒 2026-09-12 · new reporting from The Hacker News
  • CISA added ConnectWise ScreenConnect flaw CVE-2026-84869 to its KEV catalog.
  • ConnectWise ScreenConnect flaw CVE-2026-84869 has a CVSS score of 9.9.
  • ConnectWise ScreenConnect flaw CVE-2026-84869 allows unauthorized file transfer and execution.
  • CISA added MikroTik RouterOS flaw CVE-2026-67277 to its KEV catalog.
  • MikroTik RouterOS flaw CVE-2026-67277 has a CVSS score of 8.8.
🕒 2026-09-12 · new reporting from BleepingComputer
  • NCSC-NL warns of imminent exploitation of Check Point VPN flaws.
  • Check Point VPN flaws affect R81.10.x and R82.00.x versions.
🕒 2026-09-11 · new reporting from BleepingComputer
  • Attackers deploy a Rust-based backdoor on JFrog Artifactory self-hosted servers.
  • The JFrog Artifactory flaws allow attackers to execute arbitrary commands and steal configuration data.
  • Attackers establish persistence on JFrog Artifactory servers.
  • Wiz confirmed exploitation of JFrog Artifactory flaws across multiple environments.
  • Attackers obtain a JSON Web Token (JWT) for an internal anonymous user via CVE-2026-42018.
  • Attackers increase permissions to admin level by exploiting CVE-2026-42016.
  • Attackers created an administrator account in less than five minutes in some JFrog Artifactory attacks.
🕒 2026-09-11 · new reporting from SecurityWeek
  • Check Point flaws CVE-2026-85102 and CVE-2026-85103 have a CVSS score of 9.8.
  • CVE-2026-85102 affects Security Gateway and Spark Firewall using Site to Site VPN or Remote Access VPN.
  • CVE-2026-85103 impacts Security Management Server, Security Gateway, and Spark Firewall.
  • Security updates for Check Point flaws were released for versions R82.10, R82, and R81.20.
  • Check Point recommends manually defining VPN rules as a mitigation for the flaws.
  • The mitigation does not apply to locally managed Spark Firewall instances.
🕒 2026-09-11 · new reporting from The Hacker News
  • The critical Cisco FMC flaw CVE-2026-20079 has a CVSS score of 10.0.
  • The Cisco FMC flaw CVE-2026-20316 allows an unauthenticated remote attacker to log in with a low-privilege account.
  • UAT-12197 deployed JSP-based web shells and a Java Archive (JAR)-based command executor.
  • Attackers chained JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016.
  • Wiz observed JFrog Artifactory attacks between August 15 and September 8.
  • CVE-2026-42018 makes Artifactory hand an internal anonymous-user token to an unauthenticated caller.
  • CVE-2026-42016 allows a low-privilege token to be swapped for an administrator-scoped token.
🕒 2026-09-10 · new reporting from BleepingComputer
  • Cisco Talos reported two Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, were exploited by three threat clusters.
  • The threat clusters include ransomware affiliates and state-sponsored actors.
  • Attackers used the FMC flaws to deploy web shells, steal credentials, create reverse shells and proxies.
  • Attackers deployed Qilin ransomware and Cyclops Blink malware via the FMC flaws.
  • Cisco is tracking the threat clusters as UAT-12197, UAT-11823, and UAT-11988.
  • CVE-2026-20316 is a static credential vulnerability with a CVSS score of 5.3.
🕒 2026-09-10 · new reporting from The Hacker News
  • Check Point patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products.
  • The Check Point flaws affect Security Gateways and Security Management Servers.
  • Check Point disclosed the flaws and began delivering fixes on September 9.
  • Check Point discovered the flaws internally and has no indication of exploitation.
  • CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation.
  • CVE-2026-85103 is a heap-based buffer overflow during ASN.1 structure decoding of a VPN certificate.
🕒 2026-09-10 · new reporting from SecurityWeek, The Hacker News
  • Cisco and CISA warned about active exploitation of CVE-2026-20079 on Wednesday.
  • CVE-2026-20079 allows attackers to run malicious scripts on vulnerable devices.
  • Cisco patched CVE-2026-20079 in early March.
  • Cisco updated its advisory for CVE-2026-20079 with IoCs in late July.
  • Cisco updated its advisory for CVE-2026-20079 on September 9.
  • CISA added CVE-2026-20079 to its KEV catalog, mandating federal agencies patch by September 12.
  • CISA added CVE-2026-19490 to its KEV catalog, mandating federal agencies patch within three days.
  • Citrix patched CVE-2026-19490 on August 19.
  • Rapid7 warned that CVE-2026-19490 could be exploited remotely without authentication.
  • Rapid7 expected threat actors to exploit CVE-2026-19490 shortly after patching.
🕒 2026-09-10 · new reporting from SecurityWeek, BleepingComputer
  • Fortinet RCE flaw CVE-2025-25249 (CVSS 7.4) is a heap-based buffer overflow.
  • Fortinet RCE flaw CVE-2025-25249 was patched in January in FortiOS and FortiSwitchManager.
  • SOCRadar reported hackers exploiting Fortinet flaw CVE-2025-25249 to deploy PivotC2 RAT.
  • PivotC2 RAT is a FortiGate post-exploitation tool providing interactive shell access.
  • SOCRadar believes PivotC2 was developed using AI and used in attacks since July 2026.
  • Fortinet flaw CVE-2025-25249 exploitation infected 178 devices, mainly targeting US entities.
  • WatchGuard Firebox RCE flaw CVE-2025-14733 is being exploited by ransomware groups.
  • WatchGuard Firebox flaw CVE-2025-14733 is an out-of-bounds write.
  • WatchGuard Firebox flaw CVE-2025-14733 affects Fireware OS 11.x, 12.x, and 2025.1 through 2025.1.3.
  • WatchGuard Firebox flaw CVE-2025-14733 was patched in December.
  • WatchGuard Firebox flaw CVE-2025-14733 is vulnerable if configured to use IKEv2 VPN.
  • Shadowserver found over 115,000 unpatched Firebox firewalls exposed online in December.
  • Nearly 9,000 WatchGuard Firebox instances remain unsecured after nine months.
🕒 2026-09-09 · new reporting from SecurityWeek
  • Fortinet patched 10 vulnerabilities across its products.
  • Fortinet critical flaw CVE-2026-84390 (CVSS 9.6) affects FortiMonitorOnSight web portal.
  • CVE-2026-84390 allows remote, unauthenticated attackers to bypass authentication via a forged JWT.
  • Fortinet critical flaw CVE-2026-84388 (CVSS 9.1) affects Privileged Access Agent Chrome extension.
  • CVE-2026-84388 allows remote, unauthenticated attackers to proxy user's browser traffic.
  • FortiPAM must be upgraded to 1.9.1 or 1.8.4, and Chrome extension to 8.0.1.123+ for CVE-2026-84388.
  • Fortinet also patched high-severity bugs in FortiSandbox (CVE-2026-26084) and FortiOS/FortiProxy Agentless ZTNA portal.
🕒 2026-09-09 · new reporting from SecurityWeek
  • Ivanti patched critical and high-severity vulnerabilities in Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM).
  • Ivanti Neurons for ITSM received fixes for eight bugs, six critical and two high-severity.
  • CVE-2026-12647, CVE-2026-12645, and CVE-2026-12646 are critical missing authorization issues in Neurons for ITSM.
  • CVE-2026-12650, CVE-2026-12744, and CVE-2026-12745 are critical deserialization of untrusted data weaknesses in Neurons for ITSM.
  • CVE-2026-12651 and CVE-2026-12648 are high-severity deserialization of untrusted data defects in Neurons for ITSM.
  • CVE-2026-12744 and CVE-2026-12745 in Neurons for ITSM can be exploited without authentication.
  • Neurons for ITSM vulnerabilities were addressed in September 2026 security updates for versions 2025.2, 2025.3, 2025.4, and 2026.1.
  • Neurons for ITSM version 2026.2, scheduled for September 21, will include the fixes.
🕒 2026-09-09 · new reporting from The Hacker News
  • The SAP flaw CVE-2026-44756 stems from missing boundary validation during EPP data deserialization.
  • The SAP flaw CVE-2026-44756 is triggered by processing externally supplied length fields.
  • The SAP flaw CVE-2026-44756 allows attackers to run OS commands with SAP administrative privileges.
  • The SAP flaw CVE-2026-44756 can lead to total compromise of SAP business data and processes.
  • The SAP flaw CVE-2026-44756 can be exploited by sending crafted network requests with a malformed EPP header.
  • The SAP flaw CVE-2026-44756 can cause abnormal program termination.
  • The SAP flaw CVE-2026-44756 resides in the SAP kernel.
  • cPanel patched CVE-2026-67401, allowing authenticated hosting accounts with mail privileges to run code as root.
  • The cPanel flaw CVE-2026-67401 allows creating files on the server through EmailTrack.
  • The cPanel flaw CVE-2026-67401 affects all supported versions of cPanel and WHM.
  • cPanel published the advisory for CVE-2026-67401 on September 8.
  • The cPanel flaw CVE-2026-67401 is an SQL injection issue in EmailTrack.
  • The cPanel flaw CVE-2026-67401 allows an attacker to gain full administrative access to the server.
  • The cPanel flaw CVE-2026-67401 allows an attacker to compromise all hosted accounts.
🕒 2026-09-09 · new reporting from The Hacker News
  • CISA added N-able N-central flaw CVE-2026-86218 to its KEV catalog on Tuesday.
  • Federal agencies must patch N-able N-central flaw CVE-2026-86218 by September 11, 2026.
  • N-able N-central Hotfix 4 was released on September 5, 2026.
  • Huntress began investigating a compromise of a customer's N-central environment on September 4, 2026.
🕒 2026-09-08 · new reporting from SecurityWeek, BleepingComputer
  • The SAP flaw CVE-2026-44756 is a memory corruption issue in Extended Passport Processing (EPP).
  • The SAP flaw CVE-2026-44756 is dubbed OVERPASS by Onapsis.
  • The SAP flaw CVE-2026-44756 allows unauthenticated attackers to execute arbitrary system commands and access sensitive data.
  • The SAP flaw CVE-2026-44756 impacts various SAP products.
  • The SAP flaw CVE-2026-44756 is triggered when a new user session is opened from client to server.
  • The SAP flaw CVE-2026-44756 can be exploited over SAP Internet Communication Manager (ICM).
  • More than 10,000 internet-facing SAP systems are potentially exposed to the CVE-2026-44756 flaw.
🕒 2026-09-08 · new reporting from SecurityWeek
  • N-able patched CVE-2026-86218 after patching CVE-2026-86206 and CVE-2026-86207.
  • N-able observed scans for CVE-2026-86218 from IP range 23.234.64.0/18.
  • N-able advises administrators to check for newly created user accounts.
🕒 2026-09-07 · new reporting from The Hacker News
  • N-able patched two severe N-central flaws (CVE-2026-86206, CVE-2026-86207) allowing authentication bypass and full platform access.
🕒 2026-09-07 · new reporting from The Hacker News
  • TantoSec released a public exploit for Telerik UI for ASP.NET AJAX vulnerabilities.
  • The Telerik UI exploit targets a specific non-default configuration.
  • Progress Software fixed the Telerik UI flaws in version 2026.2.708 (2026 Q2 SP1) on July 8.
  • Progress Software published CVEs and an advisory for Telerik UI flaws on July 22.
  • TantoSec's Marcio Almeida released a command-line tool, telerik-rau-exploit, for the Telerik UI flaws.
  • The Telerik UI exploit includes two mixed-mode DLL payloads.
🕒 2026-09-07 · new reporting from The Hacker News
  • N-able issued its fourth N-central hotfix in five weeks.
  • The N-central flaw (CVE-2026-86218) has a CVSS 4.0 score of 10.0.
  • The N-central flaw is a static code injection weakness (CWE-96).
  • The N-central flaw affects all on-premises N-central builds prior to 2026.3.1.14.
  • N-able's communications disagree on whether the N-central flaw has been exploited in the wild.
  • N-central Hotfix 4 (2026.3.1.14) was shipped in the early hours of September 6 (UTC).
  • N-able had published Hotfix 3 (2026.3.1.13) eight hours earlier for unrelated flaws.
  • Hosted N-central (NCOD) instances have already been patched for the flaw.
🕒 2026-09-07 · new reporting from BleepingComputer
  • N-able patched a critical RCE flaw (CVE-2026-86218) in its N-central RMM platform.
  • The N-central flaw allows unprivileged attackers to execute code on unpatched systems.
  • N-able released N-central 2026.3 Hotfix 4 to address the vulnerability.
  • Shadowserver tracks nearly 1,500 N-central servers exposed online.
  • Huntress flagged the N-central flaw as a potential zero-day.
🕒 2026-09-05 · new reporting from The Hacker News
  • Broadcom credited @h4urek, @cameudis, and Stan S for discovering CVE-2026-59346.
  • Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab reported CVE-2026-59347.
  • The TeamCity flaw allowed attackers to access AWS credentials and user data.
  • Cadence is a JetBrains-hosted cloud computing service for machine learning workloads.
  • Cadence integrates with PyCharm via an optional plugin.
🕒 2026-09-05 · new reporting from The Hacker News
  • Attackers exploit PaperCut flaws (CVE-2026-81578, CVE-2026-82078) to steal credentials from schools and universities.
  • PaperCut flaws involve an authentication bypass and remote code execution chain.
  • Post-exploitation activity includes Windows registry hive collection tools and Metasploit/Meterpreter Java payloads.
  • Attackers created privileged accounts like 'Administrator17' and ran discovery commands.
  • Inbound GET requests from 45.142.193[.]132 targeted /custom/pcp_*.txt and /custom/web/pcp_*.txt files.
🕒 2026-09-04 · new reporting from Hacker News Front Page
  • Ruby on Rails ActiveStorage vulnerability CVE-2026-66066 was dubbed KindaRails2Shell.
  • The Ruby on Rails flaw affects ActiveStorage in Ruby on Rails 8 and newer.
  • Ethiack was one of the research teams that discovered the Ruby on Rails flaw.
🕒 2026-09-04 · new reporting from SecurityWeek
  • HPE patched 34 CVEs in ArubaOS-CX.
  • Over 150 flaws were resolved in ArubaOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
  • Nearly two dozen issues are tracked collectively as CVE-2026-73749.
  • The ArubaOS-CX critical flaws are due to improper processing of malformed input to an unnamed service.
  • ArubaOS-CX updates resolved 22 high-severity CVEs leading to DoS, RCE, command execution, script execution, authentication bypass, privilege escalation, and info disclosure.
  • The remaining 11 ArubaOS-CX CVEs are medium-severity access control flaws.
🕒 2026-09-04 · new reporting from SecurityWeek, BleepingComputer
  • Sangoma Switchvox flaw has a CVSS score of 9.3.
  • The Sangoma Switchvox flaw is in an endpoint that processes XML content.
  • Citrix NetScaler flaw CVE-2026-19490 is being actively exploited.
