CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal BleepingComputer Advisory UniFi Connect Application network-edge UniFi Talk

Ubiquiti warns of new max severity UniFi OS vulnerability

Read full story

Ubiquiti has released security updates to address seven critical vulnerabilities across UniFi OS, including a maximum-severity command injection issue tracked as CVE-2026-50746. The flaw affects UniFi Connect Application (versions 3.4.16 and earlier) and could allow an attacker with network access to inject commands and compromise the host device. In addition, Ubiquiti patched six other critical-severity issues (CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-54402, CVE-2026-55115, CVE-2026-55116) affecting UniFi Talk, UniFi Access, UniFi Protect, the UniFi OS Server, and a range of Ubiquiti routers, gateways, NAS, and surveillance systems. With many UniFi OS instances exposed online, timely upgrades matter to reduce the risk of automated compromise.

Earlier39 stories
Jul 8
BleepingComputer Exploited Adobe ColdFusion web-app4 min read

CISA orders feds to patch max severity ColdFusion flaw by Friday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal civilian agencies to remediate an actively exploited, maximum-severity vulnerability in Adobe ColdFusion by Friday, June 10. The issue, tracked as CVE-2026-48282, impacts ColdFusion versions 2025.9 and 2023.20 (and earlier) and can allow remote attackers to execute code on unpatched systems without special privileges. Adobe has already released security updates and warned administrators to deploy them immediately, underscoring the fast-moving exploitation risk that prompted CISA to add CVE-2026-48282 to its Known Exploited Vulnerabilities catalog.

Jul 8
The Hacker News PoC privilege-escalation5 min read

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a long-standing Linux kernel flaw (present since 2011) that allows a logged-in user on unpatched systems to gain full root privileges and break out of containers. The issue is triggered via ordinary local threading behavior with no special permissions or network access, making it a serious risk for multi-tenant hosts, cloud instances, CI runners, and shared environments. Nebula published working exploit code, underscoring the urgency of applying the latest kernel updates from affected distributions.

Jul 8
The Hacker News Exploited Adobe ColdFusion web-app6 min read

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active in-the-wild abuse affecting Adobe ColdFusion, Joomlack Page Builder, JoomShaper SP Page Builder, and Langflow. The affected CVEs are CVE-2026-48282 and CVE-2026-56290 (both with CVSS 10.0), CVE-2026-55255, and CVE-2026-48908 (CVSS 10.0), spanning issues like path traversal and improper access control that can enable remote code execution and other takeovers. This matters because KEV-listed bugs are prioritized for remediation, with FCEB agencies advised to patch by July 10, 2026.

Jul 7
BleepingComputer Incident Ruckus routers UAT-78103 min read

Chinese hackers develop LONGLEASH malware to expand ORB network

Researchers at Cisco Talos say a China-aligned actor tracked as 'UAT-7810' is expanding its Operational Relay Box (ORB) infrastructure by compromising internet-exposed networking devices, with a focus on unpatched Ruckus routers. The campaign includes new malware components such as LONGLEASH (an upgraded SHORTLEASH backdoor) and others, and the initial access targets multiple vulnerabilities including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 (as well as similar issues in ASUS AiCloud devices). This matters because ORB networks can proxy malicious traffic through seemingly legitimate local infrastructure, making detection and attribution significantly harder.

Jul 7
BleepingComputer Patch Tenda FH1201 network-edge3 min read

Hidden backdoor in Tenda router firmware grants admin access

CERT/CC reports a hidden authentication backdoor in multiple Tenda router firmware builds, tracked as CVE-2026-11405 (and also referenced in the bulletin as CVE-2026-13753), that can grant full administrator access to the web management interface without needing the configured admin username. The issue affects Tenda devices including FH1201 (USFH1201V1.0BRV1.2.0.14(408)ENTD), W15E (USW15EV1.0brV15.11.0.5(10681567841)ENTDE), AC10 (USAC10V1.0reV15.03.06.46multiTDE01), AC5 (USAC5V1.0RTLV15.03.06.48multiTDE01), and AC6 V2 (USAC6V2.0RTLV15.03.06.51multiT). With no patch currently available, the practical impact is that attackers could reconfigure the device and weaken local-network security; users are advised to disable remote web management and reduce exposure to automated scanning.

