Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

231 articles in this topic

Vulnerabilities

CVE-2026-41940: cPanel Zero-Day Exploited for Months Puts 1.5 Million Servers at Risk

A CVSS 9.8 authentication bypass in cPanel & WHM was exploited as a zero-day for two months before patching. With 1.5M servers exposed, Saudi financial institutions must act now.

21 May 2026 5 min
Vulnerabilities

MiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines

A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.

21 May 2026 5 min
Vulnerabilities

SEPPmail Gateway Flaws CVE-2026-2743: When Your Email Security Becomes the Attack Vector

Seven critical SEPPMail flaws — including CVSS 10.0 RCE — turn secure email gateways into wiretaps. Here's what Saudi financial institutions must do now.

21 May 2026 5 min
Vulnerabilities

CVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines

A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.

21 May 2026 4 min
Vulnerabilities

YellowKey BitLocker Bypass CVE-2026-45585: A USB Drive Is All It Takes to Unlock Your Encrypted Data

A researcher's frustration with Microsoft's bug bounty process led to the public release of YellowKey — a BitLocker bypass that decrypts protected volumes with nothing more than a USB stick and a reboot. Here's what Saudi financial institutions need to do right now.

21 May 2026 6 min
Vulnerabilities

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Crashes Servers and Opens the Door to RCE

Critical Apache HTTP/2 double-free vulnerability CVE-2026-23918 is actively exploited for DoS with RCE potential. Saudi financial institutions must patch to 2.4.67 immediately to meet SAMA CSCC and NCA ECC requirements.

21 May 2026 5 min
Vulnerabilities

CVE-2026-31431 Copy Fail: 732 Bytes to Root on Every Linux Server Since 2017

A 732-byte Python script can root nearly every Linux distribution shipped since 2017. CVE-2026-31431 exploits a logic flaw in the kernel's crypto API — and it escapes containers too.

21 May 2026 5 min
Vulnerabilities

Drupal SA-CORE-2026-004: No-Auth SQL Injection Threatens Every PostgreSQL-Backed Site

Drupal released emergency patches for a highly critical SQL injection that requires zero authentication. If your organization runs Drupal on PostgreSQL, you have hours — not days — before weaponized exploits hit the wild.

21 May 2026 6 min
Vulnerabilities

CVE-2026-42897: Exchange Server Zero-Day Turns Your Inbox Into an Attack Surface

Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS flaw in Exchange Server OWA. No patch available yet — here's what Saudi financial institutions must do now.

21 May 2026 5 min
Vulnerabilities

CVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click

Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.

21 May 2026 5 min
Vulnerabilities

CVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi

A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.

21 May 2026 6 min
Vulnerabilities

CVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.

20 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality