Cyber.TechVoid
Read latestCT
HomeLibraryCVEThreatsMalwareResearch

Following

Find topics and threat categories to follow

LatestBreakingVulnerabilitiesThreatsBreachesMalwareCVEResearch
See suggestions
Latest newsCVE trackerRSSllms.txt© 2026

Cyber.TechVoid

Know what happened in cybersecurity today. Source-driven cybersecurity coverage with attribution. Content may be AI-assisted from external feeds and advisories.

Sections

Latest cybersecurity newsData breach newsVulnerability updatesCVE trackerThreat intelligenceMalware watch

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber.TechVoid. Accuracy over SEO.

  • Latest
  • Breaking
  • Vulnerabilities
  • Threats
  • Breaches
  • Malware
  • CVE
  • Research
CCISA AdvisoriesinCVE·Oct 7high

Critical Remote Code Execution Vulnerability in Hitachi Energy SOI

Hitachi Energy has disclosed a high-severity Remote Code Execution vulnerability in the Apache ActiveMQ component of its SOI product. The flaw, tracked as CVE-2026-34197, stems from improper control of code generation in the Jolokia JMX-HTTP bridge. An authenticated attacker can exploit the default access policy to execute arbitrary code on the broker's JVM, potentially compromising confidentiality, integrity, and availability. The vulnerability affects SOI versions 2.0.0 through 2.2.0 and has been assigned a CVSS v3 base score of 8.8 (HIGH).

12m
CCISA AdvisoriesinCVE·Oct 7critical

Six Vulnerabilities Discovered in Hitachi Energy RTU500 End-of-Life Firmware

Hitachi Energy has published a cybersecurity advisory addressing six vulnerabilities in its RTU500 series CMU firmware versions 11.x and prior, identified by Dragos and tracked by CISA. The flaws range from authentication bypass and relative path traversal to improper authorization, with CVSS scores of 9.1. End-of-life versions are no longer maintained, and Hitachi Energy recommends upgrading to currently supported firmware versions 12.7.8 or 13.9.1 or later.

12m
BBleepingComputerinCVE·Oct 7critical

Atlassian Issues Critical Advisory for Arbitrary File-Access Vulnerability in Data Center Products

Atlassian has identified a critical vulnerability, tracked as CVE-2026-21589, that could allow arbitrary file-access on self-hosted Data Center instances of Confluence, Jira, and Bitbucket. The flaw was disclosed on October 6, 2026, and affected organizations are urged to apply the latest security updates immediately.

11m
BBleepingComputerinCVE·Oct 6high

Active scanning detected for critical Rejetto HFS vulnerability

Security researchers and threat actors are actively scanning the internet for Rejetto HTTP File Server (HFS) instances exposed to the internet. The activity targets a critical vulnerability, tracked as CVE-2026-61500, which stems from a weak signing key. Successful exploitation could allow session forgery, account takeover, and remote code execution. No official patch has been confirmed in the reporting, and the CVE assignment is noted to fall outside typical assignment windows, requiring independent verification.

21m
BBleepingComputerinCVE·Oct 5high

Citrix Patches Actively Exploited NetScaler SAML Zero-Day

Citrix has released emergency security updates to address CVE-2026-88779, a denial-of-service vulnerability in NetScaler SAML functionality that has been exploited in zero-day attacks. The company confirms active exploitation in the wild, while researchers investigate whether the flaw can be leveraged for remote code execution beyond the initial denial-of-service impact.

21m
BBleepingComputerinCVE·Oct 3high

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab has identified a critical remote code execution vulnerability in its AI Gateway service. The flaw requires immediate patching to prevent potential arbitrary command execution on vulnerable instances. Details of active exploitation are currently unreported, but the vendor has urged customers to update to the latest patched version without delay.

