// THREAT ADVISORIES

THREAT ADVISORIES

Advisories, vulnerabilities and threat intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
2
Last 24h
18
Last 7 Days
18
Critical (7d)
All Critical High Medium Low
✕ Clear All
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]

Critical · Sep 23, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCheck Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]

Critical · Sep 22, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏥
VERISQ BRIEFlwIP TCP/IP Stack MQTT Client Application

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full code execution on the device. The following versions of lwIP TCP/IP Stack MQTT Client Application are affected: MQTT Client Application >=2.0.1|<=2.2.1 (CVE-2026-87121) CVSS Vendor Equipment Vulnerabilities v3 9.8 lwIP lwIP TCP/IP Stack MQTT Client Application Out-of-bounds Write Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Sweden Vulnerabilities Expand All + CVE-2026-87121 The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. View CVE Details Affected Products lwIP TCP/IP Stack MQTT Client Application Vendor: lwIP Product Version: lwIP MQTT Client Application: >=2.0.1|<=2.2.1 Product Status: known_affected Remediations Mitigation Users of lwIP are encouraged to update their version of lwIP using the repository found at https://savannah.nongnu.org/projects/lwip . The commit identifier that contains the fix is f89407ea711879c04d91c92b35d67be78bbaf0f1.   Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Versi...

🌐 nongnu.orgCVE-2026-87121
Critical · Sep 22, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏦
VERISQ BRIEFWeek in review: Cisco patches exploited email gateway 0-day, Revolut breach

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut. The bank confirmed the incident on Saturday, September 12. DeepZero: Open-source hunting for vulnerable Windows drivers DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You … More → The post Week in review: Cisco patches exploited email gateway 0-day, Revolut breach appeared first on Help Net Security .

Critical · Sep 20, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

Critical · Sep 19, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

Critical · Sep 19, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCisco Zero-Day Highlights API Endpoint Authentication Issues

The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.

Critical · Sep 18, 2026 · Dark Reading
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFPublic Exploits Released for Four Linux Kernel Flaws That Enable Local Root

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

Critical · Sep 18, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFNew Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

Critical · Sep 18, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔗
VERISQ BRIEFZero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said. “Anyone running a major coding agent that installs plugins from a marketplace is exposed. The exposure … More → The post Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched appeared first on Help Net Security .

Critical · Sep 18, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as […]

Critical · Sep 18, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔑
VERISQ BRIEFCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

Critical · Sep 17, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions

Critical · Sep 17, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]

Critical · Sep 17, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

Critical · Sep 17, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

Critical · Sep 17, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

Critical · Sep 16, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🎓
VERISQ BRIEFParallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts, JFrog vulnerability … More → The post Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) appeared first on Help Net Security .

Critical · Sep 16, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCritical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]

Critical · Sep 16, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFWindows 11 out-of-band update fixes audio glitch and other bugs – grab it now

The latest out-of-band update resolves a few problems in Windows 11, including one that cut off the sound for certain USB audio devices.

Critical · Sep 16, 2026 · ZDNet Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week; […]

Critical · Sep 15, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔗
VERISQ BRIEFHackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

Critical · Sep 15, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 📧
VERISQ BRIEFMultiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution

Multiple vulnerabilities have been discovered in Cisco Secure Email products, the most severe of which could allow for remote code execution. Cisco Secure Email Gateway (formerly ESA) is an email security appliance that filters spam, malware, and other threats at the mail gateway. Cisco Secure Email and Web Manager (formerly SMA) is a centralized management and reporting platform for Cisco Secure Email Gateway and Secure Web Appliance deployments.   Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution as root, which may lead to the complete compromise of the affected device.