  • Previdian founder Ryan Dewhurst confirmed exploitation of CVE-2026-19490 on Thursday.
  • A NetScaler sensor received requests targeting CVE-2026-19490 on September 3.
🕒 2026-09-04 · new reporting from SecurityWeek
  • Broadcom patched two critical vulnerabilities, CVE-2026-59346 and CVE-2026-59347, in VMware Workstation and Fusion.
  • CVE-2026-59346 is an integer overflow (CVSS 9.3) allowing code execution from a VM with VMXNET3 adapter.
  • CVE-2026-59347 is a stack-based buffer overflow (CVSS 8.1) allowing code execution from a VM.
  • The VMware Workstation and Fusion flaws affect versions 25H2 and 26H1.
  • The VMware Workstation and Fusion flaws were fixed in version 26H1u1.
🕒 2026-09-03 · new reporting from The Hacker News, BleepingComputer
  • Cisco patched a critical vulnerability (CVE-2026-20212) in 10 Silicon One-based Nexus 9000 switches.
  • The Nexus 9000 flaw (CVE-2026-20212) has a CVSS score of 9.8.
  • The Nexus 9000 flaw (CVE-2026-20212) is due to unrestricted IP address binding on TCP ports 43210 and 43211.
  • Exploitation of the Nexus 9000 flaw can crash the S1HAL process and reload the device.
  • HPE patched a critical remote code execution vulnerability (CVE-2026-73749) in ArubaOS-CX.
  • The ArubaOS-CX flaw (CVE-2026-73749) is a buffer overflow.
  • The ArubaOS-CX flaw (CVE-2026-73749) allows unauthenticated remote attackers to execute code with elevated privileges.
  • ArubaOS-CX versions 10.18.0001, 10.17.1021, 10.16.1051, 10.13.1180, and 10.10.1180 and earlier are affected by CVE-2026-73749.
  • ArubaOS-CX fixed CVE-2026-73749 in versions 10.18.1002+, 10.17.1030+, 10.16.1060+, 10.13.1190+, and 10.10.1181+.
🕒 2026-09-03 · new reporting from SecurityWeek
  • Cisco warned about two unpatched medium-severity flaws in its Secure Email product.
  • The Secure Email flaws are CVE-2026-20354 and CVE-2026-20355.
  • The Secure Email flaws affect S/MIME decryption functionality.
  • The Secure Email flaws allow attackers to intercept and modify traffic between email gateways.
  • A successful exploit of the Secure Email flaws could allow obtaining plaintext content from encrypted communication.
  • All Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
  • Cisco is not aware of in-the-wild exploitation of the Secure Email flaws.
  • Cisco released patches for critical-severity flaws in IOS XR and Nexus 9000 series switches.
🕒 2026-09-03 · new reporting from The Hacker News
  • CISA added seven vulnerabilities to its KEV catalog on Wednesday.
  • The KEV catalog additions include flaws in Kludex, Kestra, and Berri LiteLLM products.
🕒 2026-09-02 · new reporting from BleepingComputer
  • Horizon3 discovered 12 flaws in Sangoma Switchvox and reported them on April 10.
  • The Sangoma Switchvox flaw is in the /pa HTTP endpoint.
  • The Sangoma Switchvox flaw allows SQL injection via the PhoneIP field in an XML message.
🕒 2026-09-02 · new reporting from BleepingComputer
  • The JFrog Artifactory flaw is present in the default configuration of self-managed instances.
  • The JFrog Artifactory flaw could compromise software supply chains by replacing trusted artifacts with malicious code.
🕒 2026-09-02 · new reporting from SecurityWeek
  • Rockwell Automation patched over a dozen vulnerabilities across its industrial automation products.
  • Rockwell Automation released patches for four critical and high-severity DoS issues in RSLinx Classic.
  • Rockwell Automation fixed a high-severity RCE issue in FactoryTalk Historian.
  • Rockwell Automation resolved a privilege escalation flaw in FactoryTalk Activation Manager.
  • Rockwell Automation addressed DoS vulnerabilities in 1756-ENBT and Logix controllers.
🕒 2026-09-02 · new reporting from The Hacker News, SecurityWeek
  • SonicWall's William Perry and Adam Babis discovered the SMA1000 vulnerabilities.
  • CVE-2026-83549 is a post-authentication OS command injection.
  • Cleo Harmony has an authentication bypass vulnerability CVE-2026-84115.
  • The Cleo Harmony flaw allows privilege escalation via JWT refresh token manipulation.
  • The Cleo Harmony flaw is in an unknown function in '/api/connections'.
  • Cleo Harmony vulnerability CVE-2026-84115 was addressed in version 5.8.1.11.
🕒 2026-09-02 · new reporting from BleepingComputer, The Hacker News
  • SonicWall SMA1000 flaws are CVE-2026-83548 (command injection) and CVE-2026-83549 (command injection).
  • SonicWall SMA1000 CVE-2026-83548 is a pre-authentication SSRF in the Appliance WorkPlace interface.
  • SonicWall SMA1000 CVE-2026-83549 is a command injection in the Appliance Management Console.
  • SonicWall SMA1000 flaws affect models 6210, 7210, and 8200v.
  • Shadowserver tracks over 400 SMA1000 appliances exposed online.
  • Sangoma Switchvox SMB Edition 8.3 has a critical SQL injection vulnerability (CVE-2026-9586).
  • Sangoma Switchvox flaw allows unauthenticated attackers to execute code as PostgreSQL superuser.
  • Sangoma Switchvox flaw affects approximately 4,000 internet-exposed instances, primarily in the U.S.
  • Sangoma Switchvox flaw was patched in version 8.4.0.2 on July 14, 2026.
  • Sangoma Switchvox flaw allows attackers to deploy reverse shells.
  • GeoNetwork has two vulnerabilities (CVE-2026-63219, CVE-2026-58400) that can be chained for RCE.
  • GeoNetwork released fixes in versions 4.4.12 and 4.2.17 on July 8, 2026.
  • GeoNetwork vulnerability details were published on August 31.
  • GeoNetwork flaw CVE-2026-63219 is a missing authorization check on the formatter upload endpoint.
  • GeoNetwork flaw CVE-2026-63219 allows unauthenticated file upload of .xsl or .zip formatter files.
🕒 2026-09-02 · new reporting from SecurityWeek
  • SonicWall SMA1000 zero-days are CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8).
  • CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface.
  • CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC).
  • SonicWall observed exploitation of both SMA1000 vulnerabilities chained in attacks.
  • Affected SMA1000 models are 6210, 7210, and 8200v.
  • SMA1000 hotfixes 12.4.3-03526 and 12.5.0-02952 patch the vulnerabilities.
🕒 2026-09-01 · new reporting from The Hacker News, BleepingComputer
  • The JFrog Artifactory flaw has a CVSS score of 9.8.
  • The JFrog Artifactory flaw affects versions 7.161.0 through 7.161.19, 7.146.0 through 7.146.36, 7.133.0 through 7.133.28, 7.125.0 through 7.125.19, 7.117.0 through 7.117.27, and 7.111.4 through 7.111.21.
  • The JFrog Artifactory flaw allows an unauthenticated attacker to obtain administrative privileges under default configuration.
  • The JFrog Artifactory flaw is an authentication bypass in JFrog Access.
  • The Langflow flaw allows attackers to steal OpenAI API keys and AWS credentials.
  • Attackers exploiting the Langflow flaw query environment variables and check .ssh access and .bash_history size.
🕒 2026-09-01 · new reporting from The Hacker News, SecurityWeek, Tom's Hardware
  • JFrog Artifactory vulnerability CVE-2026-82329 allows unauthenticated attackers to obtain administrative privileges.
  • JFrog Artifactory updates were released on August 28.
  • JFrog Artifactory updates include versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.
  • WatchTowr observed attackers minting admin tokens via CVE-2026-82329.
  • Langflow vulnerability CVE-2026-0768 has a CVSS score of 9.8.
  • Langflow flaw CVE-2026-0768 is in the code validator of the custom component editor.
  • Langflow flaw CVE-2026-0768 allows arbitrary code execution as root without authentication.
  • Langflow flaw CVE-2026-0768 was reported through ZDI in July 2025.
  • Langflow flaw CVE-2026-0768 was publicly disclosed as a zero-day in January 2026.
  • VulnCheck observed exploitation attempts for Langflow flaw CVE-2026-0768 from Russia.
  • VulnCheck observed over 360 exploitation attempts for Langflow flaw CVE-2026-0768 in the UK.
🕒 2026-08-31 · new reporting from SecurityWeek
  • ServiceNow patched a high-severity sandbox escape vulnerability (CVE-2026-6876) with a CVSS score of 8.7.
🕒 2026-08-28 · new reporting from The Hacker News, The New Stack
  • Cosmos EVM flaw (GHSA-7g4w-cg88-2cq2) exploited to drain funds from six blockchains.
  • Cosmos EVM flaw was exploited between August 20 and August 25, 2026.
  • Cosmos Labs was aware of the Cosmos EVM flaw since April 25.
  • Cosmos Labs confirmed the Cosmos EVM flaw affected all chains by August 13.
  • Cosmos EVM flaw affects versions < 0.6.2 and >= 0.7.0 < 0.7.2.
  • Cosmos EVM flaw was fixed in versions v0.6.2 and v0.7.2 on August 19.
  • JetBrains' Cadence cloud development service was compromised.
  • Attackers exploited TeamCity flaw on JetBrains' own unpatched server.
  • The compromised server was api.cadence.jetbrains.com.
🕒 2026-08-28 · new reporting from The Hacker News
  • CISA added ownCloud vulnerability CVE-2023-49105 to its KEV catalog on Thursday.
  • A Chinese-speaking threat actor exploited ownCloud CVE-2023-49105 to target a Philippine nuclear research body.
  • The ownCloud flaw allows unauthenticated file access via WebDAV API if a username is known and no signing-key is configured.
  • The ownCloud vulnerability CVE-2023-49105 affects core versions 10.6.0 through 10.13.0.
  • ownCloud fixed CVE-2023-49105 in version 10.13.1.
  • Hunt.io identified an open directory on 31.58.209[.]241 staging custom Python scripts and offensive security tooling.
  • The open directory contained exfiltrated data from a Philippine nuclear research body and a marine engineering company.
🕒 2026-08-28 · new reporting from The Hacker News, BleepingComputer
  • cPanel patched CVE-2026-65643, allowing authenticated users to achieve root code execution.
  • The cPanel flaw affects domain parking and addon domain functionality.
  • cPanel patched versions 11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, and 11.138.1.7+ (WP Squared).
  • ServiceNow patched three maximum-severity AI Platform vulnerabilities.
  • The ServiceNow flaws include code injection (CVE-2026-18885), privilege escalation (CVE-2026-18886), and SQL injection (CVE-2026-74820).
  • The ServiceNow flaws can be exploited by unauthenticated attackers with low complexity and no user interaction.
  • ServiceNow AI Platform is used by 85% of Fortune 500 companies.
  • VulnCheck discovered two factory implants, SPEAKINGSTONE and DARKLANTERN, in ZBT router firmware.
  • The ZBT router implants are tracked as CVE-2026-74232 and CVE-2026-74233.
  • The ZBT router implants have CVSS 4.0 scores of 9.3 and CVSS 3.1 scores of 9.8.
  • SPEAKINGSTONE sends beacons over UDP port 10000 to a hardcoded C2 server.
  • SPEAKINGSTONE can execute commands, exfiltrate WAN PPPoE credentials, hijack DNS, and open reverse SSH tunnels.
  • ServiceNow published its advisory on August 27, 2026.
  • CVE-2026-18885 is a code injection flaw in the GraphQL Composite Data API.
  • CVE-2026-18886 is an improper access control flaw in the system configuration image upload processor.
  • CVE-2026-74820 is a SQL injection flaw via a dynamic schema ORDER BY clause.
🕒 2026-08-27 · new reporting from The Hacker News
  • Next.js has two critical RCE flaws: one in AVIF image processing, another a Windows path traversal.
  • The Windows path traversal flaw is CVE-2026-75604 with a CVSS score of 9.0.
  • The Windows path traversal flaw affects Next.js applications using Pages Router and App Router without Cache Components.
  • The Windows path traversal flaw only affects servers using a Windows filesystem.
  • Next.js fixes are available in versions 15.5.24 and 16.3.3, published August 25, 2026.
  • The AVIF flaw affects Next.js versions 13.4 through 15.5.
  • Vercel-hosted applications are protected from both Next.js vulnerabilities.
🕒 2026-08-27 · new reporting from The Hacker News, BleepingComputer
  • CISA added six flaws to its KEV catalog on Wednesday.
  • The critical Citrix flaw affects NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA virtual servers.
  • Shadowserver tracks over 22,000 NetScaler ADC appliances and nearly 1,800 Gateway instances exposed online.
🕒 2026-08-27 · new reporting from SecurityWeek
  • CISA issued an urgent directive for government organizations to patch CVE-2026-8452.
  • The Citrix vulnerability is tracked as CVE-2026-8452.
  • Citrix announced patches for CVE-2026-8452 on June 30.
  • Versions 14.1-72.61 (FIPS), 13.1-63.18, and 13.1-37.272 fix CVE-2026-8452.
  • WatchTowr demonstrated CVE-2026-8452 allows unauthenticated remote code execution.
  • WatchTowr made details and PoC code for CVE-2026-8452 public on August 14.
  • Previdian and Defused observed in-the-wild exploitation of CVE-2026-8452.
  • Attackers dropped a web shell and executed discovery commands via CVE-2026-8452.
🕒 2026-08-27 · new reporting from BleepingComputer
  • Avada WordPress theme flaw is a chain of six security issues.
  • Avada WordPress theme flaw involves authorization, input-validation, trust-boundary, and file-handling weaknesses.
  • Avada WordPress theme flaw allows full website compromise.
  • Avada WordPress theme flaw was reported by Defiant's Wordfence team.
🕒 2026-08-26 · new reporting from The Hacker News, BleepingComputer
  • CERT/CC disclosed two unpatched Kaltura mwEmbed vulnerabilities, CVE-2026-19913 and CVE-2026-19912.
  • Kaltura mwEmbed flaws allow unauthenticated remote attackers to read files and execute code.
  • Kaltura mwEmbed vulnerabilities stem from unsafe deserialization in mwEmbedLoader.php endpoint.
  • Kaltura mwEmbed vulnerabilities affect individual customer installations and Kaltura's shared CDN infrastructure.
  • CERT/CC was unable to reach Kaltura to coordinate the mwEmbed vulnerabilities.
  • Administrators should restrict or disable external access to mwEmbedLoader.php and enforce an allow-list for ServiceUrl parameter.
  • Ubiquiti patched three maximum-severity vulnerabilities in UniFi Protect, UniFi Talk, and UniFi OS.
  • Ubiquiti UniFi Protect flaw is an authentication bypass (CVE-2026-77551).
  • Ubiquiti UniFi OS has a CRLF injection flaw (CVE-2026-77550) allowing authentication bypass.
  • Ubiquiti UniFi Talk has a command injection flaw (CVE-2026-77554) due to improper input validation.
  • Ubiquiti fixed flaws in UniFi Protect Application 7.2.105+, UniFi Talk Application 5.3.2+, and UniFi OS Server 5.1.21 and earlier.
