N-able N-central RCE Vulnerability Hit Again

N-able N-central RCE Vulnerability Hit Again

An N-able N-central RCE vulnerability has forced the vendor to ship its fourth emergency hotfix in five weeks, and Huntress investigators say a customer’s server — already patched against an earlier round of flaws — was compromised a second time anyway. Tracked as CVE-2026-86218 with a maximum CVSS score of 10.0, the flaw hits a…

Read More

SonicWall SMA1000 RCE Vulnerability: Patch Now

SonicWall SMA1000 RCE vulnerability

A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…

Read More

Zimbra Command Injection Vulnerability Actively Exploited

A Zimbra command injection vulnerability is under active exploitation against on-premises mail servers; the CISA federal deadline already passed.

A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…

Read More

Windows IKE RCE: Patched in April, Exploited Now

CVE-2026-33824 Windows IKE RCE is now actively exploited despite an April patch. CVSS 9.8, no auth needed. See who's affected and what to check today.

CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…

Read More

Progress LoadMaster CVE-2026-8037: 792 Attacks Logged

Progress LoadMaster CVE-2026-8037 (CVSS 9.6) is on CISA's KEV list after 792 exploit attempts. Unauthenticated root RCE — patch now.

Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…

Read More