2026-10-08 00:18 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerabilit…
P30
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process…
P30
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by t…
P30
2026-10-07 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-10-07 16:15 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and str…
P30
2026-10-05 06:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 08:00 UTC
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to
P30
2026-10-05 05:14 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-05 05:30 UTC
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.
P30
2026-10-02 19:21 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-10-02 08:07 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-02 08:20 UTC
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek.
P30
2026-10-01 22:42 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 22:45 UTC
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
P30
2026-10-01 12:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 12:40 UTC
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]
P30
2026-09-30 12:48 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 12:50 UTC
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek.
P30
2026-09-30 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]
P30
2026-09-29 21:31 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-29 21:50 UTC
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
P30
2026-09-29 18:37 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 18:50 UTC
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
P30
2026-09-29 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…
P30
2026-09-29 06:18 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 06:30 UTC
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ appeared first on SecurityWeek.
P30
2026-09-28 07:29 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-28 07:45 UTC
Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek.
P30
2026-09-23 08:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
P30
2026-09-22 19:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-22 20:50 UTC
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable […]
P30
2026-09-22 18:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 19:25 UTC
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
P30
2026-09-22 16:52 UTC
Government
CERT-EU Security Advisories · indexed 2026-09-22 17:10 UTC
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.
P30
2026-09-22 12:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-22 12:55 UTC
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]
P30
2026-09-22 12:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
P30
2026-09-20 16:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-20 17:10 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details on how the […]
P30
2026-09-17 21:13 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-02 16:10 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-09-17 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
P30
2026-09-16 16:07 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-09 16:30 UTC
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity…
P30
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:05 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-09-16 13:43 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has […]
P30
2026-09-14 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-14 16:20 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL …
P30