🕒 2026-08-25 · new reporting from The Hacker News
  • Marimo patched a high-severity vulnerability (CVE-2026-75149) in its notebook software.
  • The Marimo flaw allowed arbitrary Model Context Protocol (MCP) commands to execute as a local subprocess.
  • The Marimo flaw affects versions prior to 0.23.15.
  • The Marimo flaw allowed code injection before any notebook cells ran.
  • The Marimo flaw has a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8.
  • The Marimo flaw was published on August 19.
  • The Marimo flaw is caused by a crafted notebook supplying an attacker-controlled MCP server command through notebook configuration.
  • Marimo's PEP 723 hardening patch treats notebook metadata as attacker-controlled.
🕒 2026-08-25 · new reporting from BleepingComputer
  • Over 270 Zimbra Collaboration Suite instances were compromised.
  • Zimbra is used by hundreds of millions of people and organizations.
  • CERT Polska warned security teams to check logs for suspicious activity.
  • CISA added the Zimbra flaw to its KEV catalog following CERT Polska's warning.
🕒 2026-08-25 · new reporting from The Hacker News, SecurityWeek
  • CISA added Oracle WebLogic flaw CVE-2026-21962 to KEV catalog on August 24.
  • Federal agencies must patch Oracle WebLogic flaw CVE-2026-21962 by August 27.
  • Oracle WebLogic flaw CVE-2026-21962 is a remote code execution vulnerability.
  • Oracle WebLogic flaw CVE-2026-21962 affects Oracle HTTP Server and WebLogic Server Proxy plugin.
  • Oracle WebLogic flaw CVE-2026-21962 has been exploited since January 2026.
  • CloudSEK first flagged exploitation attempts for Oracle WebLogic flaw CVE-2026-21962.
🕒 2026-08-24 · new reporting from BleepingComputer
  • A Calix GS7 XGS (GS5239XG) residential router vulnerability (CVE-2026-75501) allows remote, unauthenticated attackers to create port-forwarding rules.
  • The Calix flaw bypasses NAT and exposes local network devices.
  • The Calix flaw affects devices running EXOS/6.6.47 firmware.
  • Brian Khan Quintana discovered the Calix flaw and reported it to CERT/CC.
  • Calix is a vendor for Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
  • The affected Calix model GS5239XG is also marketed as the GigaSpire 7u10txg.
  • The Calix GigaSpire 7u10txg combines Wi-Fi 7 with an integrated XGS-PON fiber terminal.
  • The Calix vulnerability is caused by the device exposing "the MiniUPnPd contr".
🕒 2026-08-24 · new reporting from BleepingComputer, The Hacker News, SecurityWeek
  • CISA mandated US government agencies patch the Zimbra flaw within three days.
  • Keycloak vulnerability CVE-2026-18963 allows unauthenticated attackers to reset any user's password.
  • Keycloak flaw CVE-2026-18963 has a CVSS score of 9.1.
  • Keycloak flaw CVE-2026-18963 is classified as CWE-640 (weak password recovery mechanism).
  • Keycloak fixed the flaw in versions 26.7.2, 26.4.15, and 26.6.6.
  • The Keycloak flaw has no evidence of exploitation or public exploit as of August 24, 2026.
  • The Keycloak flaw is due to improper state validation in the reset-credentials authentication flow.
  • Spring application framework released updates patching 91 vulnerabilities.
  • Spring framework's critical vulnerability is CVE-2026-59270.
  • CVE-2026-59270 affects Spring Security's embedded UnboundID LDAP server.
  • CVE-2026-59270 allows an attacker to authenticate and modify entries in the in-memory directory.
  • Sonatype found Spring patches impact over 200,000 software components.
🕒 2026-08-21 · new reporting from The Hacker News
  • Cisco patched nine vulnerabilities in Crosswork and Secure Workload.
  • Five Cisco vulnerabilities have a CVSS score of 10.0.
  • Cisco Crosswork flaws include SQL injection (CVE-2026-20030), missing authentication (CVE-2026-20357), and external control of file system (CVE-2026-20358).
  • Cisco Crosswork also has an insufficiently protected credentials flaw (CVE-2026-20359) with a CVSS of 9.9.
  • Cisco Crosswork vulnerabilities affect Release version 7.2.1 and earlier.
  • Cisco Secure Workload has improper neutralization of special elements flaws (CVE-2026-20231) with a CVSS of 9.9.
🕒 2026-08-20 · new reporting from The Hacker News, SecurityWeek
  • The Zimbra flaw (CVE-2026-73570) has a CVSS score of 8.9.
  • The Zimbra flaw requires the optional zimbra-snmp package to be installed and SNMP notifications enabled.
  • CERT Polska observed active exploitation of the Zimbra flaw this week.
  • The isolated-vm flaw (GHSA-864f-rcv7-6rh4) affects all versions before and including 7.0.0.
  • The isolated-vm flaw was patched in versions 6.2.0 and 7.0.1.
  • Isolated-vm is a Node.js library for running untrusted JavaScript inside a V8 Isolate.
  • The isolated-vm flaw allows untrusted JavaScript to escape its sandboxed environment.
  • The isolated-vm flaw could lead to host memory corruption.
  • The critical Citrix flaw (CVE-2026-19490) affects SecurAccess ZTNA Hybrid deployments.
  • The Citrix vulnerabilities do not apply to Citrix-managed cloud services or Adaptive Authentication.
🕒 2026-08-20 · new reporting from BleepingComputer, SecurityWeek
  • Zimbra RCE flaw (CVE-2026-73570) allows unauthenticated attackers to execute OS commands.
  • Zimbra security team released version 10.1.20 on July 20 to patch CVE-2026-73570.
  • The Zimbra flaw is a command injection weakness in the SNMP monitoring component.
  • Shadowserver tracks over 12,100 Zimbra servers exposed online.
  • MLflow is an open-source AI engineering platform for LLMs and agents.
  • MLflow has over 30 million monthly downloads.
  • The MLflow flaw is a DNS-rebinding server-side request forgery (SSRF) bypass.
  • The MLflow flaw allows unauthenticated attackers to access internal services or cloud metadata configurations.
  • Cisco patched 15 vulnerabilities across its products.
  • Cisco Crosswork version 7.2.1-SP fixed four critical CVEs.
  • Cisco Secure Workload versions 4.0.4.16 and 3.10.9.1 fixed five CVEs.
  • The critical Citrix flaw (CVE-2026-19490) allows authentication bypass when SAML Action is configured.
  • Atlassian patched 10 critical and 162 high-severity issues in third-party dependencies.
  • Splunk patched at least 150 vulnerabilities across its products.
🕒 2026-08-20 · new reporting from SecurityWeek
  • Citrix released patches for two vulnerabilities in NetScaler ADC and NetScaler Gateway.
  • The critical Citrix flaw is CVE-2026-19490, with a CVSS score of 9.3.
  • The Citrix flaw affects NetScaler appliances configured as a gateway or an AAA virtual server.
  • The Citrix flaw impacts NetScaler ADC and NetScaler Gateway versions 14.1-43.56 or later, 14.1-66.68-FIPS or later, 14.1-43.55 or earlier, 13.1-61.28 or later, 13.1-61.27 or earlier, and 13.1 FIPS.
  • Citrix fixed the flaw in versions 14.1-73.32, 13.1-63.21, 14.1-73.32 FIPS, and 13.1-FIPS and 13.1-NDcPP 13.1-37.277.
  • The second Citrix vulnerability is CVE-2026-19489, a high-severity memory overflow issue.
  • CVE-2026-19489 could lead to DoS if SIP ALG is enabled at an LSN group configuration.
  • Secure Private Access Hybrid deployments using NetScaler instances are also affected.
🕒 2026-08-18 · new reporting from The Hacker News
  • Attackers are exploiting MLflow SSRF flaw (CVE-2026-64849) to steal cloud credentials and secrets.
  • MLflow vulnerability CVE-2026-64849 has a CVSS score of 9.3.
  • MLflow flaw CVE-2026-64849 affects versions < 3.15.0.
  • FUXA, an open-source SCADA/HMI software, has a vulnerability (CVE-2026-25895) with a CVSS score of 9.5.
  • FUXA flaw CVE-2026-25895 allows unauthenticated remote attackers to write arbitrary files and achieve RCE.
  • FUXA vulnerability CVE-2026-25895 affects versions <= 1.2.9.
🕒 2026-08-18 · new reporting from The Hacker News
  • CISA added Ray vulnerability CVE-2025-62593 to its KEV catalog on Monday.
  • The Ray vulnerability CVE-2025-62593 has a CVSS score of 9.4.
  • The Ray flaw allows RCE via DNS rebinding attacks in Firefox and Safari.
  • Ray is an open-source, Python-native distributed computing framework.
  • Ray has over 43,500 stars and 7,900 forks on GitHub.
  • Ray maintainers issued an advisory in November 2025 about the flaw.
  • The Ray flaw stems from a lack of authentication on critical endpoints like /api/jobs.
🕒 2026-08-17 · new reporting from The Hacker News
  • The VMware vCenter flaw (CVE-2026-59310) has a CVSS score of 9.8.
  • Exploitation of the VMware vCenter flaw can lead to arbitrary code execution.
  • The VMware vCenter exploitation led to deployment of a backdoor and reverse SSH binary.
  • The VMware vCenter exploitation ultimately led to deployment of Babuk-derived ransomware.
🕒 2026-08-17 · new reporting from The Hacker News
  • GeoServer has a zero-day SQL injection vulnerability (GHSA-mqjf-5f49-2fjh) with a CVSS score of 9.8.
  • The GeoServer flaw was disclosed on August 12, 2026, by @q1uf3ng on X.
  • The GeoServer vulnerability allows RCE in the case of a system administrator database.
  • GeoServer exploitation attempts were observed within hours of public disclosure.
  • GeoServer released versions 3.0.1, 2.28.5, and 2.27.6 to address the flaw.
  • Alfredo Pesoli of Bynario discovered and reported the macOS Screen Sharing flaw.
  • The SAP Commerce Cloud flaw (CVE-2026-58231) is due to insufficient authorization checks and input validation.
  • The SAP Commerce Cloud flaw allows an unauthenticated attacker to abuse a default authentication client.
  • A suspected China-nexus APT is exploiting a Broadcom VMware vCenter flaw (CVE-2026-59310).
  • The VMware vCenter flaw is a directory-traversal vulnerability.
  • Broadcom released a fix for the VMware vCenter flaw on July 29, 2026.
  • The VMware vCenter exploitation campaign has compromised 361 unique IP addresses across 47 countries.
  • QUIRSO attributed the VMware vCenter exploitation to a Chinese-speaking threat actor.
🕒 2026-08-17 · new reporting from SecurityWeek
  • SAP Commerce Cloud vulnerability CVE-2026-58231 was exploited three days after disclosure.
  • The SAP Commerce Cloud flaw has a CVSS score of 10.
  • SAP released patches for CVE-2026-58231 on August 11.
  • Defused honeypots observed exploitation attempts for the SAP Commerce Cloud flaw on August 14.
  • A public PoC exploit for the SAP Commerce Cloud flaw became available on August 15.
  • The SAP Commerce Cloud vulnerability allows arbitrary code execution and compromise of internal components.
  • Apple improved state management mechanisms to fix the macOS Screen Sharing flaw.
🕒 2026-08-16 · new reporting from Tom's Hardware
  • Attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
  • The macOS Screen Sharing flaw allows attackers to gain root access and install Monero cryptocurrency miners.
  • The macOS vulnerability affects Macs with port 5900 exposed to the Internet.
  • Apple patched the macOS flaw on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • CISA raised the CVSS score of the macOS flaw from 7.1 to 9.8 on August 14.
  • The Dutch National Cyber Security Centre (NCSC-NL) reported the macOS exploitation on August 12.
  • NCSC-NL first flagged the macOS vulnerability in an advisory on August 7.
  • Public proof-of-concept code is available for the macOS Screen Sharing flaw.
  • Technical details of the macOS bug were presented at Black Hat conference.
🕒 2026-07-28 · new reporting from SecurityWeek, The Hacker News
  • Arista released patches for the VeloCloud Orchestrator vulnerability on Monday.
  • The VeloCloud Orchestrator flaw is an OS injection vulnerability.
  • JetBrains released updates for a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises.
  • The TeamCity flaw allows unauthenticated attackers to execute arbitrary OS commands.
  • The TeamCity vulnerability affects all TeamCity On-Premises versions.
  • The TeamCity flaw was addressed in versions 2025.11.7 and 2026.1.3.
  • TeamCity Cloud instances have already been updated for the flaw.
  • Antoni Tremblay discovered and reported the TeamCity flaw on July 10, 2026.
  • The TeamCity vulnerability has a CVSS score of 9.8.
  • The TeamCity flaw allows unauthenticated remote code execution via the agent polling protocol.
🕒 2026-07-28 · new reporting from The Hacker News
  • The VeloCloud Orchestrator flaw affects on-premises versions.
  • The flaw was addressed in hosted and dedicated VCO versions earlier.
  • Affected VCO versions include 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1.
🕒 2026-07-28 · new reporting from BleepingComputer
  • Arista patched a maximum-severity command injection vulnerability (CVE-2026-16812) in VeloCloud Orchestrator.
  • The VeloCloud Orchestrator flaw allows unauthenticated remote attackers to compromise the orchestrator and its managed data.
  • The VeloCloud Orchestrator vulnerability has a CVSS score of 10.0.
  • VeloCloud Orchestrator is a centralized management platform for VeloCloud SD-WAN deployments.
  • The flaw allows remote attackers to access privileged functionality intended for internal use.
  • No VCO tenant or operator credentials are needed to exploit the flaw.
  • Arista discovered CVE-2026-16812 externally.
🕒 2026-07-27 · new reporting from The Hacker News
  • A public exploit for vBulletin CVE-2026-61511 was released on July 27.
  • The vBulletin flaw affects versions 6.2.1 and earlier, and 6.1.6 and earlier.
  • vBulletin released fixed version 6.2.2 on July 1.
  • The vBulletin exploit requires no user interaction or authentication.
  • vBulletin Cloud sites have already been patched against the flaw.
🕒 2026-07-27 · new reporting from The Hacker News
  • n8n patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m).
  • The n8n flaw allowed authenticated workflow editors to execute OS commands.
  • Security Joes found the n8n vulnerability while probing a February fix for CVE-2026-27577.
  • Affected n8n versions are <2.31.5 and >=2.32.0,<2.32.1.
  • n8n fixed the flaw in versions 2.31.5 and 2.32.1.
  • The n8n vulnerability has a CVSS 4.0 score of 8.7.
  • Exploitation of the n8n flaw requires a valid account with workflow editing permissions.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~16 min · 14 stories · Oct 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

