CVE Vulnerability Alerts

Application Security
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass authentication controls.
CVE Vulnerability Alerts
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by ...
Application Security
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
Application Security
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.