On September 1, 2026 SonicWall PSIRT disclosed two critical vulnerabilities affecting SMA1000 series appliances. Tracked as CVE-2026-83548 and CVE-2026-83549, SonicWall confirmed that the vulnerabilities are being actively exploited in the wild.
Sep 1, 2026 - 2 Min Read
On August 31st, CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation of the flaws in PaperCut NG and MF.
Aug 31, 2026 - 4 Min Read
On August 19th, Citrix published a security advisory detailing a critical authentication bypass vulnerability in their NetScaler ADC and NetScaler Gateway products. The vulnerability can be exploited remotely and without credentials, and given the typical deployment of these products, can provide threat actors initial access into targeted organizations’ networks.
Aug 19, 2026 - 3 Min Read
An unauthenticated, critical SQL injection flaw in Metabase’s password reset endpoint has been exploited in the wild to gain full administrator access to self-hosted and cloud instances.
Aug 11, 2026 - 4 Min Read
A new supply chain attack identified on multiple npm packages stemming from Keyv and Cacheable actively being exploited.
Aug 3, 2026 - 2 Min Read
N-able has confirmed active exploitation of an authentication bypass flaw in N-central that lets unauthenticated attackers take over administrator accounts and pivot into every managed endpoint beneath a compromised server.
Aug 3, 2026 - 4 Min Read
Check Point patched three vulnerabilities in its Security Management platform on July 22nd, 2026, (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145). CVE-2026-16232 was already exploited in the wild as to seize full administrative control of firewall management servers.
Jul 22, 2026 - 3 Min Read
A flaw can allow an unauthenticated attacker to establish unauthorized VPN sessions on vulnerable GlobalProtect deployments when certain configuration conditions are present, currently added to KEV and is being used by Qilin Ransomware affiliates.
Jul 21, 2026 - 4 Min Read
On July 17th, WordPress disclosed two separate vulnerabilities which when chained together, could enable a remote unauthenticated attacker to achieve Remote Code Execution on default installations of the WordPress “core” product.
Jul 17, 2026 - 3 Min Read
F5 has patched three memory-corruption vulnerabilities in NGINX Plus and NGINX Open Source, the most severe of which lets an unauthenticated attacker crash worker processes and, under the right conditions, execute code.
Jul 15, 2026 - 4 Min Read