Topic
Compliance & Regulation
Saudi regulatory frameworks — NCA controls, the SAMA framework and the Personal Data Protection Law.
83 articles in this topic
CVE-2026-32201: SharePoint Zero-Day Threatens Saudi Bank Intranets
Microsoft's actively exploited SharePoint zero-day CVE-2026-32201 puts Saudi bank intranets and document portals at risk. Over 1,300 servers remain exposed. Here is what Saudi CISOs must do now under SAMA CSCC.
VulnerabilitiesCVE-2026-27681: SAP BPC SQL Injection Endangers Saudi Bank Regulatory Reporting
A CVSS 9.9 SQL injection flaw in SAP Business Planning and Consolidation lets low-privileged users alter financial data — a direct threat to SAMA reporting integrity at Saudi banks.
VulnerabilitiesCVE-2026-4112: SonicWall SMA1000 SQL Injection Threatens Saudi Bank VPNs
A newly disclosed SonicWall SMA1000 SQL injection flaw (CVE-2026-4112) lets read-only administrators escalate to primary admin and seize bank VPN gateways. Saudi financial institutions must act under SAMA CSCC.
VulnerabilitiesCVE-2026-20147: Cisco ISE RCE Chain Hits Saudi Bank NAC Backbone
Three critical Cisco ISE vulnerabilities allow authenticated attackers to escalate to root on the very appliance that authorizes every device on a Saudi bank's network — a direct hit on SAMA CSCC segmentation and NCA ECC identity controls.
VulnerabilitiesCVE-2026-33825 "BlueHammer": Defender LPE Threatens Saudi Banks
BlueHammer (CVE-2026-33825): an actively exploited Microsoft Defender LPE flaw that bypasses endpoint defenses on Saudi bank workstations. Patch under SAMA CSCC.
VulnerabilitiesCVE-2026-34197: 13-Year-Old ActiveMQ RCE Threatens Saudi Banks
CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to KEV with an April 30 deadline. With 6,000+ exposed instances and active exploitation, Saudi financial institutions must act now under SAMA CSCC.
VulnerabilitiesCVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks
A zero-click Windows Shell flaw silently leaks NTLMv2 hashes the moment a user browses a folder. Saudi financial institutions under SAMA CSCC must patch CVE-2026-32202 by May 12 to avoid credential theft and lateral movement across Active Directory.
VulnerabilitiesCVE-2026-34621: Adobe Reader Zero-Day Targets Saudi Financial PDFs
CVE-2026-34621, an actively exploited Adobe Acrobat Reader zero-day, enables arbitrary code execution via weaponized PDFs. Saudi banks and fintechs face immediate endpoint and SAMA CSCC exposure.
VulnerabilitiesCVE-2026-1281 & CVE-2026-1340: The Ivanti EPMM Zero-Days Putting Saudi Bank MDM Fleets at Risk
A single bulletproof-hosted IP is driving 83% of active Ivanti EPMM exploitation via CVE-2026-1281 and CVE-2026-1340. Saudi banks running on-prem MDM face direct SAMA CSCC exposure — here is what to patch, hunt, and rotate now.
Cloud & IdentityMcGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure
A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.
Compliance & RegulationNIST Stops Scoring Most CVEs: What Saudi Financial Institutions Must Do Before Their Next SAMA Audit
NIST's National Vulnerability Database will no longer enrich most CVEs with CVSS scores effective April 15, 2026. For SAMA-regulated institutions that built patch SLAs around CVSS thresholds, this creates an immediate compliance and operational risk.
Compliance & RegulationOperation PowerOFF Dismantles 53 DDoS-for-Hire Platforms: A Wake-Up Call for Saudi Financial Institutions
Europol's Operation PowerOFF seized 53 DDoS booter domains and warned 75,000 users in April 2026. Here is what Saudi banks and financial institutions must do to meet SAMA CSCC and NCA ECC availability requirements.