Jul 7
SecurityWeek Exploited Gitea web-app2 min read

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Attackers are reportedly exploiting a vulnerability in Gitea’s reverse-proxy authentication logic to gain access to internet-reachable instances by providing only a valid username. The issue, affecting Gitea official Docker images before 1.26.3, is tracked as CVE-2026-20896 (CVSS 9.8) and can be triggered using a single HTTP header, enabling authentication bypass when reverse-proxy auth is configured incorrectly. Researchers say exploitation began shortly after disclosure, and organizations should upgrade to patched Gitea versions as quickly as possible to reduce risk of full compromise of repositories and secrets.

Jul 7
SecurityWeek Exploited Adobe ColdFusion web-app3 min read

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

Attackers have started exploiting a critical path traversal vulnerability in Adobe ColdFusion shortly after it was made public, with proof of in-the-wild use reported for CVE-2026-48282 (CVSS 10/10). The flaw can enable arbitrary code execution, making it a high-impact risk for systems running Adobe ColdFusion versions patched by Adobe in ColdFusion 2025 update 10 and ColdFusion 2023 update 21. This matters because exploitation began within two hours of disclosure, leaving little time for organizations to validate and deploy mitigations before attackers moved.

Jul 7
BleepingComputer PoC Linux kernel cloud3 min read

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A long-standing Linux kernel issue dubbed Januscape allows attackers inside a guest virtual machine to escape into the host, leading to arbitrary code execution or host crashes. The problem, tracked as CVE-2026-53359, is a use-after-free bug in KVM/x86 shadow MMU emulation and has been present for about 16 years before a June 2026 fix (commit 81ccda30b4e8). This matters for multi-tenant cloud environments running KVM, where exploitation can compromise other guests or cause denial of service.

Jul 7
Help Net Security Exploited Adobe ColdFusion web-app4 min read

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)

Active exploitation attempts have been observed against Adobe ColdFusion shortly after patches were released on June 30, 2026. The targeted issue is CVE-2026-48282, a path traversal vulnerability that can be abused by remote, unauthenticated attackers to upload a malicious file and trigger arbitrary code execution via a web-accessible location. This matters because attackers can leverage the Remote Development Services (RDS) feature when it is enabled and access is not properly restricted, so organizations running affected ColdFusion versions should urgently update and hunt for suspicious artifacts.

Jul 7
Cisco Talos Research Ruckus wireless routers UAT-781014 min read

UAT-7810 continues building ORB networks using new malware

Cisco Talos reports that the China-nexus APT actor UAT-7810 continues expanding LapDogs Operational Relay Box (ORB) networks, adding new malware capabilities to support follow-on attacks on high-value targets. The actor is developing an updated version of SHORTLEASH tracked as LONGLEASH and has introduced additional backdoors including DOGLEASH and the Java-based JARLEASH for remote administration. Talos also observed UAT-7810 exploiting unpatched Ruckus wireless routers using CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, underscoring the risk of ORB-based persistence and device compromise when these vulnerabilities remain unremediated.

Jul 7
SecurityWeek Research Linux Kernel cloud2 min read

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A newly reported Linux kernel issue, tracked as CVE-2026-53359 and dubbed Januscape, can be exploited by a guest VM to corrupt host state and gain execution on the underlying system via the KVM shadow MMU. This matters for multi-tenant x86 cloud environments—especially those with nested virtualization—because successful exploitation can lead to full host compromise, denial of service, or root-level code execution. Researchers note the flaw was present for 16 years and has been patched in the mainline kernel as of June 19.

