Vulnerabilities
Microsoft Entra ID: CVE-2026-69836 patched
Microsoft fixed CVE-2026-69836 in Entra ID, a critical deserialization flaw rated CVSS 10.0. No customer action is needed.
Aug 23, 2026 · 2 min
COLCERT warns on Operation Dream Job
COLCERT warned on Operation Dream Job and CVE-2026-68820, a Windows flaw used to raise privileges and deploy malware.
Aug 22, 2026 · 3 min
CISA Adds Four Critical CVEs to KEV Catalog
CISA added four actively exploited flaws in Apple, Microsoft and VMware to its KEV catalog and set the federal deadline for Aug. 21.
Aug 22, 2026 · 3 min
INCIBE flags PLCnext, Quay, and OpenShift flaws
INCIBE-CERT issued alerts on PLCnext, Red Hat Quay, and OpenShift components, including one critical flaw with no active exploitation seen.
Aug 20, 2026 · 2 min
CERT-PY flags critical Ubiquiti flaws
CERT-PY issued an alert on critical Ubiquiti flaws, while CSIRT Panama also warned about a PAN-OS issue on August 13, 2026.
Aug 18, 2026 · 2 min
CVE-2026-20349 hits Cisco ASA
CISA added CVE-2026-20349 to its KEV catalog. The Cisco ASA and FTD flaw can trigger remote reboots, and hotfixes are available.
Aug 17, 2026 · 2 min
CVE-2026-50656 ShieldBreak Bypasses Defender Patch
ShieldBreak targets CVE-2026-50656 and, according to multiple reports, can raise privileges to SYSTEM on fully patched Windows.
Aug 15, 2026 · 3 min
VMware vCenter: CVE-2026-59310 exploited
Telconet and Shadowserver confirmed active exploitation of CVE-2026-59310 in vCenter. Broadcom has issued patches and there is no workaround.
Aug 14, 2026 · 2 min
Microsoft patches 421 CVEs in August 2026
Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.
Aug 12, 2026 · 3 min
CISA adds CVE-2026-34486 to KEV catalog
CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min
CVE-2026-8037 lands in CISA's KEV catalog
CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
Aug 10, 2026 · 2 min
Panama CSIRT Warns on Check Point CVE-2026-18574
CSIRT Panama and Check Point warned about CVE-2026-18574, a critical flaw that can bypass authentication and run commands.
Aug 7, 2026 · 2 min
CISA Confirms SharePoint, Check Point Exploits
CISA added SharePoint and Check Point flaws to KEV as active exploitation continues. Latin America faces added pressure from ERP and firewall bugs.
Aug 4, 2026 · 3 min
CVE-2026-18577 hits N-able N-central
N-able issued a hotfix for CVE-2026-18577, an active authentication bypass in N-central affecting MSPs.
Aug 4, 2026 · 3 min
INCIBE warns on 5 critical VMware flaws
INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.
Aug 3, 2026 · 2 min
CISA Adds Cisco FMC CVE-2026-20316 to KEV
CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
Jul 30, 2026 · 2 min
CISA adds CVE-2026-16812 to KEV catalog
CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
Jul 28, 2026 · 2 min
Chile Flags Critical Ivanti Flaws
Chile’s CSIRT warned of critical Ivanti and Citrix flaws with active exploitation, and urged patching, config review, and log monitoring.
Jul 27, 2026 · 2 min
Brazil warns on CVE-2024-24919 in VPNs
CERT.br warned of active exploitation of CVE-2024-24919 in enterprise VPNs used in Brazil and urged immediate patching.
Jul 26, 2026 · 2 min
Chile alerts on OpenSSH CVE-2024-6387
CSIRT Chile warned about critical OpenSSH flaw CVE-2024-6387 and confirmed active exploitation. Patch or mitigate now.
Jul 26, 2026 · 2 min