CISA and Fortinet issued an alert regarding a critical FortiMail zero-day vulnerability (CVE-2026-104286) that is being actively exploited. The flaw allows attackers to write arbitrary files and potentially execute code, with patches not yet released.

A critical zero-day vulnerability in Fortinet FortiMail (CVE-2026-104286) is being actively exploited, allowing unauthenticated attackers to write arbitrary files on affected systems. CISA has added this flaw to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply patches or workarounds by October 4, 2026.

Debian has released a security advisory, DSA-6528-1, addressing numerous vulnerabilities in the Linux kernel. This advisory lists over 100 CVEs, indicating a broad range of security flaws that require patching to maintain system integrity and prevent potential exploits.

Fortinet issued a warning about a critical FortiMail vulnerability (CVE-2026-104286) with a CVSS score of 9.8, which is being actively exploited in zero-day attacks. The flaw allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests to the management interface, enabling unauthorized code execution.

A high-severity OS command injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) was exploited by attackers between the patch release and public disclosure. Attackers used specially crafted SMTP requests to achieve remote code execution, deploy webshells, and exfiltrate credentials.

CISA has added a critical authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. This flaw allows unauthenticated remote attackers to gain admin privileges, making it a significant concern for organizations using the platform.

Cisco released urgent patches for CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager that is actively being exploited. This flaw allows remote, unauthenticated attackers to gain administrative access, affecting all deployments regardless of configuration.

Threat actors are exploiting a critical pre-authentication command injection vulnerability (CVE-2026-88771) in Citrix NetScaler ADC and Gateway to install web shells and exfiltrate configuration data. The exploitation involves attacker-controlled usernames and the deployment of second-stage payloads that create superuser accounts and establish reverse shells, indicating activity beyond basic vulnerability validation.

Microsoft reported that attackers are exploiting CVE-2026-73570, a critical vulnerability in Zimbra Collaboration Suite, to steal email backups and authentication credentials. The flaw allows unauthenticated remote operating system command execution, impacting organizations across various sectors and regions.

Threat actors exploited a patched Zimbra Collaboration Suite (ZCS) vulnerability (CVE-2026-73570) to deploy web shells and access mailbox data. This flaw allowed remote code execution via a crafted SMTP request, impacting organizations across multiple regions and industries.

CISA issued a warning about CVE-2026-84411, a critical pre-authentication integer underflow vulnerability in MikroTik RouterOS that allows remote code execution or denial-of-service. The flaw affects RouterOS versions below 7.24, and users are advised to update to version 7.23 or later to mitigate the risk.

Cisco issued an advisory regarding active exploitation of CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager. This flaw allows unauthenticated remote attackers to gain administrative access to the Manager's API, posing a significant risk to affected organizations.

Cisco released security updates for a critical zero-day vulnerability (CVE-2026-76504) in its Catalyst SD-WAN Manager, which attackers are actively exploiting to gain administrative privileges. This vulnerability allows unauthenticated remote access due to improper handling of URI encoding in HTTP requests, bypassing authentication rules.

WatchGuard released patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) flaw (CVE-2026-86131) that allows remote attackers to execute commands with root privileges. Additionally, fixes were issued for two critical RCE flaws in WatchGuard Access Points, which could allow unauthenticated API session acquisition and arbitrary shell command execution. These updates address significant security risks in WatchGuard's network devices.

Mandiant and GTIG reported active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 since early September, affecting government, financial, and other sectors. Attackers gained root access, deployed web shells and tunneling tools for internal network reconnaissance and credential theft, impacting dozens of organizations.

TeamViewer issued an urgent advisory for users to update their client and host software due to multiple high-severity vulnerabilities. These flaws, including a remote session access control bypass, could allow remote code execution or privilege escalation on affected systems. Updating to version 15.82 is recommended to mitigate potential exploitation.

Threat actors are exploiting a newly patched vulnerability (CVE-2026-88772) in Citrix NetScaler ADC and Gateway appliances to gain root access and deploy custom malware. The attacks, observed in North America and Europe, target government, financial, and technology sectors, enabling reconnaissance and credential theft.

OpenSSL and WolfSSL have released patches addressing multiple vulnerabilities, including high-severity flaws that could lead to data exposure, denial-of-service, or authentication bypass. These updates are critical for applications using these cryptographic libraries, such as VPNs, VoIP, IoT products, and various web servers, to maintain secure communication and prevent potential exploits.

Cybersecurity researchers have published technical details of CVE-2026-88772, a critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway that is currently being exploited. This flaw allows for remote code execution or denial-of-service due to improper handling of Datagram Transport Layer Security (DTLS) fragment sizes, enabling attackers to write past buffer limits and potentially execute shellcode with root privileges.

Attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day vulnerability to deploy web shells, gain root access, and steal credentials from organizations in North America and Europe. Citrix released security updates for CVE-2026-88771 and CVE-2026-88772, both of which were exploited in unmitigated NetScaler deployments.

Mandiant and Google Threat Intelligence Group identified active exploitation of two zero-day vulnerabilities, CVE-2026-88772 and CVE-2026-88771, in Citrix NetScaler ADC and NetScaler Gateway appliances. The exploitation allows for authentication bypass and root-level access, impacting government, financial, education, and legal sectors in North America and Europe.

Three Artifactory vulnerabilities, including one critical and two high-severity, are under active exploitation, enabling authentication bypass and persistent administrator access on self-hosted instances. Attackers can chain these flaws to gain full control, leading to credential theft, arbitrary code execution, and persistence. Users with exposed instances should assume compromise and hunt for post-exploitation artifacts.

Government cybersecurity agencies in the US, UK, and Netherlands issued urgent warnings about two actively exploited zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler application delivery controllers (ADC) and Gateway devices. These vulnerabilities, with severity scores of 9.5 out of 10, allow threat actors to exploit critical network infrastructure, prompting CISA to mandate patching for federal agencies and advise all users to review Citrix advisories.

Citrix released patches for actively exploited vulnerabilities (CVE-2026-88771, CVE-2026-88772) in NetScaler ADC and Gateway, which allow for arbitrary command execution and remote code execution. Separately, cryptocurrency exchange Bitget resumed withdrawals after a $387 million hack, attributed to suspected North Korean actors, impacting its hot wallets.

Citrix released patches for two critical NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which are being actively exploited. These vulnerabilities, with CVSS scores of 9.5, affect NetScaler ADC and Gateway, prompting CISA to add them to its Known Exploited Vulnerabilities catalog and issue an alert.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical Citrix NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771, CVE-2026-88772) to its Known Exploited Vulnerabilities catalog. Threat actors are actively exploiting these flaws globally, which could allow unauthenticated command execution or remote code execution.

CISA has ordered U.S. government agencies to patch two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) by Wednesday. These flaws allow unauthenticated remote code execution and are actively being exploited in zero-day attacks, posing a significant risk to affected systems.

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in attacks and released security updates. These zero-days affect NetScaler ADC and NetScaler Gateway appliances, posing a significant risk as these devices are often internet-facing and can provide attackers with an initial network foothold.

Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, allowing remote code execution, are being actively exploited. These flaws are distinct from a previously patched authentication bypass and affect critical network edge devices, prompting some administrators to take appliances offline.

The ShinyHunters extortion group is using a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate the Oracle PeopleSoft CVE-2026-35273 flaw. This technique allows the group to continue exploiting the vulnerability on servers that have not applied security updates, despite WAFs blocking the vulnerable endpoint.

Google has issued a warning about renewed mass exploitation of a known Oracle PeopleSoft vulnerability (CVE-2026-35273) by the ShinyHunters-linked group. The attackers are bypassing web application firewalls (WAFs) by URL-encoding a character in the request path, allowing them to deploy web shells and achieve remote code execution across various sectors globally.

The threat group UNC6240 (ShinyHunters) has renewed its mass exploitation campaign targeting Oracle PeopleSoft vulnerability CVE-2026-35273, expanding its global reach across multiple sectors. The group developed a WAF bypass technique by URL-encoding a character in the request path, allowing them to exploit systems protected by string-based WAF rules. This campaign follows an earlier zero-day exploitation and targets organizations that implemented WAF rules but did not patch the vulnerability.

A pre-authentication SQL injection vulnerability (CVE-2026-48842) in Roundcube Webmail's virtuser_query plugin is being actively exploited. This flaw allows unauthenticated attackers to inject SQL statements, potentially exposing mail account credentials and stored messages. Organizations using affected Roundcube versions should update immediately to mitigate the risk of data compromise.

Researchers detailed the full exploitation of CVE-2025-13032, a double-fetch vulnerability in Avast Antivirus's kernel driver, on Windows 11. The exploit achieved arbitrary kernel read/write and SYSTEM privilege escalation via token theft, demonstrating a method to bypass the antivirus sandbox.

A high-severity SQL injection vulnerability (CVE-2026-48842) in the open-source Roundcube webmail client is being actively exploited by threat actors. This flaw allows unauthenticated attackers to bypass security measures in the virtuser_query plugin, potentially leading to data tampering and unauthorized access to user information.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These flaws could lead to remote code execution in WSO2 products and elevated access in Adobe Commerce, posing risks to affected organizations.

A high-severity SQL injection vulnerability in Roundcube Webmail (CVE-2026-48842), patched in May, is now being actively exploited in attacks. This flaw allows unauthenticated threat actors to bypass authentication, execute malicious database commands, and steal data from Roundcube databases, impacting thousands of services using the client.

CISA has warned that ransomware gangs are now exploiting a critical authentication bypass vulnerability (CVE-2026-63077) in JetBrains TeamCity On-Premises. This flaw allows unauthenticated attackers to execute arbitrary commands, potentially compromising CI/CD pipelines and sensitive data.

SolarWinds released patches for two critical remote code execution (RCE) vulnerabilities, CVE-2026-28324 and CVE-2026-28325, in its Observability Self-Hosted product. These flaws, which could allow unauthenticated remote attackers to execute code, affect all versions up to 2026.2.2 and were addressed in version 2026.2.3.

Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in its Security Gateway VPN, and CVE-2026-93616, a pre-authentication path traversal flaw. Attackers began exploiting these vulnerabilities on September 12, prompting CISA to add them to its Known Exploited Vulnerabilities catalog and urge federal agencies to apply fixes by September 25, 2026.

A vulnerability chain, dubbed MikroTrick, allows attackers to gain full administrative control over Internet-exposed MikroTik routers without requiring a password or SSH key. This chain combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug (CVE-2026-86060) in the RouterOS login process. The exploit was observed in logs before MikroTik released patches on September 3.

A recent InfraTrust Pulse report indicates a rise in attacks targeting network management systems, with several critical vulnerabilities actively exploited. This trend allows attackers to gain full control over compromised infrastructure, highlighting a shift in high-value targets for cybercriminals.

Arista Networks released security patches for CVE-2026-93952, an actively exploited zero-day vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem deployments. The flaw allows remote attackers to access privileged internal VCO host functionality without authentication, prompting CISA to add it to its Known Exploited Vulnerabilities catalog.

Security firm DepthFirst released an exploit for a use-after-free vulnerability (CVE-2026-80521) in the Linux kernel's AF_UNIX socket subsystem that allows container escape and root access on the host. The flaw was fixed upstream in August, but Ubuntu has not yet patched its 26.04, 24.04, and 22.04 LTS releases, leaving many systems vulnerable to attack.

Arista has issued urgent patches for a critical-severity zero-day vulnerability (CVE-2026-93952) in its on-premises VeloCloud Orchestrator (VCO) deployments, which is actively being exploited. This flaw, an improper input validation issue, allows remote attackers to access privileged internal functionality, impacting the confidentiality, integrity, and availability of the orchestrator and its managed data.

F5 released hotfixes for a critical vulnerability (CVE-2026-94127) in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw affects systems where APM functions as an OAuth authorization server and has been added to CISA's Known Exploited Vulnerabilities catalog.

F5 and CISA issued warnings about a critical vulnerability (CVE-2026-94127) in BIG-IP Access Policy Manager (APM) being actively exploited as a zero-day. The flaw allows unauthenticated remote code execution when specific configurations are present, prompting CISA to add it to its Known Exploited Vulnerabilities list.

F5 released security updates for a critical zero-day vulnerability in its BIG-IP APM product, which is actively being exploited for remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities Catalog, mandating U.S. federal agencies to patch by Friday due to the significant risk posed by such vulnerabilities.

Check Point released urgent patches for CVE-2026-93616, a critical directory traversal vulnerability in its Management Server products that has been actively exploited as a zero-day. This flaw allows unauthenticated attackers to upload and execute arbitrary scripts, impacting multiple Check Point security products.