Jul 7
The Hacker News Exploited Roundcube webmail UNK_MassTraction6 min read

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A suspected China-aligned threat group has been observed targeting Roundcube webmail used by physics and engineering departments at U.S. and Canadian universities, enabling credential theft and persistent access. The campaign chains exploitation of CVE-2024-42009 (XSS) and then leverages CVE-2025-49113 for remote code execution, with payloads such as VShell for post-compromise activity; Proofpoint tracks the activity as UNKMassTraction. This matters because opening a crafted email in the Roundcube client can trigger access to the mail server, turning email delivery into a practical path to compromise.

Jul 7
BleepingComputer Patch Remote Support (RS) auth-bypass4 min read

BeyondTrust warns of critical flaws in remote access software

BeyondTrust has disclosed critical issues in its Remote Support (RS) and Privileged Remote Access (PRA) products that could let attackers bypass authentication and reach protected appliances. The company cites CVE-2026-40138 (RS and PRA versions 25.3.2 or earlier) and CVE-2026-40139, where improper handling of RS authentication requests could allow unauthenticated remote attackers to gain unauthorized access. BeyondTrust also released fixes for CVE-2026-40140 and CVE-2026-40141 affecting unpatched RS and PRA instances, which can lead to denial-of-service or unintended access to restricted resources, making patching urgent.

Jul 6
Dark Reading Exploited NetScaler Application Delivery Controller network-edge5 min read

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Citrix disclosed CVE-2026-8451, a memory overread issue in NetScaler ADC and NetScaler Gateway devices configured as a SAML identity provider (IDP), with a CVSS score of 8.8. Researchers and security vendors report that threat actors are actively scanning for and using a proof-of-concept-style exploit, potentially leaking sensitive information and enabling further compromise (including privilege escalation and lateral movement). Organizations using affected NetScaler systems should prioritize applying the fixed versions and reviewing SAML IDP activity for suspicious events.

Jul 6
The Hacker News Incident Cavern Manticore nation-state7 min read

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

Check Point reports that the Iran-linked threat cluster “Cavern Manticore” is using a previously undocumented modular command-and-control framework called Cavern (aka Cav3rn) to target Israeli organizations, with IT service providers and government entities among the main focuses. The activity leverages SysAid software update functionality to trigger DLL side-loading and then delivers additional payload modules via the Cavern agent, enabling tailored reconnaissance, data theft, and lateral movement while complicating analysis through mixed compilation formats. Separately, CVE-2025-52691, CVE-2025-68613, CVE-2025-9316, CVE-2025-34291, and CVE-2025-54068 are referenced as part of broader exploitation activity tied to the same state-linked operations.

Jul 6
The Hacker News PoC KVM Hypervisor zero-day6 min read

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A use-after-free bug in Linux’s KVM shadow MMU can be triggered from a guest VM to corrupt host kernel shadow-page state, with a public proof-of-concept able to panic the host. The issue, tracked as CVE-2026-53359 (“Januscape”), affects KVM on Intel and AMD x86 systems and matters because a malicious tenant could potentially crash the host and, in reported research, even reach host code execution under the right conditions (root in the guest and nested virtualization enabled). Fixes have been merged as commit 81ccda30b4e8 and stable releases include kernel versions such as 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, and 5.10.260.

Jul 6
Dark Reading Exploited ransomware6 min read

JadePuffer: The First Complete LLM-Driven Ransomware Attack

Researchers reported “JadePuffer,” an LLM-driven ransomware operation attributed to an “agentic” threat actor that carried out extortion with no human operator during key stages. The attack began by exploiting CVE-2025-3248 in an Internet-facing Langflow deployment, then moved to compromise a production database server running a MySQL database and an Alibaba Nacos configuration service to enumerate, exfiltrate selected data, delete it, and demand payment. The incident matters because it demonstrates a full, automated ransomware lifecycle that can adapt in real time—highlighting the need to patch Langflow quickly and avoid exposing code-execution endpoints to the Internet.

