Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers h… Continue reading Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)→

SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)

SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote unauthenticated attackers “to direct the appliance to issue requests on their … Continue reading SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)→

CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)

CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways. “Citrix has observed targeted attacks o… Continue reading CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)→

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)

Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to read emails and attachments of other users in the same organization, but &#8… Continue reading Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)→

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. “Used together, [the tw… Continue reading AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit→

New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)

For the fifth time this year, Cisco revealed attackers have exploited a vulnerability (CVE-2026-76504) in its SD-WAN solution in zero-day attacks. The vendor’s incident responders became aware of active exploitation of this vulnerability in Septe… Continue reading New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)→

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days,… Continue reading Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)→

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. OpenInfra Europe’s security incident… Continue reading OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised→

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become widespread “spray and pray” exploitation, fueled by the publicat… Continue reading NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)→