// THREAT ADVISORIES

THREAT ADVISORIES

Advisories, vulnerabilities and threat intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
0
Last 24h
39
Last 7 Days
39
Critical (7d)
All Critical High Medium Low
✕ Clear All
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFDutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

Critical · Sep 12, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

Critical · Sep 11, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFArtifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

Critical · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFGitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]

Critical · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💀
VERISQ BRIEFCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

Critical · Sep 11, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEF[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Critical · Sep 11, 2026 · Exploit Database
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💀
VERISQ BRIEFCisco Firewall Bugs Let in Sandworm, Qilin

Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption.

Critical · Sep 10, 2026 · DataBreachToday
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure […]

Critical · Sep 10, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💀
VERISQ BRIEFCisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]

Critical · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFNightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit

The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.

Critical · Sep 10, 2026 · Dark Reading
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFNew 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

Critical · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

Critical · Sep 10, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏦
VERISQ BRIEFCisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More → The post Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) appeared first on Help Net Security .

Critical · Sep 10, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

Critical · Sep 10, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFCISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]

Critical · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🏛️
VERISQ BRIEFU.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a […]

Critical · Sep 10, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-657: ASUS Control Center Express Agent Missing Authentication Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19397.

Critical · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PAPPL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.

Critical · Sep 10, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

Critical · Sep 09, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 📧
VERISQ BRIEFA Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution

A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components. Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.

Critical · Sep 09, 2026 · CIS Advisories
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFActive exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.

Critical · Sep 09, 2026 · Cisco Talos Intelligence
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFAlby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

Critical · Sep 09, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFMicrosoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.

Critical · Sep 09, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFPoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory

PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments. Sophos tracks it as Linux/Agnt-IC. F5 has confirmed exploitation of the […]

Critical · Sep 09, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 📧
VERISQ BRIEFNew cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

Critical · Sep 09, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFChaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]

Critical · Sep 09, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFMicrosoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update. The company also […]

Critical · Sep 09, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

Critical · Sep 09, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

Critical · Sep 09, 2026 · Zero Day Initiative
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]

Critical · Sep 08, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFWeChat Worm Can Hijack Accounts Without Victims Answering Calls

Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The attack works only when the caller already appears in […]

Critical · Sep 08, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFAdobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

Critical · Sep 08, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

Critical · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🔑
VERISQ BRIEFFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

Critical · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFMikroTik router flaws allow takeover without a password

Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.

Critical · Sep 08, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

Critical · Sep 08, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFAugust 2026 CVE Landscape

In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation, 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month.

Critical · Sep 08, 2026 · Recorded Future Feed
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFStyleSmuggler: The Magento Zero-Day Behind New Store Attacks

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticated attackers a path to run code on vulnerable online stores. Sansec researchers say it affects current […]

Critical · Sep 07, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

Critical · Sep 07, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCritical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

Critical · Sep 06, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

Critical · Sep 06, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

Critical · Sep 05, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFCritical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Critical · Sep 05, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🎓
VERISQ BRIEFAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Critical · Sep 05, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFBroadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as […]

Critical · Sep 05, 2026 · Security Affairs
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 🛡️
VERISQ BRIEFCritical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

Critical · Sep 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF 💣
VERISQ BRIEFNew CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]

Critical · Sep 04, 2026 · BleepingComputer
Read Full Intelligence Brief →
VULNERABILITY VERISQ BRIEF ☁️
VERISQ BRIEFOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Critical · Sep 04, 2026 · The Hacker News
Read Full Intelligence Brief →