Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Hits SAMA Bank Collaboration

Microsoft confirms active exploitation of SharePoint zero-day CVE-2026-32201. Over 1,300 servers remain exposed online. Here is what SAMA-regulated banks must do this week to stay aligned with CSCC controls.

4 May 2026 4 min
Vulnerabilities

CVE-2026-0625: D-Link DSL Zero-Day Threatens SAMA Bank Edge

Active exploitation of CVE-2026-0625 in end-of-life D-Link DSL gateways enables DNS hijacking and remote code execution. SAMA banks must audit branch and home-office edge devices now.

4 May 2026 4 min
Vulnerabilities

CVE-2026-33824: Critical Windows IKE RCE Threatens SAMA Bank VPNs

Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-33824, a CVSS 9.8 unauthenticated RCE in Windows IKE Service Extensions. SAMA-regulated banks running IPSec VPNs must patch immediately.

4 May 2026 5 min
Vulnerabilities

FortiClient EMS CVE-2026-35616: Pre-Auth RCE Risk to SAMA Banks

CVE-2026-35616 in Fortinet FortiClient EMS allows pre-auth RCE on endpoint management servers across Saudi banks. Active exploitation confirmed by CISA — patch immediately under SAMA CSCC.

4 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: SAMA Bank Hosting Risk

A critical CRLF injection flaw (CVSS 9.8) lets unauthenticated attackers seize root on cPanel and WHM servers. Saudi banks face TPRM and hosting-supply-chain exposure. Here is the action plan.

4 May 2026 5 min
Vulnerabilities

Cisco SD-WAN Manager Exploited Trio (CVE-2026-20122/20128/20133): SAMA Bank Branch Risk

Three actively exploited Cisco Catalyst SD-WAN Manager vulnerabilities (CVE-2026-20122/20128/20133) place Saudi bank branch networks under immediate threat. Here is what SAMA-regulated CISOs must do this week.

4 May 2026 4 min
Vulnerabilities

Fortra GoAnywhere MFT Flaws: Pre-CVE Threat to SAMA Banks

New Fortra GoAnywhere MFT vulnerabilities expose Saudi banks' regulated file transfers. Darktrace observed pre-CVE exploitation. SAMA CSCC remediation guide for Saudi CISOs.

3 May 2026 4 min
Ransomware

ScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks

CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.

3 May 2026 4 min
Vulnerabilities

Copy Fail (CVE-2026-31431): 732-Byte Linux Root Escalation Hits Saudi Banks

A 732-byte Python script grants root on every major Linux distribution since 2017. CVE-2026-31431 'Copy Fail' threatens every Saudi bank's Linux infrastructure. Here's what SAMA CSCC requires now.

3 May 2026 5 min
Vulnerabilities

Ni8mare CVE-2026-21858: n8n RCE Threatens Saudi Bank AI Workflows

A CVSS 10.0 unauthenticated RCE in n8n webhook handling — dubbed Ni8mare — exposes the AI workflow automation platforms many Saudi banks now run for SOC orchestration and DevSecOps pipelines. Here is the SAMA CSCC patch path.

3 May 2026 4 min
Ransomware

CVE-2025-61882: Oracle EBS Clop Extortion Hits Saudi Banks

Clop is weaponizing Oracle EBS zero-day CVE-2025-61882 (CVSS 9.8) against insurers like Allianz UK. Saudi banks running EBS face direct SAMA CSCC and PDPL exposure.

3 May 2026 5 min
Vulnerabilities

SonicWall SonicOS Trio (CVE-2026-0204/0205/0206) Threatens Saudi Bank Perimeters

Three newly disclosed SonicOS vulnerabilities — including a CVSS 8.0 access-control bypass — put SonicWall Gen6/7/8 firewalls at risk across Saudi banking perimeters. Here is the SAMA CSCC remediation playbook.

3 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality