Blog
MikroTrick (CVE-2026-86060, CVSS 9.8): Passwordless Takeover of 122,500 MikroTik Routers — Patch Before Attackers Find Yours
The MikroTrick exploit chain silently grants full RouterOS admin access without credentials. 122,500 devices exposed. CISA KEV-listed. Patch RouterOS 7.24.2 now.
Read More →CVE-2026-93643 (CVSS 9.8): Zimbra OnlyOffice Zero-Day Drops a PoC — Unauthenticated RCE Puts Your Corporate Email at Risk
A CVSS 9.8 zero-day (CVE-2026-93643) in Zimbra's OnlyOffice integration enables unauthenticated RCE. A PoC is already live. Patch to ZCS 10.1.21 immediately.
Read More →CVE-2026-85102 & CVE-2026-93616 (CVSS 9.8): Check Point VPN Zero-Days Under Active Attack — CISA Deadline Is Today
Two CVSS 9.8 zero-days (CVE-2026-85102, CVE-2026-93616) in Check Point Security Gateway and Management Server are being actively exploited. CISA deadline is today. Here is what to patch and how.
Read More →CVE-2026-76461 (CVSS 9.8): Cisco Secure Email Gateway Zero-Day Lets Attackers Execute Root Commands via a Single Email
CISA-confirmed zero-day CVE-2026-76461 (CVSS 9.8) in Cisco Secure Email Gateway allows unauthenticated attackers to execute root OS commands by sending one crafted email. All on-premises AsyncOS builds through 16.5 are…
Read More →CVE-2026-87902 (CVSS 9.2): WordPress Core Zero-Day Exploited Within Hours — Hundreds of Millions of Sites Face Unauthenticated RCE
CVE-2026-87902 (CVSS 9.2) is a critical WordPress Core zero-day enabling unauthenticated RCE. Exploitation began within hours of the September 22 patch. Update to WordPress 7.1.2 immediately.
Read More →CVE-2026-7273 (CVSS 8.8): Chinese Hackers Exploit Zyxel GS1900 Switches — 996 Devices Compromised, CISA Deadline Is Today
CVE-2026-7273 (CVSS 8.8) lets unauthenticated LAN attackers execute OS commands on Zyxel GS1900 switches. 996 devices hit, CISA deadline September 24. Patch now.
Read More →CVE-2026-94127 (CVSS 9.8): F5 BIG-IP APM OAuth Zero-Day Actively Exploited — Patch Before CISA’s September 25 Federal Deadline
F5 BIG-IP APM CVE-2026-94127 is a CVSS 9.8 heap overflow actively exploited as a zero-day. CISA added it to KEV on 22 September 2026 — U.S. federal patch deadline is…
Read More →CVE-2026-5430 (CVSS 9.8): WSO2 API Manager JWT Bypass Lets Attackers Forge Admin Tokens — Banks, Telcos and Governments Under Active Fire
CVE-2026-5430 (CVSS 9.8) in WSO2 API Manager allows attackers to forge JWT tokens and gain full admin access with no credentials. Active exploitation confirmed September 13, 2026. Patch now.
Read More →CVE-2026-93952 (CVSS 10.0): Arista VeloCloud Orchestrator Zero-Day Lets Attackers Seize Control of Your Entire SD-WAN Fabric — Patch Incomplete for Two Release Trains
CVE-2026-93952, a CVSS 10.0 flaw in Arista VeloCloud Orchestrator, lets unauthenticated attackers seize control of every Edge in your SD-WAN. Patches are missing for 6.1.x and 7.0.x.
Read More →CVE-2026-76460 (CVSS 10.0): Cisco ISE Authentication Bypass Gives Attackers Root Access — Your Zero-Trust Backbone Is Under Attack
CVE-2026-76460 is a CVSS 10.0 authentication bypass in Cisco ISE actively exploited since 16 September 2026. No workaround exists — patch now or risk your zero-trust policy engine falling to…
Read More →