21m
TThe Hacker NewsinCVE·Oct 3high

GitLab Patches Critical AI Gateway Vulnerability Allowing Command Execution

GitLab has released patches to address a critical vulnerability in its AI Gateway component, tracked as CVE-2026-44951. The flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers under certain conditions. The vulnerability affects GitLab AI Gateway versions prior to 19.2.4, 19.3.2, and 19.4.1. Organizations running self-hosted instances are urged to update immediately.

11m
TThe Hacker NewsinCVE·Oct 3critical

CISA Adds Actively Exploited FortiMail Zero-Day to Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, affecting Fortinet FortiMail, has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system. CISA's action follows reports of active exploitation in the wild prior to the catalog addition.

11m
CCISA AdvisoriesinCVE·Oct 2critical

Critical Vulnerabilities Discovered in Armatura LLC Armatura One Platform

Armatura LLC's Armatura One and Armatura One (USA) platforms are affected by five vulnerabilities spanning critical and high severity. The most severe, CVE-2023-46604, is a deserialization flaw in embedded Apache ActiveMQ that allows unauthenticated remote code execution with highest privilege. Additional issues involve hard-coded cryptographic keys, fixed database passwords, and sensitive data leakage into logs. Versions prior to 4.7.2 (global) and 4.6.1_USA are affected. Patches have been released.

22m
CCISA AdvisoriesinCVE·Oct 2high

CISA Advises Critical Vulnerabilities in Malcolm ICS Platform

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an industrial control systems advisory detailing six vulnerabilities in the CISA Malcolm platform. The flaws range from cross-site scripting and OS command injection to path traversal and SSRF. All listed vulnerabilities affect CISA Malcolm versions earlier than v26.06.0, with the latest release (September 2026 or later) resolving the issues. Affected installations are urged to update immediately.

12m
BBleepingComputerinCVE·Oct 1critical

CISA Adds Critical Pre-Auth RCE Vulnerability in MikroTik RouterOS to KEV Catalog

CISA has added a critical pre-authentication remote code execution vulnerability in MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, mandating patching for U.S. federal civilian executive branch agencies. The flaw allows remote attackers to execute arbitrary code or cause denial-of-service without authentication. MikroTik has released patched versions 7.12.3 and 7.13.1rc to address the vulnerability.

11m
TThe Hacker NewsinCVE·Oct 1critical

Cisco Advises Urgent Patching of Critical Authentication Bypass in SD-WAN Manager

Cisco has confirmed that a critical vulnerability in Catalyst SD-WAN Manager is being actively exploited. The flaw, tracked as CVE-2026-76504, allows a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and Cisco states there is no workaround. The advisory was published on September 30, 2026.

11m
CCISA AdvisoriesinCVE·Sep 30high

CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.

12m
CCISA AdvisoriesinCVE·Sep 30high

CISA Adds CVE-2026-86950 to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability affects Apple Multiple Products and involves an out-of-bounds write flaw. Evidence of active exploitation has been confirmed, prompting CISA to require Federal Civilian Executive Branch agencies to prioritize rapid remediation on publicly exposed assets per Binding Operational Directive 26-04.

11m
TThe Hacker NewsinCVE·Sep 30high

Apple Patches Actively Exploited CoreGraphics Vulnerability in iOS, iPadOS, and macOS

Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component. The company reports the flaw may have been exploited in targeted attacks against older versions of iOS, iPadOS, and macOS. Successful exploitation could lead to arbitrary code execution in the context of the user. The updates are now available for affected devices.

11m
TThe Hacker NewsinCVE·Sep 30critical

CISA Adds Two Critical Citrix NetScaler Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities (KEV) catalog. The move follows reports of active exploitation in the wild and applies mandatory remediation requirements for U.S. federal agencies. Organizations using unpatched appliances are advised to apply security updates immediately.