Jul 6
The Hacker News Exploited Gitea Docker Images web-app4 min read

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat actors have been seen probing recently fixed Gitea Docker images for a critical authentication weakness tracked as CVE-2026-20896 (CVSS 9.8). The issue occurs when the Docker image default trusts all source IPs for the X-WEBAUTH-USER header, which can allow unauthenticated attackers to gain elevated access if reverse-proxy authentication is enabled and the allowlist is not restricted. This affects Gitea Docker image versions before and including 1.26.2, with the fix provided in version 1.26.3.

Jul 6
BleepingComputer Exploited ColdFusion rce4 min read

Max severity Adobe ColdFusion flaw now exploited in attacks

Attackers are exploiting a max-severity Adobe ColdFusion vulnerability, CVE-2026-48282, with KEVIntel reporting in-the-wild use shortly after public details emerged. The issue affects ColdFusion versions 2025.9, 2023.20, and earlier and can enable remote code execution without needing attacker privileges, making unpatched systems a priority risk. Adobe has released fixes and urged administrators to apply updates immediately, with Canadian and other monitoring efforts also warning defenders to remediate.

Jul 6
SecurityWeek PoC epoll privilege-escalation2 min read

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

A proof-of-concept exploit has been released for the Linux “Bad Epoll” issue, which is a race-condition use-after-free in the epoll subsystem. The vulnerability is tracked as CVE-2026-46242 and affects Linux kernels 6.4+ (including confirmation on Pixel 10 devices using kernel 6.6), where attackers may achieve kernel memory leakage and root privileges. Since this can be used to bypass privilege boundaries, it matters for desktops, servers, and Android systems that run affected kernels.

Jul 6
Check Point Research Advisory ERP Systems data-breach6 min read

6th July – Threat Intelligence Report

Check Point Research reports multiple incidents this week, including ransomware cases impacting River Bank & Trust, Indra Group, Nidec Chaun Choung Technology, and a major Aflac Japan breach affecting nearly 4.4 million customers. The update also covers AI-driven threats such as LLM-generated ransomware that abuses Chrome’s File System Access API and AI domain “phantom squatting” used for phishing. On the vulnerability side, critical issues including CVE-2026-46817 (Oracle E-Business Suite), CVE-2026-46242 (Linux kernel Bad Epoll), CVE-2026-8451 (Citrix NetScaler), and CVE-2026-8037 (Progress Kemp LoadMaster) are emphasized due to exploitation risk and rapid weaponization.

Jul 5
Help Net Security Patch ClamAV web-app3 min read

New ClamAV security patch closes seven scanner bugs dating back two decades

Cisco Talos’ ClamAV released security patch versions 1.5.3 and 1.4.5 to address seven vulnerabilities affecting its executable and archive parsing logic, plus quarantine handling hardening. The fixes cover CVE-2026-20213, CVE-2026-20214, CVE-2026-20217, CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, and CVE-2026-20244, which can lead to memory corruption, crashes, scanner bypass conditions, or unstable behavior when processing crafted inputs. These updates also matter because ClamAV is commonly used in mail gateways and endpoint/file scanning workflows where attackers may leverage malformed files to disrupt or evade scanning.

Jul 5
Help Net Security Advisory15 min read

Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Attackers are actively exploiting CVE-2026-48558 in SimpleHelp RMM, using the authentication-bypass weakness to deploy the Djinn Stealer malware across Windows, macOS, and Linux systems. In parallel, threat intelligence reports exploitation attempts against CVE-2026-46817 affecting Oracle E-Business Suite Payments, with the Oracle Payments module targeted via weekend activity. These incidents matter because they show how quickly patched (or still-fresh) enterprise flaws can be weaponized, increasing the urgency of remediation and monitoring for both vendors.

