Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

ASP.NET Core CVE-2026-40372: Forged Cookie Threat to SAMA Banks

Microsoft released an out-of-band patch for CVE-2026-40372, a CVSS 9.1 ASP.NET Core flaw that lets attackers forge auth cookies and gain SYSTEM. Direct risk to SAMA bank apps.

6 May 2026 4 min
Network & Infrastructure

CVE-2026-0227: PAN-OS GlobalProtect DoS Threat to SAMA Banks

An unauthenticated DoS flaw in PAN-OS GlobalProtect can force Saudi bank firewalls into maintenance mode. Here's what SAMA-regulated CISOs must do before exploitation goes mainstream.

6 May 2026 4 min
Vulnerabilities

CVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks

Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.

5 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: SAMA Bank Web Tier and Vendor Risk

CVE-2026-41940 is a CVSS 9.8 cPanel authentication bypass actively weaponised against 1.5M servers worldwide. Here is the SAMA-aligned response Saudi banks need now.

5 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 RCE: SAMA Bank Web Tier Risk

Apache shipped 2.4.67 on May 4, 2026 to fix CVE-2026-23918, an HTTP/2 double-free enabling RCE on millions of servers. Saudi banks face direct exposure on internet-facing web tiers under SAMA CSCC.

5 May 2026 4 min
Cloud & Identity

CVE-2026-42354: Sentry SAML SSO Bypass Threatens SAMA Bank IAM

A critical Sentry SAML SSO bypass (CVE-2026-42354) enables full account takeover with only the victim's email address. Saudi financial institutions relying on federated identity must act now to align with SAMA CSCC IAM controls.

5 May 2026 4 min
Vulnerabilities

CVE-2026-42779: Apache MINA Deserialization RCE Hits SAMA Banks

A critical Apache MINA deserialization flaw (CVE-2026-42779, CVSS 9.8) bypasses classname allowlists and enables unauthenticated RCE in financial messaging systems. SAMA CSCC patch guidance inside.

5 May 2026 4 min
Vulnerabilities

SonicWall CVE-2026-0204 Triad: Firewall Risk for SAMA Banks

SonicWall's April 29, 2026 advisory disclosed three SonicOS flaws — access bypass, path traversal, and a remote crash — directly threatening the perimeter of SAMA-regulated banks. Here is what Saudi CISOs must do this week.

5 May 2026 4 min
Vulnerabilities

Fortinet CVE-2026-24858: FortiCloud SSO Bypass Hits SAMA Banks

Fortinet's CVE-2026-24858 lets attackers bypass FortiCloud SSO and seize admin control over FortiOS, FortiManager, and FortiProxy. Why SAMA-regulated banks must act before patches arrive.

5 May 2026 4 min
Vulnerabilities

MOVEit CVE-2026-4670 Auth Bypass: SAMA Bank File Transfer Risk

Progress Software patched a critical MOVEit Automation auth bypass (CVE-2026-4670) that exposes credentials and financial files. Saudi banks must act before exploitation hits SAMA-regulated MFT flows.

5 May 2026 4 min
Vulnerabilities

BlueHammer CVE-2026-33825: Defender Zero-Day Hits SAMA Banks

A leaked Microsoft Defender exploit known as BlueHammer (CVE-2026-33825) escalates any unprivileged user to SYSTEM on fully patched Windows. What SAMA-regulated banks must do now to stay aligned with CSCC endpoint controls.

5 May 2026 4 min
Vulnerabilities

CVE-2026-3854: GitHub RCE Threatens SAMA Bank Source Code

A single crafted git push gave attackers cross-tenant RCE on GitHub, exposing millions of private repositories. With 88% of self-hosted GHES still vulnerable, SAMA-regulated banks face a direct threat to their source code crown jewels and CSCC compliance posture.

4 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality