Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
231 articles in this topic
CVE-2026-41940: cPanel Zero-Day Exploited for Months Puts 1.5 Million Servers at Risk
A CVSS 9.8 authentication bypass in cPanel & WHM was exploited as a zero-day for two months before patching. With 1.5M servers exposed, Saudi financial institutions must act now.
VulnerabilitiesMiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines
A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.
VulnerabilitiesSEPPmail Gateway Flaws CVE-2026-2743: When Your Email Security Becomes the Attack Vector
Seven critical SEPPMail flaws — including CVSS 10.0 RCE — turn secure email gateways into wiretaps. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines
A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.
VulnerabilitiesYellowKey BitLocker Bypass CVE-2026-45585: A USB Drive Is All It Takes to Unlock Your Encrypted Data
A researcher's frustration with Microsoft's bug bounty process led to the public release of YellowKey — a BitLocker bypass that decrypts protected volumes with nothing more than a USB stick and a reboot. Here's what Saudi financial institutions need to do right now.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Crashes Servers and Opens the Door to RCE
Critical Apache HTTP/2 double-free vulnerability CVE-2026-23918 is actively exploited for DoS with RCE potential. Saudi financial institutions must patch to 2.4.67 immediately to meet SAMA CSCC and NCA ECC requirements.
VulnerabilitiesCVE-2026-31431 Copy Fail: 732 Bytes to Root on Every Linux Server Since 2017
A 732-byte Python script can root nearly every Linux distribution shipped since 2017. CVE-2026-31431 exploits a logic flaw in the kernel's crypto API — and it escapes containers too.
VulnerabilitiesDrupal SA-CORE-2026-004: No-Auth SQL Injection Threatens Every PostgreSQL-Backed Site
Drupal released emergency patches for a highly critical SQL injection that requires zero authentication. If your organization runs Drupal on PostgreSQL, you have hours — not days — before weaponized exploits hit the wild.
VulnerabilitiesCVE-2026-42897: Exchange Server Zero-Day Turns Your Inbox Into an Attack Surface
Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS flaw in Exchange Server OWA. No patch available yet — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi
A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.
VulnerabilitiesCVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.