Advisories

Critical Vulnerability in SAP Kernel (CVE-2026-44756)

On September 8th, 2026, SAP disclosed a critical vulnerability in the SAP kernel as part of its September Security Patch Day. Tracked as CVE-2026-44756, the vulnerability grants an unauthenticated attacker remote code execution on a target SAP host. SAP products are commonly deployed internet facing, and successful compromise provides threat actors initial access into an organization’s network.

Sep 10, 2026 - 3 Min Read

Critical Vulnerabilities in Cisco Secure Firewall Management Center Under Active Exploitation (CVE-2026-20079, CVE-2026-20316)

Two Cisco Secure Firewall Management Center flaws, an unauthenticated authentication bypass that grants root and a static credential for a built-in account, are being exploited together by state-sponsored and ransomware actors to take over firewall management consoles.

Sep 9, 2026 - 7 Min Read

Critical Vulnerabilities in Multiple Adobe Products Under Active Exploitation (CVE-2026-48273, CVE-2026-75746, CVE-2026-19232, CVE-2026-75650)

On September 8th, 2026, CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source. The flaw lets an unauthenticated, remote attacker inject and execute arbitrary code through Magento's template engine. Magento is an E-commerce platform, and a compromise could expose confidential client financial data. It could also provide threat actors initial access into an organization’s internal network. It was one of four critical vulnerabilities Adobe addressed across its September 2026 security update cycle involving multiple products.

Sep 9, 2026 - 4 Min Read

Critical Remote Code Execution Vulnerabilities in Check Point Quantum Security Gateway and Security Management (CVE-2026-85102, CVE-2026-85103)

On September 9th, 2026, Check Point released emergency security updates for two critical vulnerabilities in the VPN certificate handling of its Quantum product line. The vulnerabilities could allow an unauthenticated, remote attacker to compromise and execute code on affected Check Point systems.

Sep 9, 2026 - 4 Min Read

Critical Vulnerabilities in SonicWall SMA1000 Series Appliances Under Active Exploitation (CVE-2026-83548, CVE-2026-83549)

On September 1, 2026 SonicWall PSIRT disclosed two critical vulnerabilities affecting SMA1000 series appliances. Tracked as CVE-2026-83548 and CVE-2026-83549, SonicWall confirmed that the vulnerabilities are being actively exploited in the wild.

Sep 1, 2026 - 2 Min Read

Critical RCE Vulnerabilities in PaperCut NG/MF Under Active Exploitation (CVE-2026-82078, CVE-2026-81578)

On August 31st, CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities (KEV) catalog following confirmed exploitation of the flaws in PaperCut NG and MF.

Aug 31, 2026 - 4 Min Read

Critical Vulnerability in Citrix NetScaler ADC and Gateway (CVE-2026-19490)

On August 19th, Citrix published a security advisory detailing a critical authentication bypass vulnerability in their NetScaler ADC and NetScaler Gateway products. The vulnerability can be exploited remotely and without credentials, and given the typical deployment of these products, can provide threat actors initial access into targeted organizations’ networks.

Aug 19, 2026 - 3 Min Read

Metabase SQL Injection Actively Exploited in the Wild (CVE-2026-70468)

An unauthenticated, critical SQL injection flaw in Metabase’s password reset endpoint has been exploited in the wild to gain full administrator access to self-hosted and cloud instances.

Aug 11, 2026 - 4 Min Read

Keyv & Cacheable NPM Packages in Ongoing Supply Chain Attack

A new supply chain attack identified on multiple npm packages stemming from Keyv and Cacheable actively being exploited.

Aug 3, 2026 - 2 Min Read

N-central Authorization Bypass exploited in the wild (CVE-2026-18577)

N-able has confirmed active exploitation of an authentication bypass flaw in N-central that lets unauthenticated attackers take over administrator accounts and pivot into every managed endpoint beneath a compromised server.

Aug 3, 2026 - 4 Min Read