APT28 Weaponized That Office Zero-Day in Three Days Flat
Russia's APT28 began exploiting Microsoft Office CVE-2026-21509 just 72 hours after disclosure, targeting Ukraine, Slovakia, and Romania with email-stealing malware and Covenant implants.
Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.
Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.
Updated September 14, 2026 — all 204 published advisories are browsable here. The newest one is already under active attack: a ConnectWise ScreenConnect flaw being exploited in the wild, in the remote-support tool an IT provider uses to take control of every machine in your office (CVE-2026-84869). Behind it, a GitLab flaw rated CVSS 10, the maximum possible severity score, that lets an attacker with no login read any file off the server that stores your source code (CVE-2026-85706), and a pair of PaperCut print-management zero-days already used to break into 395 organizations, on the server that quietly sits inside the network and talks to every desktop in the building (CVE-2026-81578 and CVE-2026-82078). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.
Russia's APT28 began exploiting Microsoft Office CVE-2026-21509 just 72 hours after disclosure, targeting Ukraine, Slovakia, and Romania with email-stealing malware and Covenant implants.
A high-severity Microsoft Office zero-day (CVE-2026-21509) is being actively exploited to bypass security controls designed to block risky COM and OLE content. Successful exploitation requires a user to open a malicious Office document, enabling follow-on payload execution and intrusion activity. Apply Microsoft's out-of-band update immediately or deploy the recommended registry-based mitigation if patching is delayed.
Read moreReact2Shell refers to a newly disclosed set of exploitation paths affecting React Server Components and modern server-side rendering workflows. In vulnerable implementations, attackers may escalate from user-driven application behavior into sensitive server-side execution, data access, or compromise of backend services. Organizations using RSC or SSR patterns should audit server-executed components, reduce dynamic execution paths, and apply strict validation and least-privilege controls.
Read moreOur CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.
Subscribe to our newsletter and get the latest security insights delivered to your inbox.