Posts Tagged ‘CISA KEV’
VMware vCenter CVE-2026-59310: Germany Hit Hardest
VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…
Read MoreTop 5 Cybersecurity News Stories August 14, 2026
This week’s Cybersecurity News Stories August 14, 2026 arrives during a week when defenders discovered something uncomfortable: the tools and infrastructure they depend on to manage, monitor, and protect their environments were themselves the target. A nation-state rootkit disabled Windows security callbacks at the kernel level. A heating plant lost control of its steam turbine…
Read MoreTeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover
TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…
Read MoreN-central CVE-2026-18577 Auth Bypass — CISA 3-Day Deadline
N-central CVE-2026-18577 auth bypass is being actively exploited to seize administrative control of N-able N-central servers — a remote monitoring and management (RMM) platform managed service providers (MSPs) use to run client networks. CISA gave federal civilian agencies just three days to patch, with the deadline landing August 6, 2026. What Happened N-able disclosed that…
Read MoreCisco Secure FMC CVE-2026-20316 Exploited
Cisco Secure FMC CVE-2026-20316 is under confirmed active exploitation: a hardcoded, low-privilege account built into every on-premises Secure Firewall Management Center gives an unauthenticated attacker a foothold — and in the same advisory cycle, Cisco quietly reactivated a five-month-old, maximum-severity root-level bypass in the same product, sharing an identical indicator of compromise. CISA added the…
Read More