Jul 4
BleepingComputer Research langflow ai-ml4 min read

JadePuffer ransomware used AI agent to automate entire attack

Researchers report a ransomware case, JadePuffer, in which an autonomous LLM agent handled reconnaissance through credential theft, lateral movement, persistence, privilege escalation, and finally encryption. Initial access was achieved by exploiting CVE-2025-3248 in Langflow, with later impact on Alibaba Nacos also involving CVE-2021-29441 for an authentication bypass that enables rogue admin creation. This matters because AI-driven “agentic” malware could reduce the expertise needed to run full intrusion chains while also changing detection requirements for defenders.

Jul 3
The Hacker News PoC esp-idf ics-ot-iot6 min read

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

runZero disclosed seven vulnerabilities in FatFs, a filesystem library used to access FAT and exFAT volumes on removable storage. The issues are tracked as CVE-2026-6682, CVE-2026-6683, CVE-2026-6684, CVE-2026-6685, CVE-2026-6686, CVE-2026-6687, and CVE-2026-6688, including integer overflows that can lead to memory corruption and possible code execution when a device mounts attacker-controlled or malformed storage/update images. This matters because FatFs is bundled into many embedded platforms and firmware (e.g., Espressif ESP-IDF, STMicroelectronics STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, and the SWUpdate updater), expanding potential impact across consumer IoT, industrial systems, drones, and crypto wallets.

Jul 3
The Hacker News PoC linux kernel privilege-escalation6 min read

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A newly disclosed Linux kernel issue called “Bad Epoll” (CVE-2026-46242) enables unprivileged local users to gain root access. It impacts Linux systems and Android devices that run affected kernel builds, because an epoll use-after-free race can corrupt kernel memory and turn a normal account into full control. Fixes are available via upstream (commit a6dc643c69311677c574a0f17a3f4d66a5f3744b) and distribution backports, and timing makes the bug hard but the published proof of concept reliably achieves escalation on tested setups.

Jul 3
The Hacker News Research ransomware7 min read

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Researchers uncovered the modular malware framework Avalon, which uses a multi-stage phishing chain to bypass security controls and ultimately deploy a ransomware component internally tracked as CrownX. Avalon is designed to harvest credentials and browser data, establish remote access and lateral movement, suppress forensic visibility (including ETW interference), and then encrypt files while disrupting recovery using shadow copy removal. The same report also highlights a JADEPUFFER agentic ransomware campaign that gained access via CVE-2025-3248 affecting a Langflow instance, underscoring how readily AI-assisted tooling can accelerate ransomware development and attack execution.

Jul 3
The Hacker News Research government agencies armored likho7 min read

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

Security researchers attribute a campaign by the threat actor Armored Likho to attacks against government organizations and the electric power sector in Russia, Brazil, and Kazakhstan. The activity includes spear-phishing and malware that deploys BusySnake Stealer, a Python-based information stealer for Windows that can exfiltrate browser data (including cookies), screenshots, clipboard contents, and other sensitive material. The intrusion chain also leverages a Windows shortcut-related flaw, tracked as CVE-2025-9491 (aka ZDI-CAN-25373) and patched by Microsoft in November 2025, enabling remote code execution when LNK files are handled improperly.

Jul 3
SecurityWeek Exploited langflow jadepuffer4 min read

Agentic AI Used to Conduct Ransomware Attack via Langflow

A threat actor used agentic LLM-driven automation to carry out a ransomware operation after compromising internet-exposed Langflow via CVE-2025-3248, a critical missing authentication issue that enables arbitrary Python code execution on the host. The intruder tracked as JadePuffer then used AI-assisted reconnaissance and credential harvesting, before targeting a production MySQL and Alibaba Nacos setup, including abuse of CVE-2021-29441 and Nacos weaknesses tied to a default JWT signing key. This matters because it demonstrates how capable models can lower the barrier for large-scale, hands-off malicious actions against neglected and improperly hardened application and configuration infrastructure.

