Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated October 3, 2026 — all 220 published advisories are browsable here. The four drawing the most attention right now: a FortiMail email-gateway flaw being exploited before any fix exists (CVE-2026-104286, rated 9 out of 10 for severity) — there is no patch yet, so every affected 8.0, 7.6, 7.4 and 7.2 system is relying on Fortinet’s workaround, starting with switching off the Identity Based Encryption portal if you do not use it; two Citrix NetScaler flaws exploited for weeks before the September 27 fix (CVE-2026-88771 and CVE-2026-88772) — a patched box can still be hosting a webshell (a hidden back door left behind in the software itself), so update to 14.1-73.37 or 13.1-64.23 and then go looking for what was left behind; a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in (CVE-2026-48842), patched in May 2026 and still being exploited because it ships inside hosting control panels most firms forget they run; and a Microsoft SharePoint Server flaw under active attack that lets an intruder run their own code on the server holding your internal documents (CVE-2026-65660), whose CISA federal patch deadline passed on September 28, so an unpatched server is now overdue rather than pending. Two of the four are email systems, and one has no fix at all, which is why what decides the cost is how fast someone notices. If you are not sure who is reading the alerts at 2 a.m., our 24/7 staffed security operations center handles the detection and the response.

Severity: All Critical High Medium Low
138 articles found
Featured Story
CVE-2026-76504
critical
Oct 3, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Cisco Catalyst SD-WAN Manager Auth Bypass Exploited in the Wild

Cisco confirmed active exploitation of CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager that grants unauthenticated attackers admin API access. CISA added it to KEV with an October 3 deadline. No workaround exists, so upgrade to the fixed release and hunt the logs for encoded j_security_check requests.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerability•Sep 23, 2026

CRITICAL: F5 BIG-IP APM CVE-2026-94127 Exploited for Unauthenticated RCE

F5 is shipping emergency hotfixes for CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM that hands unauthenticated attackers remote code execution on appliances acting as OAuth authorization servers. CISA added it to the Known Exploited Vulnerabilities catalog on September 22 and gave federal agencies until Friday. Shadowserver tracks more than 14,700 exposed BIG-IP APM fingerprints.

Read more
critical
CVE AdvisoryVulnerability•Sep 14, 2026

CRITICAL: MikroTik RouterOS Flaws Chained to Hijack Routers Over SSH

MikroTik patched CVE-2026-67276 and CVE-2026-86060, two CVSS 9.2 RouterOS SSH flaws that CERT Polska found chained in the wild into an unauthenticated full admin takeover dubbed MikroTrick. Exploitation began a day before fixes shipped, CISA added CVE-2026-86060 and CVE-2026-67277 to KEV, and roughly 122,500 devices expose SSH. Upgrade to RouterOS 6.49.21, 7.23.4 or 7.24.2 and audit for rogue accounts.

Read more
critical
CVE AdvisoryVulnerability•Sep 13, 2026

CRITICAL: ConnectWise ScreenConnect CVE-2026-84869 Under Active Attack

ConnectWise patched CVE-2026-84869, a CVSS 9.9 missing authorization flaw in the ScreenConnect client that lets files be pushed and executed during a live remote session without Host confirmation. Huntress linked it to worm-like campaigns that infect technicians who connect to compromised endpoints, and CISA added it to the KEV catalog on September 11. Upgrade to 26.6.5 and reinstall host clients.

Read more
critical
CVE AdvisoryVulnerability•Sep 11, 2026

CRITICAL: PaperCut Zero-Days Exploited to Breach 395 Organizations

PaperCut has shipped maintenance releases 26.0.5, 25.0.13, and 24.1.10 to replace three rounds of emergency patches for CVE-2026-81578 and CVE-2026-82078, two actively exploited flaws that chain into preauthentication remote code execution. Researchers tracked a campaign that compromised more than 440 instances at 395 organizations across 48 countries, reaching domain admin at one school in seven minutes.

Read more
critical
CVE AdvisoryVulnerability•Sep 10, 2026

CRITICAL: Cisco Firewall Management Center CVE-2026-20079 Under Active Attack

CISA added Cisco Secure Firewall Management Center flaw CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 federal remediation deadline. The CVSS 10.0 authentication bypass chains a static boot-time session ID and hardcoded credentials into unauthenticated root code execution on the appliance that manages your firewall policy. Patches have been available since March.

Read more
critical
CVE AdvisoryVulnerability•Sep 8, 2026

CRITICAL: FreeIPA CVE-2026-76578 Gives Anonymous Clients Admin Rights

FreeIPA CVE-2026-76578 lets an unauthenticated LDAP client create a Kerberos principal of its own choosing and land it in the administrators group, with no credentials and no prior access required. Red Hat rates it 9.8 critical and reproduced the chain against default installations. FreeIPA 4.13.4 fixes it, while the 389 Directory Server half of the chain is still catching up across platforms.

Read more
critical
CVE AdvisoryVulnerability•Sep 7, 2026

CRITICAL: N-able N-central CVE-2026-86218 Pre-Auth RCE Under Active Attack

N-able shipped Hotfix 4 for N-central 2026.3 on September 5, closing CVE-2026-86218, an unauthenticated remote code execution flaw rated CVSS 10.0 that lets attackers run code on the RMM console with no credentials. It is the fourth emergency hotfix in five weeks, and Huntress confirmed a compromised production server. On-premises customers need build 2026.3.1.14 now.

Read more
critical
CVE AdvisoryVulnerability•Sep 6, 2026

CRITICAL: Magento and Adobe Commerce Zero-Day Exploited With No Patch Available

Attackers are actively exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce that Sansec has named StyleSmuggler. Every current version is affected including 2.4.9, exploitation began on September 4, and Adobe has not published a CVE, an advisory, or a fix. The chain ends in a persistent Rust backdoor disguised as a kernel thread.

Read more
critical
CVE AdvisoryVulnerability•Sep 5, 2026

CRITICAL: Cisco Nexus 9000 CVE-2026-20212 Allows Unauthenticated Root RCE

Cisco patched CVE-2026-20212, a CVSS 9.8 flaw in Nexus 9000 Series switches built on Silicon One ASICs that lets an unauthenticated remote attacker execute code as root. The S1HAL process listens on TCP ports 43210 and 43211 through the default Layer 3 VRF, and NX-OS releases 10.3(1) through 10.6(3s) are affected. Upgrade to 10.6(4) or later, or apply an infrastructure access control list.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Page 1 of 7Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.