Blog
Seven Security Flaws in OpenVPN 2.7.7: Windows RCE, Binary Hijack, and Buffer Overflows — Patch Your VPN Server Now
OpenVPN 2.7.7 patches 7 CVEs including CVE-2026-84256 (Windows RCE via certificate injection), CVE-2026-84226 (tapctl binary planting), and cross-platform buffer overflows. Patch your VPN now.
Read More →CVE-2026-82078 (CVSS 9.4): PaperCut’s Emergency Patch Was Bypassed — Pre-Auth RCE Chain Is Being Exploited in the Wild
PaperCut NG/MF's first emergency patch was bypassed within 48 hours. CVE-2026-82078 (CVSS 9.4) chains with CVE-2026-81578 for pre-auth RCE. Patch to Release 3 now.
Read More →CVE-2026-67276 (CVSS 9.2): The “MikroTrick” SSH Auth Bypass Is Hijacking MikroTik Routers Without a Password — Patch RouterOS Now
CVE-2026-67276 and the MikroTrick exploit chain are hijacking MikroTik RouterOS devices via unauthenticated SSH. Patch to 7.24.2 or 6.49.21 immediately.
Read More →CVE-2026-60004 (CVSS 9.8): Gitea RCE Actively Exploited — Patch Your Self-Hosted Git Server Before Your Software Supply Chain Is Compromised
CVE-2026-60004 (CVSS 9.8): Gitea RCE exploited via diffpatch. Attackers plant Git hooks and run OS commands on your git server. CISA KEV confirmed. Patch to 1.27.1 now.
Read More →CVE-2026-85046 (CVSS 8.8): Google Chrome’s V8 Zero-Day Is Being Actively Exploited — Update All 3.45 Billion Users Immediately
CVE-2026-85046, a V8 type-confusion zero-day in Google Chrome, is actively exploited. CISA KEV deadline: 18 Sep 2026. Patch to Chrome 152.0.7977.82 now.
Read More →CVE-2026-19490 (CVSS 9.3): Citrix NetScaler Auth Bypass Now Under Active Attack — Patch Your Enterprise VPN Gateway Today
CVE-2026-19490 (CVSS 9.3) is a critical Citrix NetScaler authentication bypass now being actively exploited. Organisations running NetScaler as a Gateway or AAA server must patch to build 14.1-73.32 or 13.1-63.21…
Read More →CVE-2026-76657 & CVE-2026-76658 (CVSS 10.0): Twin Maximum-Severity HPE Fabric Composer Flaws Put Your Network Management Plane at Risk
Two CVSS 10.0 flaws in HPE Networking Fabric Composer let unauthenticated attackers gain full root control of your network management plane. CVE-2026-76657 bypasses API authentication; CVE-2026-76658 enables OS-level RCE via…
Read More →CVE-2026-20212 (CVSS 9.8): Critical Cisco Nexus 9000 Silicon One Flaw Opens AI Data Centre Backbone to Unauthenticated Root RCE
Cisco discloses CVE-2026-20212 (CVSS 9.8) in Nexus 9000 Silicon One switches: unauthenticated root RCE via TCP ports 43210/43211. 10 models, 45 NX-OS releases affected.
Read More →CISA Adds 7 Exploited CVEs: AI Gateways, VoIP Servers and Workflow Engines Under Active Attack — Your Action Plan
CISA added 7 flaws to KEV on Sept 2, 2026 — Kestra CVSS 10.0 auth bypass, LiteLLM MCP token bypass (Qilin ransomware chain), and Switchvox SQLi RCE. Patch now.
Read More →CVE-2026-83548 (CVSS 10.0) + CVE-2026-83549: SonicWall SMA 1000 Zero-Day Chain Enables Pre-Auth RCE — Patch Immediately
SonicWall confirms active exploitation of two SMA 1000 zero-days: CVSS 10.0 SSRF (CVE-2026-83548) chained with command injection (CVE-2026-83549) for pre-auth RCE on models 6210, 7210, 8200v.
Read More →