Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
ASP.NET Core CVE-2026-40372: Forged Cookie Threat to SAMA Banks
Microsoft released an out-of-band patch for CVE-2026-40372, a CVSS 9.1 ASP.NET Core flaw that lets attackers forge auth cookies and gain SYSTEM. Direct risk to SAMA bank apps.
Network & InfrastructureCVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks
An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.
VulnerabilitiesCVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks
Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.
VulnerabilitiescPanel CVE-2026-41940 Auth Bypass: SAMA Bank Web Tier and Vendor Risk
CVE-2026-41940 is a CVSS 9.8 cPanel authentication bypass actively weaponised against 1.5M servers worldwide. Here is the SAMA-aligned response Saudi banks need now.
VulnerabilitiesApache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk
Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.
Cloud & IdentityCVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM
A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.
VulnerabilitiesCVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks
A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.
VulnerabilitiesSonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks
SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.
VulnerabilitiesFortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks
Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.
VulnerabilitiesMOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk
Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.
VulnerabilitiesBlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks
A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.
VulnerabilitiesCVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code
A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers