On September 26th, 2026, security researchers publicly warned of multiple unpatched remote code execution vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway, as organizations began taking the appliances offline on the advice of national authorities. On September 27th, Citrix confirmed active exploitation of CVE-2026-88771 & CVE-2026-88772, which enable unauthenticated Remote Code Execution (RCE) and impact the default configuration of Citrix Netscaler appliances.
Sep 26, 2026 - 5 Min Read
On September 25th, 2026, Kiteworks notified customers that it has received credible threat intelligence from the U.S federal government, specifically the intelligence community indicating an attack on Kiteworks systems may be imminent this weekend.
Sep 25, 2026 - 2 Min Read
Unauthenticated attackers can forge a JSON Web Tokens that WSO2 API management accepts as valid, including administrators and the APIs they control.
Sep 24, 2026 - 3 Min Read
Drupal released fixes on September 23rd for 36 vulnerabilities across 16 contributed modules, five critical that can lead to remote code execution.
Sep 23, 2026 - 5 Min Read
A critical pre-authentication path traversal flaw in Check Point Management Servers lets remote attackers upload and run arbitrary scripts on the system that administers enterprise firewall policy, and attackers have been exploiting it since July
Sep 22, 2026 - 5 Min Read
On September 22nd, 2026, F5 published an advisory for a critical vulnerability in BIG-IP Access Policy Manager (APM) and confirmed active exploitation in the wild. Tracked as CVE-2026-94127, the flaw lets an unauthenticated, remote attacker send crafted traffic to an affected virtual server and execute code on the appliance.
Sep 22, 2026 - 4 Min Read
A critical unauthenticated path traversal in WordPress Core lets a remote attacker force a site to include a local PHP file from outside its theme directories, which on common server configurations leads to remote code execution.
Sep 22, 2026 - 4 Min Read
On September 16th, 2026, Cisco disclosed a critical vulnerability in Identity Services Engine (ISE) and confirmed it is under active exploitation. Tracked as CVE-2026-76460, the flaw stems from insufficient authentication control on an API endpoint.
Sep 17, 2026 - 3 Min Read
Cisco released hardening updates for its email security appliances on September 14th, closing five sets of vulnerabilities that an unauthenticated, remote attacker can reach regardless of how the device is configured.
Sep 14, 2026 - 4 Min Read
On September 14th, 2026, Cisco disclosed a critical vulnerability in the email parsing logic of AsyncOS Software for Cisco Secure Email Gateway. Tracked as CVE-2026-76461, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day, confirming exploitation in the wild.
Sep 14, 2026 - 4 Min Read