NetScaler zero-days: check for compromise before you patch

Two zero-days, already exploited, patch available Citrix NetScaler appliances are under active attack through two critical vulnerabilities that were exploited in the wild before any patch existed. Citrix disclosed eight vulnerabilities on September 27 in bulletin CTX697096. The two headline flaws, CVE-2026-88771 and CVE-2026-88772, both score 9.5 on the CVSS v4 scale and both lead […]

CISA flags four actively exploited flaws in WSO2, Adobe Commerce, SharePoint and MikroTik

Four more flaws join the exploit catalog The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog this week, and all four carry evidence of attacks in the wild rather than a mere proof of concept. Two entries landed on September 24: a critical JWT authentication bypass in WSO2 […]

SourceHut build logs hid a wormable XSS that could take over accounts

A vulnerability researcher known as Arusekk published a writeup on September 23 describing CVE-2026-92973, a cross-site scripting flaw in the ansi2html library that let anyone who could inject text into a SourceHut build log take over the accounts of people who viewed it. The bug had been sitting in the wild for close to four […]

Cisco firewall manager flaws pulled three hacking groups into the same appliances

Cisco Talos published research this week on three separate hacking groups that broke into customers through two flaws in Cisco Secure Firewall Management Center, the central management server for Cisco firewalls. One group dropped ransomware. Another is tied to Sandworm, the hacking unit linked to Russian military intelligence. The third stole credentials through a web […]

MikroTrick: pre-auth MikroTik takeover chain under active attack

If you run a MikroTik router with SSH exposed to the internet, patch it now, then check it for compromise. CERT Polska disclosed six RouterOS vulnerabilities on September 5, and two of them chain into what the agency calls MikroTrick: an unauthenticated, full administrative takeover of any device whose SSH service is reachable from public […]

Chrome’s sixth zero-day of 2026: CVE-2026-85046 exploited in the wild

Google shipped an emergency Chrome Stable update on September 3 and confirmed that one of the twelve bugs it patched is already being exploited in the wild. The flaw, CVE-2026-85046, is a type confusion vulnerability in V8 with a CVSS score of 8.8. It is the sixth actively exploited Chrome zero-day of 2026, and all […]

8,300 Gitea servers still exposed to actively exploited RCE flaw

More than 8,300 internet-exposed Gitea instances remain unpatched against a critical remote code execution flaw that attackers are actively exploiting, according to Shadowserver Foundation scans. The watchdog counted 8,393 vulnerable IP addresses on August 27, more than a month after a fix shipped. The bug, tracked as CVE-2026-60004, carries a CVSS score of 9.8 and […]

Avada WordPress Theme Zero-Click RCE Chains Six Flaws into Remote Takeover

A zero-click remote code execution chain affecting the Avada WordPress theme and its companion Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code on vulnerable hosts. Tracked collectively as CVE-2026-18431, the vulnerability carries a CVSS score of 9.8. Because Avada stands as one of the most widely sold commercial WordPress themes in history […]

Unpatched Flaw in Calix Fiber Gateways Lets Attackers Bypass NAT to Expose Internal Devices

Residential gateways and broadband routers form the first and often only line of defense protecting home and small office networks from direct Internet exposure. Security researchers have disclosed an unpatched vulnerability in widely deployed Calix GS7 XGS (GS5239XG) residential gateways that allows unauthenticated remote attackers on the public Internet to bypass Network Address Translation (NAT) […]

seL4 Microkernel Completes Full Formal Security Proofs on AArch64 Architecture

Formal verification represents the gold standard in software security, replacing probabilistic testing with mathematical proofs that code behaves exactly according to its formal specification. Proofcraft, in collaboration with the seL4 Foundation and supported by the UK National Cyber Security Centre (NCSC), has announced the completion of formal security proofs for the seL4 microkernel on the […]

ToxicPanda 2.0 Abuses Android VPN Permissions to Blindside Google Play Protect

The Evolution of a Targeted Banking Trojan Security researchers tracking mobile threats have documented a significant architectural update to ToxicPanda, an Android banking trojan that first surfaced in late 2024. The new variant, labeled ToxicPanda 2.0, has expanded its target list to 349 financial and banking applications across Europe, Latin America, and emerging markets. Beyond […]

Poisoned arrayref Rust Crate Shows Why Build-Time Execution Needs Guardrails

A Compromised Maintainer and Three Poisoned Crates Earlier this week, security researchers identified a coordinated supply-chain attack targeting the Rust package ecosystem. Attackers compromised the crates.io account of a maintainer responsible for arrayref, a widely used Rust library with tens of millions of downloads across cryptography, networking, and graphics packages. Once inside the account, the […]