CISA Warns of Citrix Vulnerability Active Exploitation in Attacks (CVE-2026-88779)

Citrix released an emergency update to address an actively exploited vulnerability impacting Citrix NetScaler ADC and Citrix NetScaler Gateway. Tracked as CVE-2026-88779, successful exploitation of this memory overflow vulnerability may allow an attacker to achieve a denial-of-service condition.  CISA added CVE-2026-88779 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before … Continue reading “CISA Warns of Citrix Vulnerability Active Exploitation in Attacks (CVE-2026-88779)”

Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Exploited in Attacks (CVE-2026-76504)

Cisco released a security advisory addressing a critical vulnerability affecting the Cisco Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to access an affected system with admin privileges. Cisco mentioned in their advisory that they are aware of the vulnerability being exploited. CISA also acknowledged the … Continue reading “Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Exploited in Attacks (CVE-2026-76504)”

Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)

Apple released updates to address an actively exploited vulnerability tracked as CVE-2026-86950. The vulnerability affects iOS, iPadOS, macOS Tahoe, and Sequoia. This is an out-of-bounds write flaw that can be exploited by processing a maliciously crafted file. Successful exploitation of the vulnerability may lead to arbitrary code execution. Apple has addressed the vulnerability with improved bounds checking. Apple mentioned in … Continue reading “Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)”

Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered agencies to secure their systems against two critical Citrix NetScaler vulnerabilities that have been exploited in attacks. CISA added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities Catalog. CISA urged users to patch the vulnerabilities before September 30, 2026. CVE-2026-88771 This is an improper input validation … Continue reading “Citrix NetScaler ADC and Gateway Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-88771 & CVE-2026-88772)”

CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)

Cisco released security updates to address a critical severity vulnerability in Cisco Identity Services Engine. Tracked as CVE-2026-76460, successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to bypass authentication. Cisco mentioned in their advisory that they are aware of active exploitation of this vulnerability. CISA acknowledged the active exploitation of the vulnerability by adding to its … Continue reading “CISA Warns of Cisco Identity Services Engine Authentication Bypass Vulnerability (CVE-2026-76460)”

Oracle Critical Security Patch Update, September 2026 Review

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, total 104 (15%) vulnerabilities … Continue reading “Oracle Critical Security Patch Update, September 2026 Review”

Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)

Cisco released a security advisory about a critical-severity vulnerability in Cisco Secure Email Gateway. Tracked as CVE-2026-76461, the vulnerability is being exploited in the wild. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary commands with root privileges on the underlying operating system. Cisco TAC team discovered the vulnerability. CISA acknowledged the … Continue reading “Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)”

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)

Google released security updates to address 230 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-87491, is being exploited in the wild. This is an out-of-bounds write vulnerability in the V8 JavaScript engine. The vulnerability was discovered and reported by Jihyeon Jeong (Compsec Lab, Seoul National University /Research Intern). CISA acknowledged the … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-87491)”

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats. This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including … Continue reading “Microsoft Patch Tuesday, September 2026 Security Update Review”