CVE Vulnerability Alerts

CVE Vulnerability Alerts
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
Attackers exploited two Citrix NetScaler zero-days to plant custom WHIPSHOT and SLAPSHOT malware, hitting government, financial, and legal-sector networks.
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Check Point Zero-Day Exploited in July, Patched September 22
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
CVE Vulnerability Alerts
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.