Citrix NetScaler unauthenticated RCE vulnerability

Citrix NetScaler unauthenticated RCE vulnerability lets attackers run commands with no login. Two zero-days exploited, patch now, CISA deadline Sep 30.

Citrix confirmed on September 27 that a Citrix NetScaler unauthenticated RCE vulnerability, tracked as two separate CVEs, was already being exploited in the wild before any patch existed. CVE-2026-88771 lets an attacker with no credentials run arbitrary commands on any NetScaler ADC or Gateway appliance in a vulnerable version, default configuration included. Its sibling flaw,…

Read More

F5 BIG-IP APM RCE Vulnerability Exploited

F5 BIG-IP APM RCE vulnerability

F5 has confirmed active, unauthenticated exploitation of a critical F5 BIG-IP APM RCE vulnerability, tracked as CVE-2026-94127 (CVSS 9.8), affecting Access Policy Manager instances configured as OAuth Authorization Servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day F5 disclosed it, September 22, and gave federal agencies until Friday, September 25…

Read More

Cisco Secure Email Gateway Vulnerability: Patch Now

A critical Cisco Secure Email Gateway vulnerability lets one crafted email grant root access, no login needed. Active exploitation confirmed.

A critical Cisco Secure Email Gateway vulnerability, CVE-2026-76461 (CVSS 9.8), lets an attacker gain root access to the appliance by sending a single crafted email, no login or admin access required. Cisco confirmed active exploitation and published its advisory September 14; CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and…

Read More

Check Point VPN Certificate Vulnerability: Patch Now

A Check Point VPN certificate vulnerability pair (CVSS 9.8) allows pre-auth RCE. Dutch NCSC warns exploitation is imminent; patch today.

Check Point disclosed a Check Point VPN certificate vulnerability pair, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, on September 9, and the Dutch National Cyber Security Centre has since warned that large-scale exploitation is likely imminent, even though Check Point itself has not yet observed attacks in the wild. Both flaws allow unauthenticated remote code execution…

Read More

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

SAP Kernel RCE Vulnerability Hits 10,000+ Systems

A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…

Read More