Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated October 4, 2026 — all 221 published advisories are browsable here. The four drawing the most attention right now: a Cisco Catalyst SD-WAN Manager flaw that hands an attacker full admin control of your wide-area network with no password (CVE-2026-76504, rated 9.8 out of 10) — there is no workaround, the CISA federal deadline passed on October 3, and one compromised manager pushes settings to every branch router you own, so upgrade and then check the logs; a FortiMail email-gateway flaw being exploited before any fix exists (CVE-2026-104286) — there is no patch yet, so affected systems rely on Fortinet’s workaround; two Citrix NetScaler flaws exploited for weeks before the September 27 fix (CVE-2026-88771 and CVE-2026-88772) — a patched box can still be hosting a webshell (a hidden back door left behind in the software itself); and a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in (CVE-2026-48842), still exploited because it ships inside hosting control panels most firms forget they run. Three of the four were attacked before most owners heard about them, so what decides the cost is how fast someone notices. If you are not sure who is reading the alerts at 2 a.m., our 24/7 staffed security operations center handles the detection and the response.

Severity: All Critical High Medium Low
222 articles found
CVE-2026-21509
high
CVSS 7.8
CVE AdvisoryVulnerabilityCVE-2026-21509 CVSS 7.8 •Jan 28, 2026

HIGH: Microsoft Office OLE Security Feature Bypass Zero-Day - Actively Exploited

A high-severity Microsoft Office zero-day (CVE-2026-21509) is being actively exploited to bypass security controls designed to block risky COM and OLE content. Successful exploitation requires a user to open a malicious Office document, enabling follow-on payload execution and intrusion activity. Apply Microsoft's out-of-band update immediately or deploy the recommended registry-based mitigation if patching is delayed.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 11 of 12Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.