Check Point reported that a zero-day vulnerability (CVE-2026-93616) in its Security Management Server was exploited in targeted attacks on July 23. The flaw, a path traversal bug, allowed attackers to run scripts on the server without authentication, prompting Check Point to release a fix on September 22.

A critical vulnerability (CVE-2026-90898) in Bifrost, an open-source AI gateway, allows unauthenticated attackers to execute arbitrary commands on the server. This flaw affects versions before 2.1.0 when management authentication is disabled by default, potentially exposing API keys for over 20 LLM providers.

Check Point Software released emergency hotfixes for a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server, which is actively being exploited in attacks. The flaw allows unauthenticated attackers to upload and execute arbitrary scripts, impacting multiple Check Point products.

D-Link issued a warning about a critical zero-day stack-based buffer overflow vulnerability in its DIR-822A routers, which can lead to remote code execution without authentication. A public proof-of-concept exploit exists, increasing the risk of immediate exploitation.

Arista announced that a new critical vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited. This flaw, with a CVSS 3.1 score of 10.0, affects VCO deployments configured for certificate-based authentication and can lead to full compromise of the orchestrator and managed Edge devices.

A Chinese threat actor has been exploiting CVE-2026-7273, a stack-based buffer overflow vulnerability in ZyXEL GS1900 switches, to exfiltrate sensitive information from devices in 48 countries. ZyXEL released patches in June, and the US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it within three days.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Zyxel GS1900 series switch vulnerability (CVE-2026-7273) to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it by Thursday. This flaw, a stack-based buffer overflow, allows unprivileged attackers to execute OS commands and has been exploited to exfiltrate data from nearly 1,000 switches globally.

CISA added a patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog due to active exploitation. Separately, a local privilege escalation flaw in Veeam Agent for Windows (CVE-2026-32996) is also being actively exploited, allowing attackers to gain SYSTEM-level control.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the active exploitation of three Linux kernel vulnerabilities, one of which is rated critical and existed for 14 years. Federal agencies are mandated to apply security updates and mitigations by the end of today and conduct forensic triage on affected assets, as public exploits are available for two of the flaws.

Cisco issued a warning about an actively exploited maximum-severity authentication bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE). Separately, the U.S. government seized domains associated with the NightmareStresser DDoS-for-hire service, and researchers demonstrated using Anthropic's Claude Opus 5 to chain vulnerabilities for unauthorized access to OpenAI employee accounts.

The Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them immediately. These flaws, including a critical zero-length record handling issue, a race condition, and an out-of-bounds write, could lead to denial-of-service or memory corruption. The inclusion in the KEV catalog signifies active exploitation and mandates prompt remediation for government systems.

SolarWinds released security updates for Access Rights Manager (ARM) to fix a high-severity vulnerability (CVE-2026-28326) that allowed unauthenticated remote code execution due to a hard-coded key. This patch addresses a critical security risk in a widely used IT management product.

A critical unauthenticated remote code execution vulnerability, CVE-2026-58138, in Orkes Conductor versions 3.21.21 before 3.30.2 is being actively exploited in the wild. Attackers are submitting malicious JavaScript or Python expressions to the workflow API to execute arbitrary OS commands. This vulnerability allows attackers to bypass authentication and gain control over systems running affected versions of Orkes Conductor.

CISA has added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. These flaws could lead to memory disclosure, denial-of-service, or local privilege escalation, prompting Red Hat to issue high-priority advisories.

Microsoft patched a critical privilege escalation vulnerability (CVE-2026-85889) in Azure AI Foundry, which had a CVSS score of 10.0. This flaw allowed unauthorized attackers to elevate privileges over a network, but Microsoft has already mitigated the issue, requiring no customer action.

Check Point Software released security updates for a critical vulnerability, CVE-2026-91843, which allows attackers to execute code with root privileges on Security Management Server and Log Server instances. This flaw, a stack-based buffer overflow, enables unprivileged threat actors to achieve remote code execution with low complexity and no user interaction, impacting all Security Management Server deployments.

A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor is being actively exploited. The flaw allows attackers to execute arbitrary system commands by submitting malicious JavaScript or Python expressions to the workflow API endpoint, impacting organizations using vulnerable versions of the open-source framework.

Check Point, Kaspersky, and Tanium have released patches for severe vulnerabilities in their products, some of which could lead to remote code execution. These updates address critical security risks across various enterprise security solutions, requiring immediate action from affected customers to prevent potential exploitation.

Check Point has released a fix for a critical vulnerability (CVE-2026-91843) in its Security Management and Log Servers that could allow unauthenticated attackers to execute code as root. The flaw is a stack overflow in the login process, triggered by a long username, and affects multiple Check Point software versions. This vulnerability is significant because it allows remote code execution on critical security infrastructure without authentication, though there is no indication of active exploitation.

Docker has patched a critical vulnerability, CVE-2026-77179, in Docker Sandboxes for macOS that allowed malicious code within a guest VM to read and modify files outside its shared project directory on the host system. This flaw undermines the isolation provided by the sandbox, potentially leading to host compromise if an AI coding agent or other malicious code is exploited.

NLnet Labs disclosed a critical heap overflow vulnerability (CVE-2026-81642) in all Unbound DNS resolver versions before 1.26.1, which could lead to remote code execution via a malicious DNS zone. The flaw, along with eight others, including another RCE-possible bug (CVE-2026-82717), is fixed in Unbound 1.26.1, released on the same day.

Cisco released patches for numerous critical-severity vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard products. These updates address issues including remote code execution, SQL injection, and authentication bypass, some of which were publicly disclosed or actively exploited.

Cisco released security updates for a maximum-severity Identity Services Engine (ISE) vulnerability, CVE-2026-76460, which is being actively exploited. This flaw allows remote attackers to bypass authentication on ISE and ISE Passive Identity Connector (ISE-PIC) via an API weakness. Organizations must apply the updates immediately as no workarounds exist, and CISA has ordered federal agencies to patch within three days.

Cisco has issued a warning about a critical zero-day vulnerability (CVE-2026-76460, CVSS 10.0) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that is currently under active exploitation. This flaw allows unauthenticated remote attackers to bypass authentication and gain unauthorized access, potentially leading to root-level command execution.

A critical vulnerability, CVE-2026-89026, in the Issabel Framework is being actively exploited, allowing unauthenticated attackers to execute arbitrary OS commands. The flaw stems from a hard-coded JSON Web Token (JWT) signing key, which enables attackers to forge valid bearer tokens and control the system. Users are advised to apply the patch released on August 1, 2026, to secure their installations.

Google released security updates for Pixel devices, addressing a high-severity privilege escalation flaw (CVE-2026-58704) in its cellular modem that has seen limited, targeted exploitation. This vulnerability allows remote privilege escalation without user interaction and has been added to CISA's Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes.

Acronis has reported that a high-severity local privilege escalation vulnerability (CVE-2026-87886) in its Backup plugin for cPanel and Web Host Manager (WHM) has been actively exploited in limited, targeted attacks. This flaw allows low-privileged attackers to escalate permissions on Linux systems, potentially leading to unauthorized actions or arbitrary code execution, and requires immediate patching by affected users.

A critical security flaw (CVE-2026-5430) in WSO2 API Manager and related products is under active exploitation, allowing unauthorized access and potential account takeover. The vulnerability stems from improper cryptographic signature verification in JWT authentication, enabling attackers to bypass security with forged tokens. This flaw impacts multiple versions of WSO2 products and could lead to compromise of administrative accounts and API backend endpoints.

Threat actors are exploiting three high-severity vulnerabilities (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329) in JFrog Artifactory to bypass authentication, gain administrative privileges, and install backdoors. These flaws allow attackers to deploy persistent admin accounts, execute arbitrary code, and exfiltrate sensitive data from compromised Artifactory instances. Organizations using self-managed Artifactory deployments are advised to update to patched versions immediately.

CISA has added five security flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These vulnerabilities include issues leading to privilege escalation, unauthorized access, and denial-of-service, posing risks to organizations using these products.

The Dutch National Cyber Security Centrum (NCSC) has issued a warning about the imminent exploitation of two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in Check Point VPN products. These flaws could allow remote code execution, enabling attackers to gain full system control, access sensitive data, or disrupt operations, necessitating immediate patching.

Threat actors are exploiting critical vulnerabilities in JFrog Artifactory, including CVE-2026-42018 and CVE-2026-42016, to bypass authentication, gain administrative privileges, and deploy a Rust-based backdoor on self-hosted servers. This allows attackers to execute arbitrary commands, steal configuration data, and establish persistence, affecting a significant percentage of internet-exposed Artifactory instances.

Check Point released patches for two critical-severity vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its gateway and firewall products. These flaws, with a CVSS score of 9.8, could allow unauthenticated remote code execution via VPN functionality, impacting Security Gateway, Spark Firewall, and Security Management Server.

Attackers exploited two patched JFrog Artifactory vulnerabilities (CVE-2026-42018 and CVE-2026-42016) between August 15 and September 8 to gain administrator control and install backdoors on self-hosted servers. The attack chain allowed unauthenticated users to obtain administrator tokens, leading to the creation of new admin accounts and deployment of malicious plugins or Rust backdoors.

Cisco reported that two recently patched Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been actively exploited by three distinct threat clusters. These exploits led to credential theft, deployment of web shells, and Qilin ransomware attacks, prompting CISA to add one vulnerability to its Known Exploited Vulnerabilities catalog.

Cisco Talos reported that two recently patched Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been actively exploited by three threat clusters, including ransomware affiliates and state-sponsored actors. Attackers used these flaws to deploy web shells, steal credentials, and deploy malware like Qilin ransomware and Cyclops Blink, underscoring the critical need for immediate patching of network security infrastructure.

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that a critical NetScaler vulnerability, CVE-2026-19490, is being actively exploited in attacks. This flaw affects NetScaler ADC and Gateway appliances and was patched by Citrix on August 19, with exploitation observed since at least September 3.

Check Point has released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products related to VPN certificate handling. These flaws, rated 9.8 CVSS, could allow unauthenticated remote code execution under specific conditions, affecting Security Gateways and Security Management Servers. The patches are important for organizations using Check Point products to prevent potential remote code execution by attackers.

CISA has added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by September 12, 2026. These flaws include authentication bypasses and a heap-based buffer overflow, which have been observed in active attacks, including espionage and malware delivery.

Cisco and CISA issued warnings about active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC). Attackers can gain root access to affected devices, with state-sponsored and financially motivated groups already utilizing the flaw to deploy malware and steal credentials.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a critical remote code execution vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls. This flaw allows unauthenticated attackers to execute malicious code and affects Fireware OS versions 11.x, 12.x, and 2025.1 through 2025.1.3, posing a risk to organizations using unpatched devices.

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2025-25249) in Fortinet products to deploy the PivotC2 RAT. This flaw, patched in January, has led to the infection of 178 devices, primarily targeting US entities and resulting in data exfiltration.

Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software, is being actively exploited. This flaw allows unauthenticated, remote attackers to execute commands as root, posing a significant risk to affected organizations.

Fortinet released patches for 10 vulnerabilities, including two critical flaws in FortiMonitorOnSight and its Privileged Access Agent Chrome extension. These vulnerabilities could allow remote, unauthenticated attackers to bypass authentication or proxy user traffic. The patches address significant security risks across multiple Fortinet products.

Ivanti released security updates for its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products, addressing multiple critical and high-severity vulnerabilities. These patches fix issues including remote code execution and authentication bypass flaws, which could allow unauthorized access or control over affected systems.

cPanel has patched a vulnerability, CVE-2026-67401, in its web hosting control panel software that allowed an authenticated hosting account with mail-related privileges to execute code as the root user on the server. This flaw affects all supported versions of cPanel and WHM, enabling an attacker to gain full administrative access to the server and compromise all hosted accounts.

SAP released security updates addressing a critical vulnerability, CVE-2026-44756, in its Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw allows unauthenticated remote code execution on SAP hosts, potentially leading to a total compromise of business data and processes. The patch is crucial for preventing unauthorized access and data breaches across various SAP components.

CISA added a critical N-able N-central pre-authentication remote code execution vulnerability (CVE-2026-86218) to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 11, 2026. This flaw, patched in N-central 2026.3 Hotfix 4, has been observed under active exploitation, posing a significant risk to affected organizations.

SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw (CVE-2026-44756, "OVERPASS") in the SAP Kernel and a missing authentication vulnerability (CVE-2026-58240, "S4GET") in NetWeaver Message Server. The OVERPASS flaw allows unprivileged attackers to execute arbitrary commands with administrative privileges, potentially compromising over 10,000 internet-facing SAP systems, while S4GET enables unauthenticated remote code execution across SAP clusters.

SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw (CVE-2026-44756) in its Extended Passport Processing (EPP) with a CVSS score of 10/10. This vulnerability, dubbed OVERPASS, could allow unauthenticated attackers to execute arbitrary system commands and access sensitive data, impacting various SAP products.

N-able has issued an urgent hotfix for a critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-86218, in its N-central endpoint management platform, which has been actively exploited as a zero-day. This vulnerability allows pre-authenticated access to the N-central server and requires on-premises users to apply the 2026.3 HF4 hotfix immediately to mitigate risk.

N-able released hotfixes for critical N-central vulnerabilities, including a maximum-severity flaw allowing remote code execution, while Google patched a Chrome 0-day vulnerability actively exploited in the wild. These updates address significant security risks in widely used software and platforms. Organizations using N-central and Chrome should apply these patches immediately to prevent potential exploitation.

Security firm TantoSec released a public exploit for a patched vulnerability chain in Telerik UI for ASP.NET AJAX, enabling unauthenticated remote code execution. The exploit targets a specific non-default configuration, and Progress Software issued a fix in July.

N-able issued its fourth hotfix in five weeks for its N-central RMM platform, addressing a critical unauthenticated remote code execution vulnerability (CVE-2026-86218) with a CVSS score of 10.0. This flaw affects all on-premises N-central builds prior to 2026.3.1.14, requiring immediate upgrades for affected customers.

N-able issued an emergency hotfix for a critical remote code execution (RCE) vulnerability, CVE-2026-86218, affecting its N-central remote monitoring and management (RMM) platform. This flaw allows unprivileged attackers to execute malicious code on unpatched systems, and while N-able has not confirmed active exploitation, cybersecurity firm Huntress flagged it as a potential zero-day, urging immediate patching for the nearly 1,500 N-central servers exposed online.

