Topic
Network & Infrastructure
Firewalls, VPNs, intrusion detection and zero trust — the network edge where most intrusions begin.
59 articles in this topic
Cisco Patches Four Critical Flaws (CVSS 9.9) in ISE and Webex — Saudi Financial Networks Face Immediate NAC and Collaboration Risk
Cisco has disclosed four critical vulnerabilities — CVSS scores reaching 9.9 — in Identity Services Engine and Webex. For Saudi financial institutions running Cisco ISE as their NAC backbone, these flaws represent a direct path to full network compromise and unauthorized user impersonation.
VulnerabilitiesCVE-2026-35616: Fortinet FortiClient EMS Zero-Day Now Actively Exploited — Urgent Action Required for Saudi Financial Institutions
A CVSS 9.1 zero-day in Fortinet FortiClient EMS allows unauthenticated attackers to execute code on your endpoint management server — and exploitation has been recorded in the wild since March 31, 2026.
VulnerabilitiesCVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet
A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.
VulnerabilitiesCVE-2026-21643: Fortinet FortiClient EMS Pre-Auth SQL Injection — CISA's 72-Hour Deadline and What Saudi Financial CISOs Must Do Before April 16
CISA confirmed active exploitation of CVE-2026-21643, a CVSS 9.1 pre-auth SQL injection in FortiClient EMS 7.4.4, on April 13 — giving organizations just 72 hours to patch or mitigate. Saudi banks running multi-tenant Fortinet EMS deployments are directly in the crosshairs.
VulnerabilitiesSeven in One Blow: CISA's April 13 KEV Update Targets Exchange, Fortinet & Adobe — Saudi Bank Patch Roadmap
CISA added 7 actively exploited vulnerabilities to its KEV catalog on April 13, 2026 — including Fortinet SQL injection, Adobe Acrobat prototype pollution, and Microsoft Exchange deserialization. Saudi financial institutions have until May 4 to comply.
VulnerabilitiesCVE-2026-35616: The Fortinet FortiClient EMS Zero-Day That CISA Just Added to Its Most-Wanted List
CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on April 6, 2026. This CVSS-9.1 Fortinet FortiClient EMS flaw has been under active attack since March 31 — Saudi financial institutions must act before the window closes.
VulnerabilitiesIvanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340: Mass Exploitation Threatens Saudi Bank Mobile Fleets
Two chained Ivanti EPMM zero-days scored CVSS 9.8 are under mass exploitation, giving attackers unauthenticated remote code execution on MDM servers that manage thousands of corporate mobile devices — including those in Saudi financial institutions.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Auth Bypass Puts Saudi Bank Server Infrastructure at Risk
A single crafted HTTP request can hand an attacker full admin access to your Cisco UCS servers. CVE-2026-20093 scores 9.8 CVSS and has no workaround — only a firmware update. Here's what Saudi bank infrastructure teams must do right now.
VulnerabilitiesInterlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure — Saudi Banks Must Audit Now
Interlock ransomware weaponized a CVSS 10.0 Cisco Firewall Management Center flaw for over a month before Cisco disclosed it. Saudi banks relying on Cisco firewalls face immediate exposure — here is what your SOC team must do today.
Breaches & Data LeaksShinyHunters Claims 3M+ Cisco Salesforce Records: The CRM Security Crisis Saudi Banks Must Act On Now
ShinyHunters claims 3 million Cisco Salesforce records stolen — FBI, NASA, and government agency data included. Saudi financial institutions using Cisco products face cascading vendor risk right now.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Authentication Bypass Puts Saudi Bank Data Centers at Risk — Patch Now
A critical authentication bypass in Cisco IMC (CVE-2026-20093, CVSS 9.8) lets unauthenticated remote attackers seize admin access with no workaround available. Saudi financial institutions relying on Cisco UCS infrastructure must patch firmware immediately.
VulnerabilitiesCVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now
A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.