Cyber News
Read latestCN

Cyber News

Know what happened in cybersecurity today. Source-driven intelligence, AI-assisted reporting, editorially reviewed.

Sections

Latest newsCVE trackerThreat actorsMalware

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber News.

CVE Tracker

Indexed vulnerabilities with severity, CVSS, and vendor context.

View CVE news
F5·about 2 hours agocriticalCVSS 9.8

CVE-2026-94127

Apply the engineering hotfixes released by F5 for CVE-2026-94127 immediately. Administrators should verify their BIG-IP APM configuration to determine if APM is functioning as an OAuth authorization server. If APM is not issuing access tokens to applications, the system is not affected by this vulnerability. Monitor F5 security advisories for further updates or full advisory releases.

Zyxel·about 2 hours agohigh

CVE-2026-7273

Organizations should check Zyxel security advisories for firmware updates addressing CVE-2026-7273. Prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. Apply defense-in-depth measures such as network segmentation and monitoring for anomalous switch behavior.

Automattic·about 2 hours agocriticalCVSS 9.8

CVE-2026-87902

Apply the latest WordPress security updates immediately. Implement web application firewall rules to block suspicious file uploads and path traversal patterns. Monitor server logs for unauthorized file creation or execution. Restrict file permissions and disable unused PHP functions.

Microsoft·about 2 hours agocriticalCVSS 10

CVE-2026-85889

Microsoft has released fixes that are applied automatically; no customer action is required. Organizations should verify that their Azure AI Foundry instances are updated and review Microsoft's security advisories for any additional guidance. It is also recommended to monitor for unusual activity and enforce least-privilege access controls.

Eufy·about 2 hours agocriticalCVSS 9.3

CVE-2026-93290

Eufy recommends upgrading firmware to version 1.6.4 or later. CISA advises minimizing network exposure for devices, ensuring they are not internet-accessible, placing them behind firewalls segregated from business networks, and using updated VPNs for remote access.

Siemens·about 2 hours agohighCVSS 8.2

CVE-2026-34223

Evaluate authorization policy for the Graphics application following the Least Privilege principle, ensuring only required users have access. Minimize network exposure for control system devices; ensure systems are not internet-facing. Locate control system networks behind firewalls and isolate from business networks. Use secure remote access methods such as VPNs, keeping them updated. Follow Siemens operational guidelines for industrial security. Monitor Siemens advisory SSA-330084 for updates on remediation.

Check Point·about 2 hours agocritical

CVE-2026-85102

Organizations using Check Point VPN should monitor official Check Point advisories and apply security updates as released. Until patches are available, implement network segmentation and review VPN access controls to reduce attack surface.

Arista Networks·about 2 hours agocriticalCVSS 10

CVE-2026-93952

Apply the latest security patches released by Arista and VMware for VeloCloud Orchestrator immediately. If patching is not immediately possible, consider disabling certificate-based Edge authentication, noting this will impact Edge connectivity. Monitor Arista and VMware security advisories for further guidance.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-82566

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-85496

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

ABB·about 2 hours agohighCVSS 7.8

CVE-2026-31431

ABB recommends applying the fix in Edgenius version 3.2.4.1 at the earliest convenience. Additional mitigations include limiting access to SSH or cockpit interfaces and noting that by default, no additional lower-privilege users are present on Edgenius installations. Refer to ABB PSIRT security advisory 7PAA024620 for further guidance.

Ubuntu·about 2 hours agohighCVSS 7.8

CVE-2026-80521

Apply upstream kernel patch released August 6, 2026. Until Ubuntu releases a patched kernel for affected LTS versions, administrators should restrict container privileges, monitor official Ubuntu security advisories, and consider kernel recompilation from source if feasible. Limit AF_UNIX socket access within containers where possible.

Eufy·about 2 hours agocriticalCVSS 9.3

CVE-2026-93289

Eufy recommends upgrading firmware to version 1.6.4 or later. CISA advises minimizing network exposure for devices, ensuring they are not internet-accessible, placing them behind firewalls segregated from business networks, and using updated VPNs for remote access.

Eufy·about 2 hours agocriticalCVSS 9.3

CVE-2026-93291

Eufy recommends upgrading firmware to version 1.6.4 or later. CISA advises minimizing network exposure for devices, ensuring they are not internet-accessible, placing them behind firewalls segregated from business networks, and using updated VPNs for remote access.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-84399

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-77967

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-82716

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-81630

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-88761

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-84403

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-75558

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-87118

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

WSO2·about 2 hours agocriticalCVSS 9.8

CVE-2026-5430

Apply the latest security patches provided by WSO2. Review and follow WSO2's JWT configuration guidelines to ensure proper signature verification. Monitor official WSO2 security advisories for updates and additional mitigation steps.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-79959

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-82708

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-82585

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Botslab·about 2 hours agohighCVSS 8.8

CVE-2026-88956

Botslab has not responded to requests to work with CISA to mitigate these vulnerabilities. No official patch has been publicly confirmed. Users of affected firmware versions are advised to reach out to Botslab via the official website (https://www.botslab.com/pages/about-botslab) for guidance. Organizations should monitor for firmware updates, segment affected devices on networks where possible, and review access controls for dashcam deployments.

Siemens·about 2 hours agocriticalCVSS 9

CVE-2026-50093

Apply vendor-supplied patches to update affected Siveillance Control products to the minimum patched versions (V3.0.12.2173 or later for Pro V3.0, V4.0.9.2178 or later for Pro V4.0, V3.0.22.2177 or later for V3.0, V4.0.11.2177 or later for V4.0). Minimize network exposure by isolating OIS web module devices behind firewalls and ensuring they are not accessible from the internet. When remote access is required, use VPNs updated to the most recent version. Follow Siemens ProductCERT advisory SSA-254516 for additional guidance.

