Advisories

Critical Vulnerabilities in SonicWall SMA1000 Series Appliances Under Active Exploitation (CVE-2026-83548, CVE-2026-83549)

On September 1, 2026 SonicWall PSIRT disclosed two critical vulnerabilities affecting SMA1000 series appliances. Tracked as CVE-2026-83548 and CVE-2026-83549, SonicWall confirmed that the vulnerabilities are being actively exploited in the wild.

Sep 1, 2026 - 2 Min Read

Critical RCE Vulnerabilities in PaperCut NG/MF Under Active Exploitation (CVE-2026-82078, CVE-2026-81578)

On August 31st, CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation of the flaws in PaperCut NG and MF.

Aug 31, 2026 - 4 Min Read

Critical Vulnerability in Citrix NetScaler ADC and Gateway (CVE-2026-19490)

On August 19th, Citrix published a security advisory detailing a critical authentication bypass vulnerability in their NetScaler ADC and NetScaler Gateway products. The vulnerability can be exploited remotely and without credentials, and given the typical deployment of these products, can provide threat actors initial access into targeted organizations’ networks.

Aug 19, 2026 - 3 Min Read

Metabase SQL Injection Actively Exploited in the Wild (CVE-2026-70468)

An unauthenticated, critical SQL injection flaw in Metabase’s password reset endpoint has been exploited in the wild to gain full administrator access to self-hosted and cloud instances.

Aug 11, 2026 - 4 Min Read

Keyv & Cacheable NPM Packages in Ongoing Supply Chain Attack

A new supply chain attack identified on multiple npm packages stemming from Keyv and Cacheable actively being exploited.

Aug 3, 2026 - 2 Min Read

N-central Authorization Bypass exploited in the wild (CVE-2026-18577)

N-able has confirmed active exploitation of an authentication bypass flaw in N-central that lets unauthenticated attackers take over administrator accounts and pivot into every managed endpoint beneath a compromised server.

Aug 3, 2026 - 4 Min Read

Critical Check Point Security Management Vulnerabilities Under Active Exploitation (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145)

Check Point patched three vulnerabilities in its Security Management platform on July 22nd, 2026, (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145). CVE-2026-16232 was already exploited in the wild as to seize full administrative control of firewall management servers.

Jul 22, 2026 - 3 Min Read

Critical Vulnerability in Palo Alto Global Protect Under Active Exploitation (CVE-2026-0257)

A flaw can allow an unauthenticated attacker to establish unauthorized VPN sessions on vulnerable GlobalProtect deployments when certain configuration conditions are present, currently added to KEV and is being used by Qilin Ransomware affiliates.

Jul 21, 2026 - 4 Min Read

"WP2Shell" Critical WordPress RCE Chain (CVE-2026-63030 & CVE-2026-60137)

On July 17th, WordPress disclosed two separate vulnerabilities which when chained together, could enable a remote unauthenticated attacker to achieve Remote Code Execution on default installations of the WordPress “core” product.

Jul 17, 2026 - 3 Min Read

Critical Memory Corruption Vulnerabilities in NGINX (CVE-2026-42533, CVE-2026-56434, CVE-2026-60005)

F5 has patched three memory-corruption vulnerabilities in NGINX Plus and NGINX Open Source, the most severe of which lets an unauthenticated attacker crash worker processes and, under the right conditions, execute code.

Jul 15, 2026 - 4 Min Read