Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

CVE-2025-32975: Quest KACE SMA Auth Bypass Hits Saudi Bank Endpoint Management

A CVSS 10.0 pre-authentication bypass in Quest KACE SMA is being actively exploited. For Saudi banks running KACE for patching and inventory, the blast radius reaches every managed endpoint. Here is what SAMA-regulated CISOs must do this week.

1 May 2026 4 min
Vulnerabilities

CVE-2026-33825: Microsoft Defender Privilege Escalation Hits Saudi Bank Endpoints

Microsoft Defender's CVE-2026-33825 (CVSS 7.8) is being actively exploited as a zero-day for local privilege escalation. Here's what Saudi banks running Defender for Endpoint must do under SAMA CSCC.

1 May 2026 4 min
Vulnerabilities

CVE-2026-34197: Apache ActiveMQ RCE Threatens Saudi Bank Transaction Brokers

A critical Apache ActiveMQ flaw (CVE-2026-34197, CVSS 8.8) is actively exploited via the Jolokia API, threatening transaction message brokers across Saudi banks. CISA KEV deadline expires this week.

1 May 2026 4 min
Vulnerabilities

CVE-2026-1089: GoAnywhere MFT Header Flaw Hits Saudi Bank File Transfer Tier

An unauthenticated information disclosure flaw in Fortra GoAnywhere MFT (CVE-2026-1089) lets remote attackers trigger DNS lookups and rebinding attacks against Saudi bank file transfer infrastructure — a known Cl0p target.

1 May 2026 4 min
Vulnerabilities

CVE-2026-33032 'MCPwn': Nginx-UI Bypass Hits Saudi Bank Web Tier

A one-line missing middleware check in nginx-ui (CVE-2026-33032 'MCPwn') hands attackers full Nginx server takeover. Saudi banks running Nginx edge proxies must patch and hunt — exploitation is already live in the wild.

1 May 2026 4 min
Vulnerabilities

CVE-2026-34621: Adobe Reader Zero-Day Hits Saudi Bank PDF Workflows

Adobe rushed an emergency fix for CVE-2026-34621, an Acrobat Reader prototype pollution flaw exploited via weaponized PDFs since late 2025. For Saudi banks where PDF is the universal currency of statements, KYC, and regulatory filings, the patch window has already closed under SAMA CSCC and CISA KEV mandates.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Threatens Saudi Bank Intranets

Microsoft's actively exploited SharePoint zero-day CVE-2026-32201 puts Saudi bank intranets and document portals at risk. Over 1,300 servers remain exposed. Here is what Saudi CISOs must do now under SAMA CSCC.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-27681: SAP BPC SQL Injection Endangers Saudi Bank Regulatory Reporting

A CVSS 9.9 SQL injection flaw in SAP Business Planning and Consolidation lets low-privileged users alter financial data — a direct threat to SAMA reporting integrity at Saudi banks.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-4112: SonicWall SMA1000 SQL Injection Threatens Saudi Bank VPNs

A newly disclosed SonicWall SMA1000 SQL injection flaw (CVE-2026-4112) lets read-only administrators escalate to primary admin and seize bank VPN gateways. Saudi financial institutions must act under SAMA CSCC.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-21643: FortiClient EMS Pre-Auth RCE Hits Saudi Banks

A pre-auth SQL injection in Fortinet FortiClient EMS 7.4.4 (CVSS 9.8) escalates to full host RCE via PostgreSQL superuser abuse. CISA KEV-listed and actively exploited — direct impact on SAMA-regulated Saudi banks.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-20147: Cisco ISE RCE Chain Hits Saudi Bank NAC Backbone

Three critical Cisco ISE vulnerabilities allow authenticated attackers to escalate to root on the very appliance that authorizes every device on a Saudi bank's network — a direct hit on SAMA CSCC segmentation and NCA ECC identity controls.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-33825 "BlueHammer": Defender LPE Threatens Saudi Banks

BlueHammer (CVE-2026-33825): an actively exploited Microsoft Defender LPE flaw that bypasses endpoint defenses on Saudi bank workstations. Patch under SAMA CSCC.

30 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality