Skip to content
October 10, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Pitfalls of developing mobile banking application
  • Technique

Pitfalls of developing mobile banking application

Do Son April 23, 2021 3 minutes read

There is an active development of mobile technologies. The modern business requirements are such that access to information should be carried out quickly, reliably, and from anywhere in the world. Payment apps are no exception. And they are gradually appearing on our mobile devices (smartphones, tablets, etc.). Mobile devices have not yet been sufficiently studied. And each mobile OS (Android, iOS, Windows Phone, Symbian, BlackBerry, etc.) has its own specifics. So in each of them, you can find a large number of both new vulnerabilities and well-known ones. Experienced mobile banking app developers always take this into consideration.

Types of mobile banking apps

The “no account access” category includes programs that perform only auxiliary work. These functions may also be present in applications that have the ability to work with an account. Often a mobile application evolves from a simple navigation application to an account-based application. Some banks, on the contrary, prefer to distribute these functions to several applications. From the main point of view, it is correct. If a critical application is not overloaded with unnecessary functionality, the number of attack vectors available to an attacker decreases.

Main disadvantages

As you can see, there are plenty of advantages of mobile banking. But you shouldn’t give in to the illusion of impeccability. The fact is that there are many factors that limit the rapid growth of financial and mobile technologies. Today, many banks are actively developing this area of โ€‹โ€‹activity, but many problems remain open.

For example, the following problems of Mobile Banking can be highlighted:

  1. Organizational and legislative base. It is planned that during the formation of this structure, all those who take part in the mobile banking market will be centralized. These structures, according to the announced plans, will take over the function of exercising control over mobile payments, which include mobile banking;
  2. Low acceptance in the banking environment. Despite the improvement of mobile technologies, they are very skeptical about the mobile banking segment. Nevertheless, 80% of banks provide mobile banking services. But customers only get access to limited functionality. That is, most of the useful functions are unreasonably cut. However, recently, many banking organizations, realizing the prospects and need for a mobile bank, are gradually expanding the capabilities of their service systems;
  3. Technological backwardness. For example, only a few banks provide full-fledged mobile banking for iPhone, iPad and Android.
  4. Security guarantees. No matter what efforts are made by information security specialists, the “holes” both exist and will continue to exist. And the main problem is not in the protection systems. And the fact is that in most cases, threats arise through the fault of the clients themselves. It often does not realize the risks from its own actions. That is, users simply do not know how to use the mobile bank correctly. It is planned that in the future such problems will be eliminated through the development of systems. They are used for scanning the face of the owner of a mobile device, fingerprints, voice recognition, etc. All this will be, but it will take time and money. Since the use of such technologies is possible only on modern devices, which can also cost a lot of money.

Each mobile OS has its own specifics, and each of them contains a large number of both new and well-known vulnerabilities. And while developing a mobile banking application these details must be considered.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
๐Ÿ“ˆ

EPSS Spike Alerts
Catch risk spikes before they make headlines.

๐ŸŽฏ

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

๐Ÿ›ก๏ธ

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

๐Ÿ™

GitHub Issues
Auto-create alert tickets without duplication.

๐Ÿ“ฌ

Weekly Digest
Clean summaries, eliminating email spam.

๐Ÿท๏ธ

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

๐Ÿ”€

Smart Routing
Route chat channels based on severity levels.

๐Ÿšจ

RBP Tracker
Early warning detection and tracking system.

Subscribe โ€“ $7/mo or try free for 14 days โ†’

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-108551CVSS 9.3
    openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript...
    📅 Updated: Oct 10, 2026
  • CVE-2026-108549CVSS 9.2
    cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that...
    📅 Updated: Oct 10, 2026
  • CVE-2026-84272CVSS 9.8
    IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated...
    📅 Updated: Oct 10, 2026
  • CVE-2026-19491CVSS 9.1
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-78401CVSS 9.8
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-14991CVSS 9.8
    IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable...
    📅 Updated: Oct 10, 2026
  • CVE-2026-16916CVSS 9.1
    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a...
    📅 Updated: Oct 10, 2026
  • CVE-2026-93945CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through...
    📅 Updated: Oct 10, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Hereโ€™s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
ยฉ 2017 - 2026 Daily CyberSecurity. All Rights Reserved.