Activity
Latest CVE events and analysis as they emerge
CVE-2026-86060 10 Sept 2026, 00:00
RouterOSAdded to CISA KEV catalog
- Vulnerability name
- MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- Product
- MikroTik RouterOS
CVE-2026-86060 is an argument-handling flaw identified in MikroTik RouterOS, specifically within its SSH login path. This vulnerability arises when usernames begin with a prohibited character, which can be manipulated to alter the trusted RouterOS policy mask. Such a change ultimately leads to privilege escalation within the system. Exploitation of CVE-2026-86060 requires an unauthenticated SSH session to successfully reach the RouterOS login helper. This flaw is often discussed in conjunction with CVE-2026-67276, an SSH authentication bypass, as chaining these two vulnerabilities can allow an attacker to gain full, unauthenticated control over affected MikroTik devices. MikroTik has released fixes for this issue in RouterOS versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
critical 9.2
Hype score
8
CVE-2026-67277 10 Sept 2026, 00:00
Added to CISA KEV catalog
- Vulnerability name
- MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- Product
- MikroTik RouterOS
CVE-2026-67277 is a vulnerability affecting the bandwidth-test service within MikroTik RouterOS. This flaw allows an unauthenticated client to establish a "related" btest connection before the primary session has completed its authentication process. An attacker can leverage this state to initiate an IPv4 UDP test. When the `random-data` parameter is set to `false`, the sender transmits an uninitialized tail from a kernel packet buffer, which can lead to the leakage of kernel memory. Additionally, an unchecked, inverted packet-size interval can cause an unsigned integer underflow and anomalously large fragmented output, potentially resulting in a remote denial-of-service (DoS) attack that restarts the RouterOS kernel or crashes the device.
high 8.8
Hype score
8
CVE-2026-87491 09 Sept 2026, 00:00
ChromiumGoogle ChromeV8Added to CISA KEV catalog
- Vulnerability name
- Google Chromium V8 Out of Bounds Write Vulnerability
- Product
- Google Chromium V8
CVE-2026-87491 is an out-of-bounds write vulnerability found in V8, Google Chrome's JavaScript and WebAssembly engine. This flaw allows a remote attacker to execute arbitrary code within the browser's sandbox by enticing a user to visit a specially crafted HTML page. The vulnerability was reported by Jihyeon Jeong of the Compsec Lab at Seoul National University on August 6, 2026. Google has confirmed that an exploit for CVE-2026-87491 exists in the wild, making it an actively exploited zero-day vulnerability. The issue has been addressed in Chrome version 153.0.8010.36 for Windows, macOS, and Linux, and is the seventh actively exploited Chrome zero-day patched by Google in 2026.
high 8.8
Hype score
10
CVE-2026-20079 09 Sept 2026, 00:00
NetworkPort (80)SystemHTTPAdded to CISA KEV catalog
- Vulnerability name
- Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Product
- Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
CVE-2026-20079 is an authentication bypass vulnerability found in the web interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows an unauthenticated, remote attacker to circumvent authentication mechanisms by sending specially crafted HTTP requests to an affected device. The root cause of the vulnerability stems from an improper system process that is created during the device's boot sequence, which introduces an alternate authentication path. Successful exploitation of CVE-2026-20079 enables the attacker to execute script files on the compromised device, ultimately leading to root access to the underlying operating system. This vulnerability affects Cisco Secure FMC Software across all device configurations.
critical 10.0
Hype score
8
CVE-2026-19490 09 Sept 2026, 00:00
Added to CISA KEV catalog
- Vulnerability name
- Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Product
- Citrix NetScaler
CVE-2026-19490 is an authentication bypass vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway appliances. This flaw, classified as CWE-288: Authentication Bypass Using an Alternate Path, allows an unauthenticated remote attacker to circumvent authentication controls on vulnerable systems. The vulnerability specifically affects appliances configured as a Gateway (such as SSL VPN, ICA Proxy, Clientless VPN/CVPN, or RDP Proxy) or as an AAA virtual server. For newer vulnerable builds, exploitation may require a SAML action to be configured, while older builds have a broader attack surface where the Gateway or AAA configuration alone is sufficient. Successful exploitation of CVE-2026-19490 could grant an attacker unauthorized access to internal applications and services that are typically secured behind authentication boundaries, without needing valid credentials or user interaction. The affected versions include NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32, and 13.1 before 13.1-63.21, along with corresponding FIPS and NDcPP releases. Cloud Software Group, the vendor, has released security updates and strongly recommends that customers upgrade affected customer-managed NetScaler appliances immediately.
critical 9.3
Hype score
0