
Citrix NetScaler adds two exploited zero-days
CVE-2026-88771 and CVE-2026-88772 were used to plant web shells in NetScaler. CISA also added CVE-2026-88779 to KEV.
Oct 8, 2026 · 3 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

CVE-2026-88771 and CVE-2026-88772 were used to plant web shells in NetScaler. CISA also added CVE-2026-88779 to KEV.
Oct 8, 2026 · 3 min

Microsoft fixed an authorization flaw in on-prem Exchange Server that could let users read other mailboxes in the same organization.
Oct 6, 2026 · 2 min

Cisco fixed CVE-2026-76504 in Catalyst SD-WAN Manager, an actively exploited authentication bypass with no workaround.
Oct 1, 2026 · 2 min

CISA added CVE-2026-88772 to its KEV catalog for active exploitation against Citrix NetScaler ADC
Sep 30, 2026 · 2 min

Apple fixed CVE-2026-86950 in iOS, iPadOS, and macOS. The CoreGraphics flaw may have been used in highly sophisticated attacks.
Sep 30, 2026 · 3 min

Brazil’s CTIR Gov added a critical alert on Check Point Quantum Security Gateway. Fortinet, GitLab and Stockagile also drew notices.
Sep 28, 2026 · 4 min

CISA added CVE-2026-65660 to the KEV catalog after active exploitation was reported. Microsoft has already released patches.
Sep 27, 2026 · 2 min

The flaw affects Security Gateway and Spark Firewall, enables unauthenticated RCE, and was patched on Sept. 9.
Sep 25, 2026 · 2 min

Mexico’s anti-corruption office opened a review of a reported Aeroméxico data exposure. The airline said it had previously suffered a cyberattack.
Sep 24, 2026 · 2 min

ECUCERT flagged three exploited CVEs in MikroTik RouterOS. Taiwan's NICS-TW and the Dutch DIVD also reported active attacks.
Sep 24, 2026 · 3 min

F5 and security agencies warned of an exploited flaw in BIG-IP APM that can enable unauthenticated RCE and is now in CISA’s KEV.
Sep 24, 2026 · 2 min

CISA confirmed active exploitation of CVE-2026-84869 in ScreenConnect. ConnectWise told customers to update to 26.6.5
Sep 22, 2026 · 2 min

CERT-PY expanded its Ubiquiti advisory with affected products, versions and remote code execution risks tied to UniFi OS flaws.
Sep 18, 2026 · 5 min

Cisco disclosed an auth bypass in ISE and ISE-PIC with active exploitation and no workaround. Patches are required for 3.1 to 3.5.
Sep 18, 2026 · 2 min

Cisco confirmed active exploitation in Secure Email Gateway. The flaw can let attackers run commands as root through a crafted email.
Sep 16, 2026 · 2 min

CERT-PY added new MISP alerts covering critical flaws, an authentication bypass, and other issues affecting versions through 2.5.45.
Sep 13, 2026 · 5 min

CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.
Sep 12, 2026 · 3 min

Microsoft’s September 2026 Patch Tuesday fixed 974 vulnerabilities, including two actively exploited Windows zero-days.
Sep 9, 2026 · 3 min

Google issued an emergency Chrome update fixing CVE-2026-85046, an actively exploited flaw in V8.
Sep 8, 2026 · 3 min

CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut
Sep 6, 2026 · 2 min

Cisco patched a critical flaw in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root.
Sep 4, 2026 · 3 min

A public PoC for CVE-2026-62911 shows an attack chain that can end in RCE and SYSTEM on Exchange, with 21,899 servers still vulnerable.
Sep 3, 2026 · 2 min

CERT.PY flagged a high-severity issue in Cisco Catalyst SD-WAN. Cisco also patched five flaws in the same round, including three critical ones.
Sep 1, 2026 · 1 min

CISA added exploited flaws in August, including Citrix NetScaler, Microsoft SQL Server and VMware vCenter, to its KEV catalog.
Aug 29, 2026 · 3 min

CERT-PY warned about critical Ubiquiti flaws and said Samba patches are already available. Ubiquiti fixed 22 UniFi vulnerabilities.
Aug 28, 2026 · 3 min

INCIBE-CERT and other CSIRTs warned about CVE-2026-59270 in Spring Security, a critical flaw with affected branches already listed.
Aug 28, 2026 · 4 min

Cisco released hardening updates for Crosswork and Secure Workload that fix nine flaws, five rated CVSS 10.0, with no known workarounds.
Aug 25, 2026 · 2 min

Microsoft fixed CVE-2026-69836 in Entra ID, a critical deserialization flaw rated CVSS 10.0. No customer action is needed.
Aug 23, 2026 · 2 min

COLCERT warned on Operation Dream Job and CVE-2026-68820, a Windows flaw used to raise privileges and deploy malware.
Aug 22, 2026 · 3 min

CISA added CVE-2026-73570 in Zimbra to KEV and set the federal remediation deadline for Aug. 24.
Aug 22, 2026 · 4 min

INCIBE-CERT issued alerts on PLCnext, Red Hat Quay, and OpenShift components, including one critical flaw with no active exploitation seen.
Aug 20, 2026 · 2 min

CERT-PY flagged critical Ubiquiti flaws that could lead to remote code execution, while technical details point to UniFi OS chains.
Aug 18, 2026 · 4 min

CISA added CVE-2026-20349 to its KEV catalog. The Cisco ASA and FTD flaw can trigger remote reboots, and hotfixes are available.
Aug 17, 2026 · 2 min

ShieldBreak targets CVE-2026-50656 and, according to multiple reports, can raise privileges to SYSTEM on fully patched Windows.
Aug 15, 2026 · 3 min

Telconet and Shadowserver confirmed active exploitation of CVE-2026-59310 in vCenter. Broadcom has issued patches and there is no workaround.
Aug 14, 2026 · 2 min

Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.
Aug 12, 2026 · 3 min

CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min

CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
Aug 10, 2026 · 2 min

CSIRT Panama and Check Point warned about CVE-2026-18574, a critical flaw that can bypass authentication and run commands.
Aug 7, 2026 · 2 min

CISA added SharePoint and Check Point flaws to KEV as active exploitation continues. Latin America faces added pressure from ERP and firewall bugs.
Aug 4, 2026 · 3 min

N-able issued a hotfix for CVE-2026-18577, an active authentication bypass in N-central affecting MSPs.
Aug 4, 2026 · 3 min

INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.
Aug 3, 2026 · 2 min

CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
Jul 30, 2026 · 2 min

CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
Jul 28, 2026 · 2 min

Chile’s CSIRT warned of critical Ivanti and Citrix flaws with active exploitation, and urged patching, config review, and log monitoring.
Jul 27, 2026 · 2 min

CERT.br warned of active exploitation of CVE-2024-24919 in enterprise VPNs used in Brazil and urged immediate patching.
Jul 26, 2026 · 2 min

CSIRT Chile warned about critical OpenSSH flaw CVE-2024-6387 and confirmed active exploitation. Patch or mitigate now.
Jul 26, 2026 · 2 min

CISA, NSA and FBI warned on a Zimbra flaw abused by LAUNDRY BEAR to steal email, 2FA codes and passwords with a single message.
Jul 24, 2026 · 1 min

CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.
Jul 19, 2026 · 3 min

CTIR Gov and Costa Rica’s CSIRT are coordinating alerts over an active campaign targeting Joomla sites with outdated JCE.
Jul 16, 2026 · 2 min