Jul 3
SecurityWeek Research cursor rce3 min read

Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

Cato Networks reports two critical vulnerabilities in the AI code editor Cursor that could enable remote code execution on the host operating system by escaping the IDE’s sandbox. The issues are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8), collectively referred to as DuneSlide, and they can be triggered through crafted prompts that abuse Cursor’s automatic terminal command execution and weaknesses in file path handling involving symbolic links. This matters because a malicious payload could move from an injected IDE action to unrestricted OS-level code execution.

Jul 2
The Hacker News Exploited netscaler anubis8 min read

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors linked to the Anubis ransomware operation have been seen abusing Citrix Bleed 2 to gain initial access, specifically via CVE-2025-5777 affecting Citrix NetScaler ADC and Gateway (CVSS 9.3). The same reporting highlights their use of remote access tools, credential theft, RDP/PsExec for lateral movement, and follow-on data theft before deploying ransomware. In related ransomware activity, Kaspersky described The Gentlemen RaaS using a Go-based backdoor and weaponizing a BYOVD scenario involving the ktapi.sys driver for kernel-level abuse, while Sophos reported a VECT and TeamPCP supply-chain partnership that enables ransomware deployment across victims of Trivy and LiteLLM supply chain attacks. These developments matter because they combine high-impact exploitation and credential compromise with scalable “industrialized” deployment tactics that lower the barrier for attackers.

Jul 2
Cisco Talos Exploited Microsoft 365 phishing8 min read

Catan and Mouse

Cisco Talos highlights ARToken, a phishing-as-a-service operator panel for Microsoft 365 focused on device code phishing, Primary Refresh Token (PRT) persistence, email access/BEC operations, and SharePoint exfiltration—capabilities exposed through 80+ API endpoints. Separately, Talos notes that a recently reported authentication bypass in SimpleHelp remote monitoring and management (RMM), tracked as CVE-2026-48558, has been exploited in the wild to obtain a fully authenticated technician session for malware delivery. These findings matter because they indicate both increasing maturity in credential/theft-driven phishing tooling and active exploitation of authentication weaknesses.

Jul 2
watchTowr Labs Patch Adobe ColdFusion rce14 min read

It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)

Adobe has released APSB26-68 addressing a large set of security issues in Adobe ColdFusion, impacting ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below). The bulletin includes fixes for multiple remote-impact vulnerabilities such as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48283, CVE-2026-48313, CVE-2026-48315, CVE-2026-48307, CVE-2026-48285, and CVE-2026-48314. These issues matter because they can enable arbitrary file read/write and privilege escalation pathways—potentially escalating to remote code execution when vulnerable features are reachable and misconfigured.

Jul 2
The Hacker News Research Apple Hide My Email China-nexus16 min read

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

Security coverage this week describes multiple weaknesses that let attackers slip through “allowed” paths, including AI compute hijacking via misconfigured Ollama model servers used as the reasoning engine in offensive tooling. Apple’s Hide My Email service has a reported flaw that can reveal users’ real addresses, while research also details an attack chain against Claude Cowork on Windows that can lead to root-level execution in its sandbox and potential data exfiltration. Separately, CISA confirmed Microsoft Defender’s BlueHammer (CVE-2026-33825) was exploited in ransomware attacks, underscoring how quickly real-world impact can follow once patching lags.

Jul 2
SecurityWeek Exploited Citrix NetScaler ADC zero-day2 min read

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

Threat actors reportedly started attacking affected Citrix NetScaler ADC and NetScaler Gateways almost immediately after public disclosure, with exploitation observed in under 24 hours. The issue, tracked as CVE-2026-8451 (CVSS 8.8), is an out-of-bounds read in the NetScaler XML parser that can disclose memory contents via the NSCTASS cookie when appliances are configured as SAML IDP; no authentication is required for successful exploitation. This matters because the rapid weaponization suggests exposed internet-facing systems could be targeted quickly, so organizations should prioritize patching or mitigate by disabling SAML IDP and checking relevant logs and cookies.