Attackers exploit Citrix NetScaler CVE-2026-88771 to deploy web shells and attempt theft of configuration data.
CISA says attackers are actively exploiting two Citrix NetScaler flaws globally; Citrix has released fixed versions.
Threat Intelligence has identified active exploitation of CVE-2026-73570, a serious unauthenticated command-injection ...
Hackers exploit Zimbra flaw CVE-2026-73570 to remotely execute commands on vulnerable mail servers without authentication.
Lasso Security and GBHackers reported in September 2026 that CVE-2026-77521 can let prompt injection trigger operating-system ...
Fortra has patched critical BoKS flaws that could lead to authentication bypass, shell command execution, and memory ...
WatchGuard has disclosed three vulnerabilities in its wireless access point platform, including two critical flaws that could ...
Multiple newly disclosed vulnerabilities in OWASP ModSecurity could let attackers bypass web application firewall protections ...
New Nozomi research identifies 19 vulnerabilities in Pepperl+Fuchs IO-Link Master enabling root access and OT attacks.
Exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra, started shortly after patches rolled out.
“An attacker can send a specially crafted SMTP request that introduces untrusted input into SNMP notification processing,” Microsoft explained. “If the input is not sufficiently sanitized, embedded ...