JetBrains' Cadence cloud service was breached last month due to the exploitation of a critical vulnerability (CVE-2026-63077) in TeamCity, leading to the compromise of AWS credentials and user data. Cadence users are advised to revoke and rotate all credentials and treat project data as potentially untrusted. This incident highlights the risks associated with unpatched software in critical infrastructure.

Broadcom released security updates for VMware Workstation and Fusion, addressing two vulnerabilities, including a critical integer-overflow flaw (CVE-2026-59346) that allows local administrative users on a VM to execute code on the host. These patches are important as VMware products are frequently targeted, and similar flaws have seen active exploitation recently.

Threat actors are exploiting newly disclosed PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to steal credentials from K-12 schools and universities in the U.S. and Europe. The attacks involve authentication bypass and remote code execution, leading to reconnaissance, privileged account creation, and deployment of credential-harvesting tools.

A critical remote code execution vulnerability (CVE-2026-66066) in Ruby on Rails ActiveStorage, dubbed KindaRails2Shell, received an emergency patch. The vulnerability, rated 9.5/10 CVSS, was exploited shortly after its disclosure, prompting rapid deployment of hotfixes across client systems, including government agencies.

HPE has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical remote code execution (RCE) flaws. These updates address vulnerabilities that could allow unauthenticated attackers to achieve RCE with elevated privileges, impacting enterprise network security.

A critical authentication bypass vulnerability in Citrix NetScaler (CVE-2026-19490) is now being actively exploited in the wild, according to vulnerability intelligence company Previdian. This flaw allows unprivileged attackers to bypass authentication remotely when NetScaler is configured as an AAA virtual server or Gateway, posing a significant risk to organizations using affected appliances.

A critical-severity SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox, an enterprise VoIP solution, is being actively exploited by threat actors. CISA has added this flaw, along with several others, to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply patches promptly.

Broadcom released patches for two critical vulnerabilities, CVE-2026-59346 and CVE-2026-59347, affecting VMware Workstation and Fusion. These flaws could allow a malicious actor with local administrative privileges on a virtual machine to execute code on the host system. The patches are important because VMware products are frequently targeted by threat actors, and these vulnerabilities have no workarounds.

HPE has released patches for a critical remote code execution vulnerability (CVE-2026-73749) in its ArubaOS-CX network operating system, which could allow unauthenticated attackers to execute code with elevated privileges. This update addresses a buffer overflow issue and 23 other security flaws affecting enterprise-grade network switches.

Cisco has released patches for a critical vulnerability (CVE-2026-20212) in 10 Silicon One-based Nexus 9000 switches that could allow unauthenticated remote attackers to execute code with root privileges. This flaw matters because it affects network infrastructure, potentially leading to full device compromise and disruption if exploited, though Cisco is not aware of active exploitation.

Cisco has issued a warning about two publicly disclosed, unpatched medium-severity vulnerabilities in its Secure Email product and released patches for multiple critical-severity flaws in IOS XR and Nexus 9000 series switches. The Secure Email flaws could allow attackers to intercept and modify encrypted email traffic, while the switch vulnerabilities could lead to remote code execution and other attacks.

CISA has added seven security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation by attackers. These flaws affect products from SonicWall, Sangoma, JFrog, Kludex, Kestra, and Berri LiteLLM, with some being used to deploy reverse shells and crypto miners.

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP platforms, to deploy reverse shells and execute remote code. This flaw allows attackers to gain control over business phone systems, impacting approximately 4,000 internet-exposed devices, primarily in the United States.

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to create administrative access tokens. This flaw allows unauthenticated attackers to gain full control over Artifactory instances, potentially compromising software supply chains by replacing trusted artifacts with malicious code.

Rockwell Automation released patches and workarounds for more than a dozen vulnerabilities across its industrial automation products. These include critical and high-severity denial-of-service issues in RSLinx Classic, remote code execution in FactoryTalk Historian, and privilege escalation flaws, impacting operational technology security.

A new authentication bypass vulnerability, CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application, with an exploit now publicly available. This flaw allows remote attackers to elevate privileges by manipulating JWT refresh token logic, posing a significant risk to organizations using the software.

SonicWall has released security updates for two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting its Secure Mobile Access (SMA) 1000 series VPN appliances that are being actively exploited. These flaws, if chained together, could allow remote attackers to execute arbitrary code on affected devices.

GeoNetwork, an open-source geospatial metadata catalog used by government geoportals, patched two vulnerabilities (CVE-2026-63219 and CVE-2026-58400) that could be chained for unauthenticated remote code execution. The fix was released on July 8, 2026, addressing a critical security flaw affecting numerous internet-exposed deployments, many of which are government-related.

Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3, to achieve remote code execution. This flaw allows attackers to deploy reverse shells and execute arbitrary commands, impacting approximately 4,000 internet-exposed instances, primarily in the U.S.

SonicWall issued a warning about two new zero-day vulnerabilities in its SMA1000 appliances that are being actively exploited in remote code execution attacks. These flaws, a maximum-severity command injection (CVE-2026-83548) and another command injection (CVE-2026-83549), allow attackers to execute arbitrary OS commands on vulnerable devices. The exploitation of these vulnerabilities poses a significant risk to large enterprises, government, and critical infrastructure organizations that use SMA1000 for secure remote access.

SonicWall has issued an urgent advisory for customers using its SMA1000 series secure remote access gateways to patch two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which are actively being exploited. These flaws could allow remote attackers to access sensitive functionality or execute arbitrary OS commands, posing a significant risk to affected organizations.

Threat actors are exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow versions 1.4.2 and earlier, to steal OpenAI API keys and AWS credentials. This critical flaw allows attackers to execute arbitrary code with root privileges by manipulating the code validator in Langflow's custom component editor, impacting users of the open-source AI application framework.

Threat actors are actively exploiting CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, to gain administrative privileges. This flaw allows unauthenticated attackers to mint admin tokens and could lead to software supply chain compromise, affecting organizations using self-managed Artifactory instances.

Threat actors are actively exploiting CVE-2026-0768, a critical remote code execution vulnerability in the AI low-code platform Langflow, affecting all versions up to 1.4.2. This exploitation allows attackers to execute arbitrary code as root without authentication, posing a significant risk to users of the platform.

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is reportedly being exploited in the wild, allowing unauthenticated attackers to gain administrative privileges. JFrog released patches on August 28, and self-hosted users are advised to update immediately to prevent potential compromise of their software artifact management systems.

The Linux kernel is nearing 2,000 CVEs per release, a significant increase from 500, primarily because AI and large language models are extensively scanning its 40 million lines of code for vulnerabilities. This surge in findings, many of which are low-priority or questionable, is overwhelming human maintainers and leading to the removal of old, rarely used driver code.

WatchGuard released patches for over two dozen vulnerabilities, including five critical flaws that could lead to remote code execution (RCE) and account takeover in its Fireware OS and Dimension products. These updates address significant security risks for users of WatchGuard network security devices and management software.

Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails, for credential harvesting and remote code execution. VulnCheck observed over 360 exploitation attempts since August 30, 2026, with traffic primarily from Russia targeting systems in the U.K.

ServiceNow has released patches for four vulnerabilities, including three critical code injection flaws (CVSS 10/10) in its AI platform and one high-severity sandbox escape vulnerability. These flaws could allow unauthenticated attackers to execute arbitrary code, modify data, elevate privileges, or execute SQL statements, impacting both hosted and self-hosted instances of the platform.

JetBrains' Cadence cloud development service was compromised after attackers exploited a critical TeamCity vulnerability (CVE-2026-63077) on an unpatched server belonging to JetBrains itself. This incident led to the potential exposure of credentials, configuration files, and source code, impacting users of the Cadence service and JetBrains employees.

A critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. Cosmos Labs was aware of the vulnerability since April 25 and had confirmed its impact on all Cosmos EVM chains by August 13, but did not follow its own emergency disclosure policy.

CISA added a critical ownCloud vulnerability (CVE-2023-49105) to its Known Exploited Vulnerabilities catalog after reports of a Chinese-speaking threat actor using it to target a Philippine nuclear research body. This flaw allows unauthenticated file access via WebDAV API if a username is known and the default configuration (no signing-key) is used, enabling data theft from affected ownCloud instances.

ServiceNow has released patches for four security vulnerabilities in its AI Platform, including three with a CVSS score of 10.0 that could allow unauthenticated attackers to execute arbitrary code or SQL. These critical flaws affect hosted and self-hosted instances, requiring immediate action for organizations managing their own deployments. The patches address severe risks of data access, modification, and privilege escalation.

VulnCheck discovered two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These implants allow unauthenticated remote attackers to execute commands as root on affected devices, posing a significant security risk due to their ability to bypass network defenses and exfiltrate sensitive data.

ServiceNow has released security patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. These flaws could be exploited by unauthenticated attackers with low complexity, impacting the platform used by many Fortune 500 companies.

cPanel released patches for a critical security flaw, CVE-2026-65643, in cPanel and WebHost Manager (WHM) that could allow an authenticated user to achieve root code execution. This vulnerability impacts all supported versions and could give an attacker full control of a server.

Vercel released security patches for two critical remote code execution (RCE) vulnerabilities in the Next.js web framework. These flaws, one involving AVIF image processing and another a Windows path traversal, could allow unauthenticated attackers to execute code remotely, necessitating immediate upgrades for affected deployments.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical remote code execution (RCE) vulnerability (CVE-2026-8452) in Citrix NetScaler appliances by Saturday. This directive follows reports of active exploitation of the flaw, which was initially downplayed by Citrix as a denial-of-service vulnerability but later shown to allow RCE.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway. This addition signifies that these vulnerabilities are actively being exploited in the wild, requiring immediate attention from organizations to mitigate potential risks.

CISA has issued an urgent directive for government organizations to patch a Citrix NetScaler vulnerability (CVE-2026-8452) that is actively being exploited. This vulnerability, initially described as a high-severity memory overflow, has been demonstrated to allow unauthenticated remote code execution, posing a significant risk to affected systems.

A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme and Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code. The flaw, rated 9.8 critical, affects versions up to Avada 7.16 and Fusion Builder 3.16, enabling full website compromise. ThemeFusion has released fixes in Avada 7.16.1 and Fusion Builder 3.16.1.

Ubiquiti released security patches for three maximum-severity vulnerabilities that could allow unauthenticated remote exploitation in UniFi Protect, UniFi Talk, and UniFi OS. These flaws include an authentication bypass and command injection, posing a risk to devices exposed online, which have historically been targeted by threat actors.

CERT/CC disclosed two unpatched vulnerabilities, CVE-2026-19913 and CVE-2026-19912, in Kaltura's HTML5 video player library (mwEmbed/html5lib). These flaws allow unauthenticated remote attackers to read arbitrary files and execute code on affected servers due to unsafe deserialization in the mwEmbedLoader.php endpoint. The vulnerabilities affect both individual customer installations and Kaltura's shared CDN infrastructure, posing a risk to multiple tenants.

Marimo has patched a high-severity security vulnerability (CVE-2026-75149) in its notebook software that permitted arbitrary Model Context Protocol (MCP) commands to execute as a local subprocess when a specially crafted notebook was opened in edit mode. This flaw allowed code injection before any notebook cells ran, affecting versions prior to 0.23.15, and required no attacker authentication.

Threat actors have compromised over 270 Zimbra Collaboration Suite (ZCS) instances by exploiting a high-severity remote code execution vulnerability, CVE-2026-73570. This ongoing exploitation impacts organizations globally, including businesses and government agencies that rely on Zimbra for email and collaboration.

CISA has instructed government organizations to immediately patch a critical remote code execution vulnerability (CVE-2026-21962) in Oracle WebLogic servers, which has been actively exploited since January 2026. This flaw, affecting Oracle HTTP Server and the WebLogic Server Proxy plugin, allows unauthenticated exploitation and requires urgent attention to prevent server compromise.

CISA has added a critical Oracle HTTP Server and Oracle WebLogic Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows unauthenticated attackers to gain unauthorized access or modify critical data, posing a significant risk to affected systems.

A vulnerability (CVE-2026-75501) in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create port-forwarding rules, bypassing NAT and exposing local network devices. This flaw affects devices running EXOS/6.6.47 firmware and impacts users of multiple U.S. broadband providers that deploy these routers.

Broadcom's Spring application development framework released updates patching 91 vulnerabilities, including one critical and over a dozen high-severity issues. These patches are significant for developers using Spring, as the vulnerabilities affect various projects and could lead to exploits like remote code execution and information disclosure.

Red Hat and the Keycloak project released patches for a critical security flaw (CVE-2026-18963) in the Keycloak identity and access management server. This vulnerability allows an unauthenticated remote attacker to reset any user's password and take over their account, including administrative accounts, due to improper state validation in the password recovery mechanism.

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. This flaw allows unauthenticated attackers to achieve remote code execution, posing a significant risk to organizations using the popular email and collaboration platform.

Cisco released security updates for its Crosswork and Secure Workload platforms, addressing nine vulnerabilities, five of which have a CVSS score of 10.0. These patches resolve issues including SQL injection, missing authentication, and improper access control, found during an internal security review. The updates are important for users to apply to prevent potential exploitation of these critical flaws.

A recently patched high-severity vulnerability in Zimbra Collaboration, tracked as CVE-2026-73570, is being actively exploited in the wild, according to CERT Polska. This flaw allows unauthenticated attackers to execute arbitrary OS commands on affected servers, potentially leading to full system control and data theft.

A critical security flaw (GHSA-864f-rcv7-6rh4) has been discovered in isolated-vm, a popular Node.js sandbox library, allowing untrusted JavaScript to escape its sandboxed environment and potentially corrupt host memory or achieve remote code execution. This vulnerability undermines the core security purpose of isolated-vm, which is used to run untrusted JavaScript code safely.

Citrix released updates for NetScaler ADC and NetScaler Gateway to fix two security flaws, including a critical authentication bypass vulnerability (CVE-2026-19490) with a CVSS score of 9.3. This bypass affects appliances configured as a Gateway or an AAA virtual server, potentially allowing unauthorized access. Organizations using affected customer-managed NetScaler deployments need to apply these updates to prevent potential security breaches.