Critical · Sep 15, 2026 · CIS Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

Cisco warns of a critical zero-day in Secure Email Gateway, exploited in the wild to gain root access through malicious emails. Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances. The flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL […]

Critical · Sep 15, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFShared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Critical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a critical flaw in LiteSpeed Enterprise can let a low‑privilege website user break out of their account and gain root on the whole server. On a box where dozens or hundreds of […]

Critical · Sep 15, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA: Critical VMware RCE flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]

Critical · Sep 15, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔑
VERISQ BRIEFWärtsilä FOS-Onboard

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 Wärtsilä Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Finland Vulnerabilities Expand All + CVE-2026-78225 A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. View CVE Details Affected Products Wärtsilä FOS-Onboard Vendor: Wärtsilä Product Version: Wärtsilä FOS-Onboard: 5.07.0923.01 Product Status: known_affected Remediations Mitigation Wärtsilä states that the vulnerabilities are not exploitable when the product is installed as recommended, and has developed a security patch. Users are also directed to contact Wärtsilä to obtain and install the patch. To obtain and install the latest patch, contact Wärtsilä:  https://www.wartsila.com/services-catalogue/engine-services-4-stroke/wartsila-ics-patch-deployment#contact Relevant CWE: CWE-321 Use...

Critical · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFmySCADA myPRO Manager

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected: mySCADA myPRO Manager <=2.1 (CVE-2026-73807, CVE-2026-82567) CVSS Vendor Equipment Vulnerabilities v3 9.8 mySCADA Technologies mySCADA myPRO Manager Missing Authorization, Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Czechia Vulnerabilities Expand All + CVE-2026-73807 The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. View CVE Details Affected Products mySCADA myPRO Manager Vendor: mySCADA Technologies Product Version: mySCADA Technologies mySCADA myPRO Manager: <=2.1 Product Status: known_affected Remediations Mitigation mySCADA Technologies has addressed these issues in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the ...

Critical · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFSiemens Reyrolle 7SR5

View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7SR5 are affected: Reyrolle 7SR5 vers:intdot/<2.70 (CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392, CVE-2026-62645, CVE-2026-62646, CVE-2026-62647, CVE-2026-62648, CVE-2026-62649, CVE-2026-62650, CVE-2026-62652, CVE-2026-62653, CVE-2026-62654) CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens Reyrolle 7SR5 Integer Overflow or Wraparound, Improper Neutralization of Delimiters, Use of Out-of-range Pointer Offset, Missing Authentication for Critical Function, Insufficient Entropy, Improper Input Validation, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Authentication Bypass Using an Alternate Path or Channel, Insertion of Sensitive Information Into Debugging Code, Download of Code Without Integrity Check Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2024-42384 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application. View CVE Details ...

Critical · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏥
VERISQ BRIEFDigital Watchdog VMAX DVR and NVR Product Lineups

View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX A1 PLUS vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VA1G4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VG4 Recorder vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) CVSS Vendor Equipment Vulnerabilities v3 9.6 Digital Watchdog Digital Watchdog VMAX DVR and NVR Product Lineups Missing Authentication for Critical Function, Use of Hard-coded Credentials, Missing Authorization, Predictable Seed in Pseudo-Random Number Generator (PRNG) Background Critical Infrastructure Sectors: Commercial Facilities, Government Services and Facilities, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide ...

Critical · Sep 15, 2026 · CISA Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFCisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

Critical · Sep 15, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFLiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

Critical · Sep 15, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 📧
VERISQ BRIEFCisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

Critical · Sep 15, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔗
VERISQ BRIEFMaximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

Critical · Sep 14, 2026 · Dark Reading
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]

Critical · Sep 14, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFDutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]

Critical · Sep 14, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.

Critical · Sep 14, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔗
VERISQ BRIEFSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode   GuardBreaker: Derailing AI-assisted malware analysis with a code comment   DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

Critical · Sep 13, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔗
VERISQ BRIEFHackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

Critical · Sep 13, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFGitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

Critical · Sep 13, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFDutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

Critical · Sep 12, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

Critical · Sep 11, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFArtifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

Critical · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFGitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]

Critical · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💀
VERISQ BRIEFCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

Critical · Sep 11, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEF[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Critical · Sep 11, 2026 · Exploit Database
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💀
VERISQ BRIEFCisco Firewall Bugs Let in Sandworm, Qilin

Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption.

Critical · Sep 10, 2026 · DataBreachToday
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure […]

Critical · Sep 10, 2026 · Security Affairs
Read Full Intelligence Brief →