Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway auto_post, september 30, 2026 CISA waarschuwt voor acht Citrix NetScaler-kwetsbaarheden, waarvan twee kritieke zero-days die remote code execution mogelijk maken en volgens CISA al wereldwijd worden misbruikt. De eerste prioriteit is het beperken van direct risico: controleer indicators of compromise en preserveer forensisch bewijs voordat patches worden toegepast, omdat updates zichtbaarheid kunnen wissen. Tegelijk… Continue Reading
Arista patches actively exploited VeloCloud Orchestrator zero-day auto_post, september 25, 2026 Arista heeft deze week een patch uitgebracht voor een actief misbruikte zero-day in VeloCloud Orchestrator (CVE-2026-93952). Direct patchen is de eerste stap, maar wie écht risico wil beperken moet daarnaast de VCO-webinterface afsluiten van openbare netwerken, toegang beperken tot beheernetwerken en logs nauwgezet onderzoeken. De kwetsbaarheid maakt misbruik mogelijk zonder… Continue Reading
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks auto_post, september 23, 2026 Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point Continue Reading
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups auto_post, september 23, 2026 Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are Continue Reading
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware auto_post, september 22, 2026september 25, 2026 Volgens berichten heeft de groep UTA0565 begin september 2026 een keten van zero-days in Google Chrome en Windows gebruikt via nepwebsites om malware (CLEANGULP) te installeren. Dit laat zien dat ons basisverhaal — dat een browserlek op zichzelf beperkt blijft — niet altijd opgaat: wanneer meerdere kwetsbaarheden worden gecombineerd, kunnen… Continue Reading
Cisco Zero-Day Highlights API Endpoint Authentication Issues auto_post, september 21, 2026september 23, 2026 The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. Continue Reading
Critical Citrix NetScaler auth bypass now leveraged in attacks post, september 4, 2026september 9, 2026 Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA… Continue Reading
Actively Exploited Oracle WebLogic Vulnerability Exposes Critical Enterprise Data post, augustus 25, 2026augustus 26, 2026 A maximum-severity vulnerability affecting Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in is being actively exploited, prompting an urgent warning from the US Cybersecurity and Infrastructure Security Agency and a compressed remediation deadline for federal agencies. The vulnerability, tracked as CVE-2026-21962, carries a CVSS severity score of 10.0,… Continue Reading
Microsoft Confirms Maximum-Severity Entra ID Vulnerability Exploited In Attacks post, augustus 21, 2026augustus 24, 2026 Microsoft has disclosed a maximum-severity security vulnerability in Microsoft Entra ID that was exploited in real-world attacks before the company completed a cloud-side fix, raising significant questions about the exposure of one of the most consequential identity platforms used by businesses, governments, and public-sector organizations worldwide. The vulnerability, tracked as… Continue Reading
Hackers Move Quickly To Exploit Critical Microsoft SharePoint Authentication Bypass post, augustus 13, 2026augustus 17, 2026 Threat actors have begun targeting internet-facing Microsoft SharePoint servers with exploit code for a critical authentication-bypass vulnerability less than 24 hours after detailed technical research and a public proof of concept were released. The vulnerability, tracked as CVE-2026-55040, affects supported on-premises editions of Microsoft SharePoint Server and carries a critical… Continue Reading