MikeTrendsTrends right now

search

CVE

Trends

  1. 1
    Critical Command Injection Flaw Disclosed in Fortra BoKS Access Managerโ–ผCVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Securityโœ‰newsTechnologyCybersecurity4 min ago

    A critical vulnerability tracked as CVE-2026-9862 has been disclosed in Fortra's BoKS Core Privileged Access Manager, involving OS command injection that could let attackers execute arbitrary system commands. Because privileged access managers hold the keys to enterprise infrastructure, security teams are being urged to review the flaw and apply patches to limit the risk of full system compromise.

  2. 2
    Security flaw disclosed in AhsayCBS backup softwareโ—AhsayCBS https:// radar.offseq.com/threat/a-flaw -has-been-found-in-ahsay-ahsaycbs-up-to-1032-cve-2026-105134-a9f0def985MmastodonTechnologyCybersecurity34 min ago

    A vulnerability, tracked as CVE-2026-105134, has been reported in AhsayCBS, the backup software from Ahsay, affecting versions up to 10.3.2. The flaw was published on a threat-tracking service and is circulating among infosec communities, with security professionals flagging it for administrators who run Ahsay backup infrastructure. Details on severity and exploitation remain limited so far.

  3. 3
    ZITADEL hit by seven vulnerabilities enabling account takeoverโ—ZITADEL cluster โ€” 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header โ†’ issue passkey enrollment for anyMmastodonTechnologyCybersecurity24 min ago

    Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.

  4. 4
    Citrix NetScaler SAML zero-day actively exploited, added to CISA KEVโ—๐Ÿšจ Citrix NetScaler SAML zero-day (CVE-2026-88779, CVSS 8.7) in CISA KEV. Actively exploited. Memory overflow in SAML hanMmastodonTechnologyCybersecurity24 h ago

    A zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88779 with a CVSS score of 8.7, has been added to CISA's Known Exploited Vulnerabilities catalog amid reports of active exploitation. The flaw is a memory overflow in the SAML handler that can crash the appliance, disrupting VPN and SSO services for organizations using SAML SP or IdP configurations. Researchers warn it may bypass the previous patch. Fixed builds are 14.1-73.41 and 13.1-64.28, and administrators are urged to update immediately.

  5. 5
    Citrix NetScaler zero-day memory flaw added to CISA KEVโ—๐Ÿค– CVE-2026-88779 (CVSS 8.7): memory corruption (CWE-119) in Citrix NetScaler ADC/Gateway, reachable unauthenticated overMmastodonTechnologyCybersecurity18 h ago

    A high-severity memory corruption vulnerability, CVE-2026-88779 (CVSS 8.7), in Citrix NetScaler ADC and Gateway can be exploited unauthenticated over the network to cause denial of service. The flaw was attacked as a zero-day and has been added to CISA's Known Exploited Vulnerabilities catalog. Citrix has issued emergency fixes, and security teams are urged to patch immediately.

  6. 6
    CISA adds exploited NetScaler flaw CVE-2026-88779 to KEV listโ—If you're spending your Sunday night anywhere near a terminal, start with the NetScaler gear. CISA put CVE-2026-88779 onMmastodonTechnologyCybersecurity19 h ago

    CISA has added CVE-2026-88779, a vulnerability in Citrix NetScaler appliances, to its Known Exploited Vulnerabilities list after evidence of active exploitation. Federal agencies must apply patches by October 7. Security practitioners are urging admins to prioritise patching internet-facing NetScaler devices immediately, as such appliances have historically been frequent targets for attackers.