A security vulnerability in Zimbra Collaboration (ZCS) affecting the optional zimbra-snmp package, CVE-2026-73570, is now being actively exploited. This flaw allows unauthenticated remote code execution due to improper input sanitization during SNMP notification processing, impacting organizations using affected Zimbra versions.

Atlassian and Splunk released patches for over 250 vulnerabilities across their products, including numerous critical and high-severity flaws. These updates address potential remote code execution, denial-of-service, and information theft risks, impacting a wide range of their enterprise software.

Citrix has issued an urgent warning for administrators to patch two new vulnerabilities in NetScaler Gateway and NetScaler ADC products. These flaws, including an authentication bypass (CVE-2026-19490) and a denial-of-service vulnerability (CVE-2026-19489), could allow remote attackers to compromise systems, making immediate updates critical for affected organizations.

A critical unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-64849, in the MLflow AI engineering platform is being actively exploited to steal cloud credentials and secrets. The US cybersecurity agency CISA has added this flaw to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch affected systems within two weeks.

Cisco released patches for 15 vulnerabilities across its products, addressing critical-severity flaws in Crosswork and Secure Workload, and a high-severity defect in BroadWorks. These updates prevent potential remote code execution, authentication bypass, and sensitive information disclosure, which is important for organizations using these Cisco products to maintain security.

CISA has added a critical MLflow vulnerability, CVE-2026-64849, to its catalog of actively exploited flaws, mandating U.S. federal agencies to patch affected systems within two weeks. This DNS-rebinding server-side request forgery (SSRF) bypass allows unauthenticated attackers to remotely access internal services or cloud metadata configurations, potentially leading to the theft of cloud credentials.

A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) is now being actively exploited by attackers. This flaw allows unauthenticated attackers to execute arbitrary operating system commands, posing a significant risk to organizations using ZCS.

Citrix released patches for a critical authentication bypass vulnerability (CVE-2026-19490) in NetScaler ADC and NetScaler Gateway, which allows remote, unauthenticated attackers to bypass authentication. This vulnerability is expected to be exploited soon due to the widespread deployment of NetScaler products in enterprise networks, making immediate patching crucial for affected organizations.

Attackers are actively exploiting a critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-64849) in MLflow, an open-source AI platform, to steal cloud credentials and secrets. Malicious scanning and exploitation efforts are also targeting a separate vulnerability (CVE-2026-25895) in FUXA, an open-source SCADA/HMI software. This activity highlights the immediate risk to organizations using these platforms, particularly those with exposed instances.

CISA has added a critical remote code execution (RCE) vulnerability in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The flaw, CVE-2025-62593, allows RCE via browser-based DNS rebinding attacks, primarily affecting developers in testing environments.

A newly patched VMware vCenter vulnerability (CVE-2026-59310) is being actively exploited by a suspected China-nexus APT group, leading to backdoor deployment and Babuk-derived ransomware. Additionally, a critical macOS Screen Sharing flaw (CVE-2026-65400) has been exploited in the wild to install a cryptocurrency miner. These incidents highlight the ongoing exploitation of recently disclosed vulnerabilities for various malicious purposes.

Threat actors are exploiting a recently patched macOS Screen Sharing vulnerability, CVE-2026-65400, to gain root access and deploy Monero cryptominers on vulnerable systems. This high-severity authentication bypass allows remote attackers to log in without valid credentials, impacting macOS systems with Screen Sharing enabled and accessible from the internet.

A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, was exploited by attackers just three days after its public disclosure. This vulnerability, with a CVSS score of 10, allows for arbitrary code execution and compromise of internal components, posing a significant risk to affected organizations.

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310, a severe directory-traversal vulnerability, and have compromised 361 unique victim IP addresses across 47 countries.

Attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to gain root access and install Monero cryptocurrency miners on compromised Macs with port 5900 exposed. CISA has increased the vulnerability's CVSS score from 7.1 to 9.8, classifying it as critical and automatable, following reports of active exploitation and the availability of public proof-of-concept code. This flaw allows attackers to authenticate without valid credentials, posing a significant risk to unpatched macOS systems.

A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is being actively exploited just three days after a patch was released. This flaw allows unauthenticated attackers to achieve arbitrary code execution and compromise internal components, posing a high risk to confidentiality, integrity, and availability.

A critical authentication vulnerability (CVE-2026-65400) in Apple macOS Screen Sharing is being actively exploited to install Monero cryptocurrency miners on systems with port 5900 exposed to the internet. This flaw allows unauthorized network attackers to bypass credential validation and gain root access, highlighting the importance of applying recent macOS security updates.

Dutch officials have warned that a high-severity macOS vulnerability, CVE-2026-65400, is being actively exploited to gain root access and install crypto miners on affected systems. The flaw, residing in the macOS screen sharing capability, allows attackers to execute malicious code without credentials. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.

The Netherlands' National Cyber Security Centre (NCSC) reports that a macOS Screen Sharing authentication bypass vulnerability (CVE-2026-65400) is being actively exploited to install Monero cryptocurrency miners. The flaw allows attackers to gain root access without valid credentials when port 5900 is exposed to the internet. This exploitation highlights the importance of applying security updates and disabling unneeded remote access features.

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, is actively being exploited in attacks just three days after a patch was released. This flaw allows unauthenticated attackers to execute arbitrary code, posing a significant risk to confidentiality, integrity, and availability for organizations using the e-commerce platform.

Threat actors are exploiting an unpatched zero-day SQL injection vulnerability in GeoServer, an open-source geospatial data platform, shortly after its public disclosure. This vulnerability, which can lead to remote code execution under certain configurations, affects GeoServer's jsonArrayContains function and impacts organizations using GeoServer across various industries.

A zero-day SQL injection vulnerability in GeoServer, disclosed on August 12, 2026, was actively exploited, leading to potential remote code execution. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to address this critical flaw, assigned GHSA-mqjf-5f49-2fjh with a CVSS score of 9.8.

A critical remote code execution vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited to install a reverse SSH tool for persistent remote access. This flaw allows unauthenticated attackers to execute arbitrary code, affecting 361 IP addresses across 47 countries within days of the patch release, posing a significant risk to organizations using vulnerable vCenter versions.

A critical-severity vulnerability in Adobe Commerce (CVE-2026-71362) was targeted by attackers immediately after its public disclosure, despite Adobe stating no evidence of in-the-wild exploitation. The flaw allows unauthenticated attackers to elevate privileges and access customer accounts, prompting Adobe to release an isolated patch for affected versions.

WordPress released version 7.0.4 to patch a high-severity remote code execution vulnerability (CVE-2026-65640) affecting installations using Imagick and Ghostscript. The flaw allowed authenticated attackers with Author-level permissions or higher to execute arbitrary code by uploading malicious Postscript files disguised as images. This update is important for WordPress users, especially those with multi-author sites, as it prevents a realistic threat of code execution through file uploads.

Threat actors are actively exploiting a critical-severity directory traversal vulnerability (CVE-2026-59310) in VMware vCenter's Syslog server, leading to remote code execution. This exploitation, identified by Quirso, began shortly after the vulnerability was disclosed and patched by Broadcom, affecting over 360 IP addresses across 47 countries.

A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms is being actively exploited to hijack customer accounts. This flaw allows attackers to gain elevated access without authentication, enabling them to access victim accounts and private customer data.

North Korean hackers, identified as the Lazarus Group, exploited a Windows zero-day vulnerability (CVE-2026-68820) in their "Operation Dream Job" campaign to target defense-sector companies. Microsoft patched the flaw in its latest Patch Tuesday updates, confirming active exploitation since early July, allowing attackers to gain SYSTEM privileges.

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a Microsoft Windows vulnerability (CVE-2026-68820) by August 25, as it is actively being exploited by North Korean hackers in the "Operation Dream Job" campaign. This vulnerability allows attackers to gain remote access after an initial phishing compromise, impacting Winsock, a critical component for internet connectivity.

Adobe has issued updates to address multiple critical security flaws in ColdFusion, Commerce, and Campaign Classic, including several with CVSS scores of 10.0. These vulnerabilities could lead to arbitrary code execution or privilege escalation, and administrators are advised to apply the patches promptly.

Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, to gain persistent remote access. This exploitation, observed shortly after public disclosure, affects hundreds of IP addresses across multiple countries and allows for arbitrary code execution and the establishment of reverse SSH connections.

Ivanti released patches for four vulnerabilities across its Endpoint Manager (EPM) and Neurons for MDM products. These updates address high-severity flaws in EPM, including two that remote, unauthenticated attackers could exploit, and a medium-severity command injection vulnerability in Neurons for MDM.

SAP has released patches for a maximum-severity security flaw in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability, along with three other critical flaws in Manufacturing Integration and Intelligence and Application Server ABAP, requires immediate patching to prevent potential system compromise and data loss.

SonicWall released patches for eight vulnerabilities across its Global Management System (GMS) and Email Security products, including critical remote code execution (RCE) flaws. These updates are important for users to apply to prevent potential exploitation, despite GMS being a discontinued product.

A security researcher released a proof-of-concept (PoC) for "ShieldBreak," a new zero-day vulnerability in Microsoft Defender for Windows. This PoC claims to bypass the patch for CVE-2026-50656 (RoguePlanet), which could allow SYSTEM-level privilege escalation. The vulnerability affects Windows 11 25H2, Windows Server 2025, and Windows 10, indicating that Microsoft's previous fix for RoguePlanet was incomplete.

Cisco has issued a warning about a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software that is being actively exploited in the wild. This flaw allows an unauthenticated, remote attacker to trigger a denial-of-service condition by sending a crafted HTTP request to the Remote Access SSL VPN service.

Cisco released patches for a zero-day vulnerability (CVE-2026-20349) affecting Secure Firewall ASA and FTD software, which was actively exploited to cause denial-of-service conditions. The vulnerability allows unauthenticated attackers to reload appliances by sending crafted HTTP requests to the Remote Access SSL VPN service. This matters because exploited security appliance flaws can disrupt network defenses and are being tracked by CISA.

Cisco issued a warning about a high-severity denial-of-service vulnerability, CVE-2026-20349, in its Secure Firewall ASA and Threat Defense (FTD) software that is being actively exploited to remotely crash devices. This flaw, caused by insufficient error checking in HTTP request processing, impacts devices with certain remote access services enabled and requires immediate patching to prevent service disruption.

Adobe released patches for over 50 vulnerabilities across its products, including critical flaws in ColdFusion, Campaign Classic, and Commerce that could lead to arbitrary code execution. These updates are rated with high priority due to the severity of the vulnerabilities, urging immediate application to prevent potential exploitation.

Zoom has released patches for four vulnerabilities, including a severe zero-click remote code execution (RCE) flaw (CVE-2026-53413) affecting its clients on all supported platforms. This RCE vulnerability allowed an attacker to execute code on a meeting participant's machine without interaction, posing a significant security risk to users.

SAP released 28 new security notes and two updates in its August 2026 Security Patch Day, including four critical vulnerabilities. These patches address issues like improper authorization, code injection, and memory corruption in various SAP products, which could lead to unauthorized access, system compromise, or data disclosure.

Cisco has issued a warning regarding two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser, which could lead to denial-of-service attacks. These flaws affect ClamAV versions 1.5.0 through 1.5.3 and have publicly available proof-of-concept exploit code, making immediate patching crucial for affected systems, especially Windows platforms.

CISA has confirmed that ransomware gangs are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a critical server-side request forgery (SSRF) flaw. These vulnerabilities affect secure remote access gateways used by large organizations, increasing the risk of network compromise for affected entities.

Cisco issued a warning regarding seven ClamAV vulnerabilities affecting its Secure Endpoint Connector products, with two having publicly available proof-of-concept (PoC) code. These flaws could lead to denial-of-service conditions, posing a high risk to Windows users due to privileged scanning processes.

Metabase released urgent patches for a critical SQL injection vulnerability actively exploited as a zero-day, allowing remote, unauthenticated attackers to gain administrative access and steal data. This vulnerability impacts self-hosted Metabase users who need to apply updates immediately to prevent potential compromise.

CISA has directed federal agencies to immediately patch a critical OS command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster, which is actively being exploited. This flaw allows unauthenticated remote code execution and could provide initial access to critical internal services if exploited.

Metabase reported that a maximum-severity zero-day vulnerability in its business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access. The flaw, with a CVSS score of 10.0, enables SQL injection to compromise Metabase instances. This impacts users running self-hosted versions, who must apply security patches immediately to prevent unauthorized access and data theft.

N-able issued Hotfix 2 for its N-central RMM product to counter ongoing exploitation of CVE-2026-18577, a vulnerability allowing authentication bypass and account takeover. Threat actors are using this flaw to gain administrative access, leverage the Take Control feature, and establish persistence on managed systems. This hotfix is critical for customers as it includes additional hardening measures beyond the initial fix and addresses active attacks.

CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows unauthenticated attackers to execute arbitrary code on affected devices, prompting a directive for federal agencies to patch by August 10, 2026.

A critical SQL injection zero-day vulnerability in Metabase, affecting versions 1.58 and above, was actively exploited to breach customer instances and steal data. Metabase has released patches for both its Cloud SaaS platform and self-hosted installations, urging users to update immediately to prevent unauthorized administrator access and data exfiltration.

WordPress has released a patch for a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen, tracked as CVE-2026-64638, which affects all versions of the content management system. This high-severity vulnerability can be chained into PHP code execution on the server if a logged-in administrator interacts with an attacker-controlled page, making immediate updates critical for site security.

Novee Security discovered and presented vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged GitHub users to execute code on CI runners or exfiltrate API keys. Two CVEs were issued and subsequently patched, highlighting a recurring security failure in the code that orchestrates AI model interactions.

Cisco released updates addressing 12 security vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three with CVSS scores of 9.9 and one with 9.8. These patches resolve issues like improper input validation, access control, and command injection, which could allow attackers to compromise affected systems.

A new KVM escape vulnerability, dubbed Zapscape (CVE-2026-64561), has been disclosed, allowing a guest virtual machine to escape to the host and execute commands with root privileges in KVM/x86 environments. This use-after-free flaw in the shadow MMU emulation poses a significant threat to guest-host isolation, particularly for multi-tenant public clouds that expose nested virtualization.

