Vulnerability & Exploit Coverage
646 articles · sorted newest first

Check Point Patches Two CVSS 9.8 VPN RCE Flaws
CVE-2026-85102 and CVE-2026-85103 allow unauthenticated RCE via VPN certificate handling in Check Point firewall products. Patches are out now.

Cisco FMC Hit by Qilin Ransomware, State-Sponsored Actors
Cisco Talos: three threat clusters exploit Cisco FMC CVE-2026-20079. Qilin ransomware deployed; credential theft observed. CISA deadline September 12.

PaperCut Issues Stable Fix as AI-Powered Attacks Widen
PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today
CISA's September 12 deadline covers confirmed exploited flaws in Cisco FMC, Citrix NetScaler, and Fortinet FortiOS. Federal agencies must patch by tomorrow; everyone else should be moving too.

Nightmare Eclipse Drops Windows Defender Zero-Day
Nightmare Eclipse's ShieldCrash exploit achieves SYSTEM privileges on fully patched Windows systems by targeting Windows Defender itself.

Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks
CVSS 8.1 heap overflow in FortiOS is exploited with PivotC2 RAT. January 2026 patch available; CISA BOD 26-04 deadline for federal agencies is September 12.

Veradigm Discloses Patient Breach After Ransomware Claim
Veradigm disclosed a patient data breach traced to a third-party vendor after the Gentlemen ransomware gang claimed responsibility for the attack.

SAP September Patches: CVSS 10 RCE in EPP Processing
SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

Ivanti Patches Critical RCE in Neurons, EPMM, Sentry
Ivanti's September 2026 patches close six critical RCEs in Neurons for ITSM and authentication bypass flaws in Sentry and EPMM. Patch now.

Cisco Confirms FMC CVSS 10 Auth Bypass Exploited
Cisco confirms CVE-2026-20079, CVSS 10.0 FMC auth bypass, is actively exploited. Unauthenticated attackers gain root OS access. CISA KEV deadline September 12.

Linux Rootkit Targets F5 BIG-IP APM, Lives in Memory
Attackers are breaching F5 BIG-IP APM devices to deploy a Linux rootkit that hooks PHP file loading and injects a fileless web shell into memory, leaving no disk artifacts.

Microsoft Patches Record 974 Vulns, 2 Zero-Days
September 2026 Patch Tuesday: Microsoft patches a record 974 CVEs, including two exploited Windows zero-days now on CISA's KEV catalog.

Google Patches Chrome's 7th Exploited Zero-Day of 2026
Google patched the seventh actively exploited Chrome zero-day of 2026 on September 9, in a 230-vulnerability update. CVE designation pending.

CISA Adds N-able N-central Auth Bypass to KEV
CISA added a maximum-severity pre-auth RCE in N-able N-central to its KEV catalog on September 9. N-able patched it; audit deployments for new user accounts.

Adobe Patches StyleSmuggler, CVSS 10 Magento Zero-Day
Adobe's September 8 emergency update patches CVE-2026-75650, a CVSS 10.0 template-injection zero-day exploited to plant Rust backdoors in Commerce and Magento stores. CISA deadline: September 11.

Fake IT Calls Drive M365 Exec Data Theft Campaign
Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

220M Passport Records Exposed in Vietnam APIS Leak
An exposed Vietnam-linked APIS database held 220 million traveler records: names, passport numbers, birth dates, nationalities, and flight routes.

Nightmare Eclipse: Zero-Days Hit CrowdStrike, Nvidia, Avast
Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike Falcon, Nvidia drivers, and Avast antivirus. No CVE IDs or vendor patches yet.

Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE
A command injection in the WISE-6610 LoRaWAN gateway's Basic Station handler allows remote code execution. Exploit is public. Patch: firmware 1.2.4_20260821.

Telerik UI RCE Chain: PoC Published, Patch Is Out
TantoSec's public exploit chains seven Telerik UI CVEs into unauthenticated RCE. Non-default configs only. Patch to 2026 Q2 SP1 now.

Patch N-central Again: Hotfix 4 Is Out
N-able's fourth N-central hotfix in five weeks renders Hotfix 3 obsolete. Update to 2026.3.1.14 now: CVE-2026-86218 is actively exploited.

JSCeal Malware Bypasses Google Auth with Stolen Cookies
JSCeal is compiled V8 JavaScript malware with credential harvesting and traffic interception. It bypasses Google Authentication using stolen session cookies.

N-central Under Active Attack: Patch CVE-2026-86218 Now
BleepingComputer reports N-central servers under active attack one day after N-able's CVSS 10.0 pre-auth RCE disclosure. Update to version 2026.3.1.14 immediately.
No articles match the current filters.