Siemens·about 2 hours agomediumCVSS 6.5

CVE-2026-89207

Update affected firmware to WTV676-HB6035 Web Interface V3.94 or later, or WTV776-HB6035 Web Interface V4.17 or later. Minimize network exposure by ensuring affected devices are not accessible from the internet. Locate control system networks behind firewalls and isolate from business networks. Use VPNs for remote access and keep VPNs and connected devices updated.

Roundcube·about 2 hours agocriticalCVSS 8.1

CVE-2026-48842

Users should upgrade Roundcube Webmail to version 1.6.16 or 1.7.1 immediately to apply the fix for CVE-2026-48842. If immediate upgrading is not possible, consider disabling the virtuser_query plugin or implementing network controls to limit exposure. Monitor for patches from Roundcube developers and apply them as soon as possible.

Oracle·about 2 hours agohigh

CVE-2026-35273

Apply Oracle PeopleSoft security patches for CVE-2026-35273. Update WAF rules to detect and block URL-encoding bypass patterns associated with the CVE-2026-35273 exploitation attempts. Monitor Oracle security advisories for further guidance.

Adobe·about 2 hours agohigh

CVE-2026-85880

CISA and BOD 26-04 require Federal Civilian Executive Branch agencies to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets. All organizations should apply available patches, adopt risk-based vulnerability management, and check for prior compromise before patching. Vulnerabilities can be nominated for addition to the KEV Catalog via CISA's KEV Nomination Form if they meet criteria of a CVE ID, evidence of exploitation, and clear mitigation guidance.

Unknown vendor·about 2 hours agoinfo

CVE-2026-7891

No patch or specific mitigation is required for this retracted vulnerability. Siemens recommends protecting network access to devices with appropriate mechanisms and following the company's operational guidelines for industrial security, available at https://www.siemens.com/cert/operational-guidelines-industrial-security and https://www.siemens.com/industrialsecurity.

Google·about 2 hours agohigh

CVE-2026-87491

Update Google Chrome to the latest version immediately. Enable automatic updates to receive security fixes promptly.

Google·about 2 hours agohigh

CVE-2026-85046

Users and administrators should update Google Chrome and Chromium-based browsers to the latest available version. CISA encourages organizations to apply security updates promptly and adopt risk-based vulnerability management practices. Federal agencies must follow BOD 26-04 requirements for prioritizing KEV Catalog remediation on publicly exposed assets.

Citrix·about 2 hours agocritical

CVE-2026-88773

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Autonomy Logic·about 2 hours agomediumCVSS 6.1

CVE-2026-88020

Autonomy Logic recommends upgrading to OpenPLC v4 as v3 is end-of-life. CISA recommends minimizing network exposure, placing control system devices behind firewalls, isolating from business networks, and using VPNs for remote access with current versions. No known public exploitation reported.

D-Link·about 2 hours agocritical

CVE-2026-86296

D-Link recommends replacing the DIR-822A routers with supported hardware due to the lack of a patch. Users should disconnect legacy devices from the network if replacement is not immediately possible. Monitor D-Link advisories for any future security updates.

MikroTik·about 2 hours agocriticalCVSS 9.8

CVE-2026-67279

MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.

Microsoft·about 2 hours agocriticalCVSS 8.8

CVE-2026-65660

Organizations should apply vendor patches from Microsoft and MikroTik as soon as possible. CISA KEV catalog entries typically require applicable updates to mitigate the vulnerabilities. Prioritize patching internet-facing SharePoint servers and MikroTik routers.

MikroTik·about 2 hours agocriticalCVSS 9.8

CVE-2026-86060

MikroTik has released RouterOS version 7.0.4 and later which patches both CVE-2026-67279 and CVE-2026-86060. Users should update to the latest stable RouterOS version immediately. If updating is not immediately possible, MikroTik recommends disabling SSH access from the WAN interface.

Linux Foundation / Kernel maintainers·about 2 hours agohighCVSS 7.5

CVE-2026-89775

Apply the latest Linux kernel patches that address the KVM ARM64 memory handling code. Disable nested virtualization if not required. Monitor vendor advisories and kernel security mailing lists for follow-up updates. Ensure systems are running kernel versions containing the fix for CVE-2026-89775.

Citrix·about 2 hours agocritical

CVE-2026-88774

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Apple·about 2 hours agohigh

CVE-2026-86950

Apple has released security updates addressing CVE-2026-86950. Users should update their devices to the latest available software versions. For iOS and iPadOS, go to Settings > General > Software Update. For macOS, use System Settings > General > Software Update. Organizations should ensure all managed devices are updated promptly. If immediate updating is not possible, exercise caution when opening files from untrusted sources, including email attachments, links, and downloads from the web.

Citrix·about 2 hours agocritical

CVE-2026-88776

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Citrix·about 2 hours agocritical

CVE-2026-88775

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Citrix·about 2 hours agocritical

CVE-2026-88772

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Citrix·about 2 hours agocritical

CVE-2026-88778

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Citrix·about 2 hours agocritical

CVE-2026-88777

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.

Citrix·about 2 hours agocritical

CVE-2026-88771

Organizations using Citrix NetScaler ADC or Gateway should review Citrix security bulletins for CVE-2026-88771 through CVE-2026-88778. Check for indicators of compromise via NetScaler Console prior to patching. Preserve forensic evidence before applying updates. Apply available patches or mitigations as released by Citrix. Monitor CISA and Citrix advisories for updates on the remaining six vulnerabilities.