Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
202 articles found
Featured Story
critical
Sep 11, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: PaperCut Zero-Days Exploited to Breach 395 Organizations

PaperCut has shipped maintenance releases 26.0.5, 25.0.13, and 24.1.10 to replace three rounds of emergency patches for CVE-2026-81578 and CVE-2026-82078, two actively exploited flaws that chain into preauthentication remote code execution. Researchers tracked a campaign that compromised more than 440 instances at 395 organizations across 48 countries, reaching domain admin at one school in seven minutes.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilitySep 10, 2026

CRITICAL: Cisco Firewall Management Center CVE-2026-20079 Under Active Attack

CISA added Cisco Secure Firewall Management Center flaw CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 federal remediation deadline. The CVSS 10.0 authentication bypass chains a static boot-time session ID and hardcoded credentials into unauthenticated root code execution on the appliance that manages your firewall policy. Patches have been available since March.

Read more
critical
CVE AdvisoryVulnerabilitySep 8, 2026

CRITICAL: FreeIPA CVE-2026-76578 Gives Anonymous Clients Admin Rights

FreeIPA CVE-2026-76578 lets an unauthenticated LDAP client create a Kerberos principal of its own choosing and land it in the administrators group, with no credentials and no prior access required. Red Hat rates it 9.8 critical and reproduced the chain against default installations. FreeIPA 4.13.4 fixes it, while the 389 Directory Server half of the chain is still catching up across platforms.

Read more
critical
CVE AdvisoryVulnerabilitySep 7, 2026

CRITICAL: N-able N-central CVE-2026-86218 Pre-Auth RCE Under Active Attack

N-able shipped Hotfix 4 for N-central 2026.3 on September 5, closing CVE-2026-86218, an unauthenticated remote code execution flaw rated CVSS 10.0 that lets attackers run code on the RMM console with no credentials. It is the fourth emergency hotfix in five weeks, and Huntress confirmed a compromised production server. On-premises customers need build 2026.3.1.14 now.

Read more
critical
CVE AdvisoryVulnerabilitySep 6, 2026

CRITICAL: Magento and Adobe Commerce Zero-Day Exploited With No Patch Available

Attackers are actively exploiting an unpatched remote code execution flaw in Magento Open Source and Adobe Commerce that Sansec has named StyleSmuggler. Every current version is affected including 2.4.9, exploitation began on September 4, and Adobe has not published a CVE, an advisory, or a fix. The chain ends in a persistent Rust backdoor disguised as a kernel thread.

Read more
critical
CVE AdvisoryVulnerabilitySep 5, 2026

CRITICAL: Cisco Nexus 9000 CVE-2026-20212 Allows Unauthenticated Root RCE

Cisco patched CVE-2026-20212, a CVSS 9.8 flaw in Nexus 9000 Series switches built on Silicon One ASICs that lets an unauthenticated remote attacker execute code as root. The S1HAL process listens on TCP ports 43210 and 43211 through the default Layer 3 VRF, and NX-OS releases 10.3(1) through 10.6(3s) are affected. Upgrade to 10.6(4) or later, or apply an infrastructure access control list.

Read more
critical
CVE AdvisoryVulnerabilitySep 1, 2026

CRITICAL: Ruby on Rails CVE-2026-66066 Exploited in the Wild

Attackers are actively exploiting CVE-2026-66066, the CVSS 9.5 Active Storage flaw in Ruby on Rails nicknamed KindaRails2Shell, with VulnCheck detections jumping from 50 to 360 in under two days. A crafted image upload gives an unauthenticated attacker arbitrary file read and a path to remote code execution. Patched in Active Storage 7.2.3.2, 8.0.5.1, and 8.1.3.1, and the fix also requires libvips 8.13 or newer.

Read more
critical
CVE AdvisoryVulnerabilityAug 19, 2026

CRITICAL: Windows IKE Flaw CVE-2026-33824 Under Active Exploitation

CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on August 18 after Unit 42 observed hands on keyboard attacks against Windows IKE VPN endpoints. The CVSS 9.8 double free in the Windows IKE Service Extensions gives unauthenticated attackers SYSTEM level code execution over UDP 500 and 4500. Microsoft patched it in April 2026 and federal agencies must remediate by August 21.

Read more
critical
CVE AdvisoryVulnerabilityAug 18, 2026

CRITICAL: Ray CVE-2025-62593 Added to CISA KEV After Active Exploitation

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026, giving federal civilian agencies until August 20 to remediate. The critical 9.4 flaw in the Ray distributed AI framework lets a malicious web page reach an otherwise unexposed Ray dashboard through DNS rebinding and execute arbitrary code. The RondoDox botnet weaponized it two days before public disclosure, and every version before Ray 2.52.0 is affected.

Read more
critical
CVE AdvisoryVulnerabilityAug 14, 2026

CRITICAL: SharePoint CVE-2026-55040 Exploited After Public PoC Release

Microsoft patched CVE-2026-55040 in July 2026, a CVSS 9.1 authentication bypass in on-premises SharePoint Server that chains four JWT validation failures to let an unauthenticated attacker forge tokens and impersonate any user, including administrators. Rapid7 published a working proof of concept on August 11 and honeypots recorded exploitation attempts roughly one day later. SharePoint Server 2016, 2019, and Subscription Edition are all affected.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Page 1 of 11Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.