CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release
PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...
CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild
CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...
Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate
CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...
CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution
CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...
CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw
CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...
SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access
Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor's advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active...
CISA Sounds Alarm as Attackers Exploit Critical FortiSandbox Command Injection Flaws
CISA has confirmed active exploitation of two OS command injection vulnerabilities in Fortinet's FortiSandbox product line, adding both to its Known Exploited Vulnerabilities catalog and giving federal agencies...