Blog
CVE-2026-20079 (CVSS 10.0) + CVE-2026-20316: Cisco Secure FMC Actively Exploited by Sandworm and Qilin Ransomware — Patch Before September 12
Cisco Secure FMC CVE-2026-20079 (CVSS 10.0) is under active attack by Sandworm, Qilin ransomware, and credential thieves. CISA deadline: September 12, 2026.
Read More →CVE-2026-3869 (CVSS 9.2): Schneider Electric Modicon M580 Safety PLC Authentication Bypass — Every ICS Operator Needs a Zero-Trust Plan Today
Schneider Electric patches CVE-2026-3869 (CVSS 9.2) — a critical authentication-algorithm bypass in Modicon M580 and M580 Safety PLCs. With patch windows months away for safety controllers, zero-trust OT segmentation is…
Read More →CVE-2026-75650 (CVSS 10.0): StyleSmuggler Zero-Day Backdoors Adobe Commerce and Magento Stores — Patch Immediately
CVE-2026-75650 (CVSS 10.0) is a zero-day RCE in Magento and Adobe Commerce. Attackers deployed Rust backdoors for 3 days before the patch. Act now.
Read More →Microsoft September 2026 Patch Tuesday: 966 CVEs Fixed and Two Windows Zero-Days Actively Exploited — Patch Today
Microsoft's record September 2026 Patch Tuesday fixes 966 vulnerabilities including two actively exploited Windows zero-days — CVE-2026-81963 and CVE-2026-85880. Patch now.
Read More →CVE-2026-86218 (CVSS 10.0): N-able N-central Gets Its Fourth Emergency Patch in Five Weeks — Every MSP Client Is at Risk
N-able issues its fourth N-central hotfix in five weeks for CVE-2026-86218, a CVSS 10.0 unauthenticated RCE flaw. On-premises deployments require immediate manual patching now.
Read More →BigBear 2.0: The MFA-Bypassing PhaaS Platform That Hit 258 Microsoft 365 Organizations — India Is Ground Zero
CloudSEK researchers have exposed BigBear 2.0, a commercial phishing-as-a-service platform that hijacked Microsoft 365 accounts at 258 organizations across 40+ countries by defeating multi-factor authentication — with India recording the…
Read More →Seven Security Flaws in OpenVPN 2.7.7: Windows RCE, Binary Hijack, and Buffer Overflows — Patch Your VPN Server Now
OpenVPN 2.7.7 patches 7 CVEs including CVE-2026-84256 (Windows RCE via certificate injection), CVE-2026-84226 (tapctl binary planting), and cross-platform buffer overflows. Patch your VPN now.
Read More →CVE-2026-82078 (CVSS 9.4): PaperCut’s Emergency Patch Was Bypassed — Pre-Auth RCE Chain Is Being Exploited in the Wild
PaperCut NG/MF's first emergency patch was bypassed within 48 hours. CVE-2026-82078 (CVSS 9.4) chains with CVE-2026-81578 for pre-auth RCE. Patch to Release 3 now.
Read More →CVE-2026-67276 (CVSS 9.2): The “MikroTrick” SSH Auth Bypass Is Hijacking MikroTik Routers Without a Password — Patch RouterOS Now
CVE-2026-67276 and the MikroTrick exploit chain are hijacking MikroTik RouterOS devices via unauthenticated SSH. Patch to 7.24.2 or 6.49.21 immediately.
Read More →CVE-2026-60004 (CVSS 9.8): Gitea RCE Actively Exploited — Patch Your Self-Hosted Git Server Before Your Software Supply Chain Is Compromised
CVE-2026-60004 (CVSS 9.8): Gitea RCE exploited via diffpatch. Attackers plant Git hooks and run OS commands on your git server. CISA KEV confirmed. Patch to 1.27.1 now.
Read More →