Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

CVE-2026-34197: 13-Year-Old ActiveMQ RCE Threatens Saudi Banks

CISA added Apache ActiveMQ CVE-2026-34197 (CVSS 8.8) to KEV with an April 30 deadline. With 6,000+ exposed instances and active exploitation, Saudi financial institutions must act now under SAMA CSCC.

30 Apr 2026 4 min
Vulnerabilities

CVE-2026-33824: Windows IKE Zero-Day Threatens Saudi Bank VPNs

An unauthenticated attacker can take over Windows IKE/IPsec VPN servers via UDP 500/4500 — CVSS 9.8. Saudi banks running Windows IKEv2 must patch immediately.

30 Apr 2026 4 min
Vulnerabilities

EngageLab SDK Flaw Exposes 50M Android Users — Saudi Mobile Banking on Alert

A third-party push-notification SDK quietly added an exported activity to 50 million Android installs, including 30 million crypto wallets. Here is what every Saudi bank's mobile security team needs to verify this week.

30 Apr 2026 5 min
Vulnerabilities

CVE-2026-32202: Windows Shell Zero-Click NTLM Leak Hits Saudi Banks

A zero-click Windows Shell flaw silently leaks NTLMv2 hashes the moment a user browses a folder. Saudi financial institutions under SAMA CSCC must patch CVE-2026-32202 by May 12 to avoid credential theft and lateral movement across Active Directory.

29 Apr 2026 4 min
Vulnerabilities

CVE-2026-3854: A Single Git Push Hijacks GitHub — Saudi Banks at Risk

A single git push can now grant full remote code execution on GitHub Enterprise Server. For Saudi financial institutions running internal repositories, CVE-2026-3854 is more than a DevOps incident — it is a SAMA CSCC source-code protection breach waiting to happen.

29 Apr 2026 4 min
Vulnerabilities

CVE-2026-34621: Adobe Reader Zero-Day Targets Saudi Financial PDFs

CVE-2026-34621, an actively exploited Adobe Acrobat Reader zero-day, enables arbitrary code execution via weaponized PDFs. Saudi banks and fintechs face immediate endpoint and SAMA CSCC exposure.

20 Apr 2026 4 min
Vulnerabilities

CVE-2026-32201: SharePoint Zero-Day Exploited — A Direct Threat to Saudi Banks

Microsoft's April 2026 Patch Tuesday fixed 167 flaws — but one actively exploited SharePoint zero-day demands urgent attention from every Saudi bank's CISO and SAMA compliance team.

19 Apr 2026 4 min
Vulnerabilities

CVE-2026-1281 & CVE-2026-1340: The Ivanti EPMM Zero-Days Putting Saudi Bank MDM Fleets at Risk

A single bulletproof-hosted IP is driving 83% of active Ivanti EPMM exploitation via CVE-2026-1281 and CVE-2026-1340. Saudi banks running on-prem MDM face direct SAMA CSCC exposure — here is what to patch, hunt, and rotate now.

19 Apr 2026 4 min
Vulnerabilities

CVE-2026-34197: The 13-Year-Old Apache ActiveMQ Flaw Now Under Active Exploitation — Saudi Financial Institutions Have Until April 30

A 13-year-old RCE flaw in Apache ActiveMQ Classic is now actively exploited via the Jolokia API. CISA added CVE-2026-34197 to its KEV catalog with a federal deadline of April 30. Here's what Saudi financial institutions need to do now.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-21643: The Fortinet FortiClient EMS Zero-Auth SQL Injection CISA Is Flagging — Action Required for Saudi Financial Institutions

CISA confirmed active exploitation of CVE-2026-21643 on April 13, 2026 — a pre-authentication SQL injection in Fortinet FortiClient EMS with a CVSS score of 9.1. Saudi financial institutions running affected versions must patch immediately or face direct risk of unauthorized remote code execution with no credentials required.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-34621: The Adobe Acrobat Zero-Day Hidden in Your Financial Institution's PDF Workflow

A critical zero-day in Adobe Acrobat Reader is being weaponized through invoice-themed PDFs targeting financial institutions. CISA's April 27 deadline is live — here's what Saudi CISOs must do immediately.

19 Apr 2026 5 min
Vulnerabilities

CVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face

A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.

18 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality