Researchers published 2,652 new CVEs between September 28 and October 4, 2026. This weekly CVE report, built...
zero-day
TL;DR Citrix admins report NetScaler appliances rebooting repeatedly even after updating to build 14.1-73.37. Citrix now says...
Since at least early September 2026, attackers have taken root-level control of Citrix NetScaler appliances without a...
On August 31, 2026, attackers broke into a school’s print server and ended up owning its entire...
TL;DR On September 29, 2026, Apple issued emergency updates to remediate an actively exploited Apple zero-day vulnerability....
Kiteworks urgently instructed its entire clientele to temporarily disconnect their secure file transfer servers. This followed a...
TL;DR Threat actors are actively attacking on-premises servers by exploiting a critical SharePoint RCE vulnerability tracked as...
TL;DR F5 Networks patched a critical zero-day flaw in its BIG-IP Access Policy Manager (APM). The vendor...
TL;DR On September 24, 2026, CISA updated its Known Exploited Vulnerabilities catalog with two high-risk security flaws....
TL;DR On May 24, 2026, Roundcube developers released important security updates to fix a critical SQL injection...
TL;DR On September 22, 2026, WordPress addressed a critical security flaw tracked as CVE-2026-87902. Security researchers confirmed...
TL;DR Security teams observed active attacks against an unpatched flaw in enterprise gateways. This critical Check Point...
TL;DR On September 22, 2026, Arista Networks warned of active attacks against a critical VeloCloud vulnerability. Tracked...
Honoring a promise made this March, Google has formally announced a more intensive update cadence for its...
TL;DR Google released Chrome 153 to fix 230 security flaws. One is a Chrome zero-day, CVE-2026-87491, already...
TL;DR Microsoft’s September 2026 Patch Tuesday fixes 996 vulnerabilities. Two of them are zero-days already exploited in...
N-able shipped an emergency hotfix for a maximum-severity flaw in its N-central platform on September 6, 2026....
The infamous NightmareEclipse public vulnerability series recently expanded its scope significantly. It rapidly transcended its initial Windows...
TL;DR A PaperCut vulnerability is under active attack. The zero-day is an exploit chain, tracked as CVE-2026-81578...
A protective security product can inadvertently transform into a highly vulnerable intrusion point. An independent security researcher...
TL;DR PaperCut confirmed a NG/MF vulnerability exploited in the wild on 27 August 2026. The flaw affects...
Update 3: Piotr Karwasz, a member of the Apache Software Foundation, stated that this alert re-covers an...