Vulnerabilities & Patches
WatchGuard Firebox Ransomware Exploitation
WatchGuard Firebox ransomware exploitation is now officially confirmed. CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2025-14733 on September 10, 2026, to reflect that ransomware gangs, not just opportunistic access brokers, are actively weaponizing a firewall flaw that has had a public patch available since December 2025. What Happened CVE-2025-14733 is an out-of-bounds write…
Read MoreCisco ISE Authentication Bypass Vulnerability Hits Root
A Cisco ISE authentication bypass vulnerability tracked as CVE-2026-76460 carries a perfect CVSS score of 10.0 and is already under active exploitation. An unauthenticated attacker can bypass Cisco Identity Services Engine’s web-based management interface entirely and, per Cisco’s own advisory, reach command execution as root. That is the one system in your network built to…
Read MoreGitLab Path Traversal Vulnerability: Patch Now
A critical GitLab path traversal vulnerability, CVE-2026-85706 (CVSS 10.0), lets an unauthenticated attacker read any file off a self-managed GitLab server, including credentials, deploy keys, and CI/CD configuration. GitLab shipped a patch on September 10; CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, and BSI issued its own warning on…
Read MoreLiteLLM MCP Authentication Bypass: Patch Now
A LiteLLM MCP authentication bypass, CVE-2026-59822 (CVSS 8.8), lets an attacker skip OAuth2 login entirely when connecting to Model Context Protocol servers through LiteLLM’s proxy, gaining whatever access an authenticated session would carry. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 2, the first MCP-related vulnerability ever listed there; WatchTowr reports…
Read MoreCisco Secure Email Gateway Vulnerability: Patch Now
A critical Cisco Secure Email Gateway vulnerability, CVE-2026-76461 (CVSS 9.8), lets an attacker gain root access to the appliance by sending a single crafted email, no login or admin access required. Cisco confirmed active exploitation and published its advisory September 14; CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and…
Read More
