Activity

Latest CVE events and analysis as they emerge

  1. CVE-2026-76504

    30 Sept 2026, 00:00

    Cisco Catalyst SD-WAN Manager

    Added to CISA KEV catalog

    Vulnerability name
    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
    Product
    Cisco Catalyst SD-WAN Manager

    CVE-2026-76504 is an API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The issue arises from the improper handling of URI/URL encoding in HTTP requests. An unauthenticated, remote attacker can exploit this flaw by sending a crafted HTTP request to the affected system's API. This allows the request to bypass an authentication rule designed to restrict access to a specific API endpoint, granting the attacker access to the API with administrative privileges without requiring any credentials. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of its system configuration. Cisco discovered the issue through a customer support case and confirmed that it is being actively exploited in the wild. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Cisco has released software updates to address the flaw, and because no workarounds are available, organizations are advised to apply the patches to secure their systems.

  2. CVE-2026-86950

    29 Sept 2026, 00:00

    Supply chainMobile device

    Added to CISA KEV catalog

    Vulnerability name
    Apple Multiple Products Out-of-Bounds Write Vulnerability
    Product
    Apple Multiple Products

    CVE-2026-86950 is an out-of-bounds write vulnerability found within Apple's CoreGraphics framework. This flaw allows for memory corruption and can potentially lead to arbitrary code execution if a device processes a specially crafted file. The CoreGraphics component is fundamental to Apple operating systems, handling the rendering of 2D content such as images and PDF documents. Apple addressed this issue by implementing improved bounds checking in affected versions of iOS, iPadOS, and macOS. The vulnerability was reported to Apple by Meta Product Security. Apple has acknowledged reports suggesting that this issue may have been exploited in highly targeted attacks against specific individuals on older versions of iOS.

  3. CVE-2026-88778

    27 Sept 2026, 22:17

    VDICitrix NetScaler ADCCitrix NetScaler Gateway

    Trended on social media

    Hype increased to 31

    CVE-2026-88778 is identified as a TCP Initial Sequence Number (ISN) prediction flaw affecting Citrix NetScaler ADC and NetScaler Gateway appliances. This vulnerability specifically impacts devices configured with TCP-based virtual servers, such as those handling HTTP, SSL, or generic TCP traffic, when the "Enhanced ISN Generation" feature is disabled. To address this issue, Citrix advises applying software updates and implementing a configuration change to enable Enhanced ISN Generation on affected appliances.

  4. CVE-2026-88772

    27 Sept 2026, 20:17

    VDICloudSystemSSLDnsMobile deviceTlsCitrix NetScaler ADCCitrix NetScaler Gateway

    Trended on social media

    Hype increased to 32

    CVE-2026-88772 is a memory overflow vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw can result in remote code execution (RCE) or a denial-of-service (DoS) condition. The vulnerability specifically affects appliances where Datagram Transport Layer Security (DTLS) is enabled. DTLS is typically enabled by default for VPN virtual servers, meaning NetScaler Gateway deployments are susceptible unless DTLS has been explicitly disabled. Citrix has confirmed that this vulnerability, alongside CVE-2026-88771, has been actively exploited in unmitigated NetScaler deployments.

  5. CVE-2026-88771

    27 Sept 2026, 18:17

    VDISAPCloudSystemSSLDnsVPNMobile deviceTlsCitrix NetScaler ADCCitrix NetScaler Gateway

    Trended on social media

    Hype increased to 33

    CVE-2026-88771 is identified as an improper input validation vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway products. This flaw enables an unauthenticated attacker to execute arbitrary commands on affected systems. The vulnerability impacts all deployments of NetScaler ADC and NetScaler Gateway, and no specific additional features are required for it to be exploitable. Citrix confirmed that this vulnerability, alongside CVE-2026-88772, has been actively exploited in the wild on unmitigated NetScaler deployments. The company released security updates to address these issues, which were attacked before a public fix was available. NetScaler ADC and NetScaler Gateway appliances are commonly deployed at the edge of enterprise networks, handling functions such as VPN, remote access, load balancing, and user authentication.