11m
CCISA AdvisoriesinCVE·Sep 28critical

CISA Adds Two Citrix NetScaler Zero-Days to KEV Catalog; Eight Vulnerabilities Disclosed

CISA has added CVE-2026-88771 and CVE-2026-88772 to the Known Exploited Vulnerabilities catalog, citing confirmed active exploitation. Both are critical, zero-day vulnerabilities enabling remote code execution. Citrix disclosed eight total vulnerabilities (CVE-2026-88771 through CVE-2026-88778) affecting NetScaler ADC and NetScaler Gateway. Organizations are advised to check for indicators of compromise before patching and to preserve forensic evidence, as updates may reduce visibility.

21m
TThe Hacker NewsinCVE·Sep 28critical

CISA Adds Actively Exploited SharePoint and MikroTik Vulnerabilities to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws impacting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The inclusion is based on evidence of active exploitation in the wild. Organizations using these products are urged to apply vendor patches immediately to reduce risk.

11m
TThe Hacker NewsinCVE·Sep 26critical

Roundcube Webmail Pre-Authentication SQL Injection Actively Exploited in the Wild

The Canadian Centre for Cyber Security has issued a warning regarding a pre-authentication SQL injection vulnerability in Roundcube Webmail that is being actively exploited in the wild. The flaw, tracked as CVE-2026-48842, has a CVSS score of 8.1 and affects the virtuser_query plugin in versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. Successful exploitation could allow remote attackers to execute arbitrary SQL commands, potentially leading to data exfiltration, modification, or denial of service. Users are strongly advised to upgrade to the patched versions immediately.

11m
TThe Hacker NewsinCVE·Sep 25critical

Active Exploitation of Critical WordPress Vulnerability CVE-2026-87902 Reported Within Hours of Disclosure

Security researchers and threat intelligence sources report that active exploitation of CVE-2026-87902 has been observed in the wild within hours of the vulnerability's public disclosure. The flaw, rated CVSS 9.2, affects WordPress core and could allow unauthenticated attackers to include arbitrary local .php files via page-template resolution, potentially leading to remote code execution. WordPress version 6.6.2 contains the fix; administrators are advised to update immediately.

11m
TThe Hacker NewsinCVE·Sep 24critical

F5 Patches Actively Exploited Zero-Day in BIG-IP APM OAuth Server

F5 has released engineering hotfixes for CVE-2026-94127, a critical vulnerability in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution when APM functions as an OAuth authorization server. The flaw was disclosed on September 22, 2026, and is reported to be actively exploited in the wild. Systems where APM issues access tokens to applications are affected; configurations not using APM as an OAuth server are not at risk.

11m
BBleepingComputerinCVE·Sep 24high

Check Point Reports Active Exploitation of CVE-2026-85102 in Security Gateway VPN

Check Point researchers have confirmed that threat actors are actively exploiting CVE-2026-85102, a pre-authentication remote code execution vulnerability in the VPN certificate-handling functionality of Security Gateway products. Exploitation does not require authentication, and the vendor has not disclosed full technical details in the available summary.

11m
CCISA AdvisoriesinCVE·Sep 23high

Siemens Desigo CC Family Client Code Execution Vulnerability (CVE-2026-34223)

A Client Code Execution (CCE) vulnerability has been identified in Siemens Desigo CC family products V6 and V7. The flaw stems from insufficient input validation when handling scripts embedded within user-defined graphics documents. Successful exploitation could allow an attacker to execute arbitrary code on client devices, write arbitrary files to the operating system, and facilitate lateral movement within the organization. The vulnerability carries a CVSS 3.1 base score of 8.2 (HIGH) and has been assigned CVE-2026-34223. No patch is currently available; mitigation focuses on authorization policy review and network exposure reduction.

12m
TThe Hacker NewsinCVE·Sep 23critical

Actively Exploited Critical Flaw in VeloCloud Orchestrator (CVSS 10.0)

Arista and VMware have confirmed active exploitation of CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator (VCO). The flaw allows a remote attacker with no login access to privilege internal functions and affect the VCO host. Only VCO deployments configured to authenticate Edge devices using certificates are affected. A CVSS score of 10.0 has been assigned. Patches have been released; organizations are urged to update immediately.

11m