Cisco released patches for two dozen vulnerabilities across its product line, including critical flaws in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability is an authentication bypass in FMC (CVE-2026-20079) with a CVSS score of 10, allowing remote attackers to gain root privileges. These patches are important for maintaining the security and integrity of network infrastructure for organizations using Cisco products.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical remote code execution vulnerability (CVE-2026-63077) in on-premise versions of JetBrains TeamCity as actively exploited in the wild. This deserialization flaw allows unauthenticated attackers to bypass authentication and execute arbitrary commands, posing a significant risk to CI/CD pipelines and sensitive data.

The US cybersecurity agency CISA has issued a warning that threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, a continuous integration/continuous delivery (CI/CD) platform. This deserialization flaw allows unauthenticated attackers to achieve remote code execution, bypassing authentication checks and executing arbitrary operating system commands on affected TeamCity On-Premises versions. The active exploitation means organizations using TeamCity On-Premises need to apply patches immediately to prevent potential compromise of their software development and deployment infrastructure.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. These flaws allow for remote code execution and administrative account hijacking, posing significant risks to affected systems.

CISA has issued a warning about three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat that are actively being exploited by threat actors. These vulnerabilities include remote code execution, authentication bypass, and an EncryptInterceptor bypass, posing risks to affected systems.

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These include a code injection flaw in Langflow, a data encryption bypass in Apache Tomcat, and an authentication bypass in N-able N-central, with one Tomcat exploit linked to an AI-enabled hacking campaign.

Security researchers at Forescout have identified 15 new vulnerabilities in TP-Link's Omada zero-touch provisioning (ZTP) systems, with some flaws allowing for full network takeover when chained together. These vulnerabilities could enable attackers to gain administrative control over cloud controllers and internal networks, impacting organizations using Omada devices for automated network configuration.

CISA has added a high-severity N-able N-central vulnerability (CVE-2026-18577) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw, an incomplete patch of a previous vulnerability, allows authentication bypass and account takeover, enabling attackers to gain administrative access and pivot into managed endpoints.

N-able issued a warning about active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting its N-central RMM servers. The company released hotfix 2026.3.1.7 to address the flaw, which allows administrative account takeover and impacts all N-central versions before 2026.3. This is significant because N-central is a widely used RMM platform, and compromise could extend attacks beyond N-able's direct customers.

The INC Ransomware group has become the primary threat actor exploiting recently disclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These flaws, CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution and device takeover, impacting organizations globally. The exploitation enables long-term persistent access and lateral movement within corporate networks, leading to ransomware deployment.

N-able has released patches for CVE-2026-18577, an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) product that has been actively exploited. This vulnerability allows attackers to gain administrative access to N-central servers, potentially compromising customer systems managed by MSPs. The exploitation of this flaw could lead to widespread access to client networks, enabling further malicious activities.

The INC Ransomware group is actively exploiting two recently patched SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to compromise organizations and deploy ransomware. These vulnerabilities allow unauthenticated remote attackers to gain root privileges and have been added to CISA's Known Exploited Vulnerabilities catalog, indicating their active use in attacks.

Attackers exploited an authentication bypass vulnerability in N-able N-central, gaining remote administrative access to servers and subsequently customer systems. An initial fix for the vulnerability proved incomplete, allowing attackers to maintain access through Cloudflare tunnels even after N-central servers were updated.

Adobe released security updates for Campaign Classic (ACC) to fix a critical vulnerability (CVE-2026-48449) with a CVSS score of 10.0, allowing arbitrary code execution without user interaction. The company also addressed eight critical flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. These updates are important for users of Adobe's marketing automation platform and creative software to prevent potential security breaches.

JetBrains released patches for a critical-severity vulnerability (CVE-2026-63077) in TeamCity On-Premises that allowed unauthenticated remote code execution. This flaw could enable attackers to bypass authentication, execute arbitrary commands, and potentially compromise CI/CD pipelines, making immediate patching crucial for affected organizations.

JetBrains has issued a warning about a critical authentication bypass vulnerability, CVE-2026-63077, in TeamCity On-Premises that could lead to remote code execution. This flaw allows attackers with HTTPS access to bypass authentication and execute arbitrary commands, potentially compromising CI/CD pipelines and sensitive data. Administrators are advised to update to patched versions or apply a security plugin immediately.

Broadcom released security updates for five vulnerabilities in VMware products, including three critical flaws that could lead to authentication bypass, arbitrary code execution, or virtual machine escapes. These vulnerabilities affect widely used VMware virtualization platforms and require immediate patching to prevent unauthorized access and system compromise.

South Korean authorities and security firms disclosed a state-sponsored campaign that exploited vulnerabilities in AnySign4PC financial-security software through compromised domestic websites. This allowed attackers to install SIGNBT or COPPERHEDGE backdoors on targeted visitors' systems without user interaction. The campaign highlights the risk of supply chain attacks targeting widely used software in specific regions.

Cisco has disclosed a critical vulnerability in its Firepower Management Center (FMC) that involves static credentials, which has been actively exploited as a zero-day. This vulnerability allows an unauthenticated attacker to gain root access to affected devices, posing a significant risk to network security.

Cisco released patches for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting its Secure Firewall Management Center (FMC) product. This vulnerability, rated high severity, involves static credentials for a low-privilege user, allowing attackers to access sensitive data and potentially escalate privileges when chained with other flaws. The exploitation of this vulnerability highlights the ongoing need for organizations to promptly apply security updates and monitor for indicators of compromise in critical network infrastructure.

CISA added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw, CVE-2026-20316, allows unauthenticated remote attackers to access sensitive data using static low-privilege credentials. This vulnerability is critical as it can be chained with other flaws to escalate privileges, posing a significant risk to affected systems.

Cisco has issued a warning regarding a high-severity static credential vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC) software, which is being actively exploited in zero-day attacks. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems, potentially leading to privilege escalation when combined with other vulnerabilities. Cisco has released hot fixes for multiple FMC releases and advises immediate installation.

A critical security flaw (CVE-2026-59726) in Ruflo, an AI multi-agent orchestration platform, allows unauthenticated attackers to execute remote commands and poison AI memory. The vulnerability impacts all versions before 3.16.3 and exposes 233 tools, including shell command execution, through an unauthenticated Model Context Protocol (MCP) bridge.

Broadcom released security updates addressing multiple vulnerabilities in VMware products, including three critical flaws. These critical vulnerabilities could allow authentication bypass, arbitrary code execution, and code execution on the host system.

Nebula Security reported a patched Firefox JIT vulnerability, CVE-2026-10702, which allowed arbitrary code execution by visiting a malicious webpage and affected Tor Browser versions incorporating vulnerable Firefox releases. This flaw highlights a critical browser security risk, as it required no user interaction beyond page visitation and could be a first stage in more complex exploit chains.

Broadcom released patches for multiple vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three critical flaws. These vulnerabilities include a VM escape in ESXi, an authentication bypass in vCenter, and a remote code execution flaw in vCenter, necessitating immediate updates for affected systems.

Cybersecurity researchers have released technical details and a public proof-of-concept (PoC) for a critical authentication bypass vulnerability (CVE-2026-16232) in Check Point Security Management Server and Multi-Domain Security Management Server. This flaw allows unauthenticated remote attackers to gain full administrative privileges, and Check Point has confirmed active exploitation as a zero-day against a limited number of customers.

vBulletin released patches for a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-61511, affecting versions 5.x and 6.x up to 5.7.5 and 6.2.1. The flaw allows unauthenticated attackers to execute arbitrary PHP code through template rendering, and a public proof-of-concept exploit is available, increasing the risk for unpatched servers.

JetBrains has released updates and a security patch for a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary operating system commands. This flaw could lead to exposure of TeamCity data, configurations, and credentials, making immediate patching crucial for affected organizations.

Arista Networks released patches for a critical OS injection vulnerability (CVE-2026-16812) in its VeloCloud Orchestrator (VCO) platform, which is being actively exploited as a zero-day. This flaw allows remote attackers to access privileged functionality without authentication, impacting the confidentiality, integrity, and availability of the orchestrator and its managed data.

A critical command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. This flaw allows remote attackers to execute arbitrary code, potentially compromising the orchestrator and managed data.

Arista has released patches for a maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises VeloCloud Orchestrator deployments that is being actively exploited. This flaw allows unauthenticated remote attackers to compromise the orchestrator and its managed data, affecting specific VCO versions.

Details and a proof-of-concept for a pre-authentication remote code execution vulnerability in vBulletin (CVE-2026-61511) were publicly released on July 27. This flaw affects versions 6.2.1 and earlier, and 6.1.6 and earlier, allowing unauthenticated attackers to execute code on unpatched vBulletin forum servers. The public release of exploit details increases the urgency for administrators to apply patches, as the vulnerability requires no user interaction or authentication.

n8n has patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) that allowed authenticated workflow editors to execute operating system commands on the server running the automation platform. This flaw could expose sensitive data like encryption keys and provide access to connected databases, making immediate updates critical for affected n8n users.

Check Point disclosed a critical zero-day vulnerability, CVE-2026-16232, in its Security Management and Multi-Domain Management products, which has been actively exploited. This authentication bypass allows attackers full administrator privileges, leading CISA to add it to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch it by July 25.

Check Point Software has addressed an actively exploited zero-day vulnerability (CVE-2026-16232) in its SmartConsole graphical user interface admin panel. This authentication bypass allows unauthenticated attackers to gain administrator privileges and modify security configurations. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities, mandating U.S. federal agencies to patch by July 25.

CISA has mandated U.S. government agencies to urgently patch a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited by threat actors. This flaw can allow unauthenticated attackers to execute code with root privileges, posing significant risks to federal operations.

SonicWall disclosed two critical vulnerabilities in SMA1000 appliances that were exploited as zero-days by attackers, leading to custom malware installation. The flaws allow unauthorized access to internal applications and management services, impacting security for users of affected VPN devices.

SonicWall's CVE-2026-15409 and CVE-2026-15410 vulnerabilities were actively exploited for weeks before patches were issued. The breaches allowed attackers using custom malware to access sensitive information on SMA1000 appliances.

A previously unknown threat actor exploited SonicWall Secure Mobile Access (SMA) 1000 series VPN vulnerabilities before their public disclosure. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution, leading to potential root takeover of affected devices.

CISA has directed U.S. government agencies to prioritize patching two critical vulnerabilities in Fortinet's FortiSandbox. Exploitation allows unauthenticated attackers to remotely execute code, necessitating immediate upgrades to mitigate risks.

CISA has added CVE-2026-25089, an unauthenticated OS command injection vulnerability in FortiSandbox, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability allows attackers to inject commands through the web interface without authentication, elevating the risk for affected users as this is the third FortiSandbox exploit detected this year.

F5 released patches for eight vulnerabilities affecting NGINX Plus, NGINX Open Source, and BIG-IP, including a critical flaw with a CVSS score of 9.2. These updates are significant as they address potential exploits leading to denial-of-service (DoS) conditions and unauthorized memory access.

Two vulnerabilities in SonicWall's SMA 1000 series are actively exploited, one allowing arbitrary command execution. SonicWall urges immediate patching to mitigate risks associated with these serious security flaws.

SonicWall has issued an urgent patch for its SMA1000 appliances following the discovery of two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities pose serious threats, including server-side request forgery and code injection risks, affecting enterprise security significantly.

SonicWall has disclosed two critical vulnerabilities in SMA1000 products being actively exploited in zero-day attacks. Patching is essential as both issues could allow unauthorized access and control over affected appliances.

SAP has released security updates to address critical vulnerabilities in its NetWeaver and Commerce Cloud products, including a CVSS 9.9 flaw in the NetWeaver ABAP server. This flaw could allow authenticated attackers to gain unauthorized access or modify data, impacting the integrity of systems across affected deployments.

Adobe has released updates for 12 products fix 88 vulnerabilities, with 13 identified in ColdFusion, including eight critical bugs allowing for arbitrary code execution. The urgency of these patches is underscored by their high priority rating, indicating immediate action is necessary to protect systems from potential exploitation.

SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in NetWeaver and Commerce Cloud. These flaws pose serious risks such as data breaches and service disruptions, making it crucial for companies using these platforms to apply the patches promptly.

SAP has released 20 new security notes addressing critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-2026-44747, could allow attackers to modify data and disrupt services, highlighting the importance of timely patching for enterprise software security.

CISA has issued a warning regarding actively exploited remote code execution vulnerabilities in Joomla extensions iCagenda and Balbooa Forms. The flaws enable attackers to upload malicious files, potentially leading to website compromise, prompting federal agencies to implement security updates immediately.

Critical vulnerabilities in Balbooa Forms and iCagenda Joomla extensions allow unauthenticated attackers to achieve remote code execution (RCE). Both vulnerabilities, tracked as CVE-2026-56291 and CVE-2026-48939, are actively exploited, prompting immediate patching recommendations from CISA for federal agencies and all organizations.

CISA has listed two critical vulnerabilities affecting Joomla extensions iCagenda and Balbooa Forms due to reported zero-day exploits. Both vulnerabilities allow arbitrary file uploads leading to remote code execution, significantly threatening Joomla site security.

CISA has warned about actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions. These flaws allow for remote code execution and are critical, with CISA urging immediate action from federal agencies to patch them.

CISA has mandated that federal agencies patch a critical ColdFusion vulnerability (CVE-2026-48282) by June 10 due to its active exploitation risk. Adobe's security update, released recently, is crucial to prevent unauthorized remote code execution on affected systems.

CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting active exploitation. These include vulnerabilities in Adobe ColdFusion, Joomla, and Langflow, with CVSS scores up to 10.0, requiring immediate attention from users and administrators.

A critical vulnerability in Adobe ColdFusion, CVE-2026-48282, is being exploited by threat actors for arbitrary code execution following its disclosure. The flaw, with a CVSS score of 10, was patched by Adobe, but attacks began within two hours of the vulnerability becoming public, emphasizing urgent risk for users.

A severe vulnerability in Adobe ColdFusion, CVE-2026-48282, is now being actively exploited by attackers. This flaw allows remote code execution on unpatched systems, prompting Adobe to urge immediate patching of affected versions.

Adobe released patches for seven critical vulnerabilities in ColdFusion and Campaign Classic that could allow arbitrary code execution. These updates address maximum-severity flaws identified by CVSS scores of 10.0, underscoring the importance of these patches for users operating these systems.

Adobe has released security updates for ColdFusion and Campaign Classic, addressing six maximum severity vulnerabilities, including critical flaws allowing arbitrary code execution. These updates come amid increased scrutiny on application security as threat actors rapidly exploit weaknesses.