Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

CVE-2026-27681: The CVSS 9.9 SAP Flaw That Puts Saudi Financial Data at Risk Right Now

A CVSS 9.9 SQL injection vulnerability in SAP Business Planning and Consolidation allows a low-privileged attacker to execute arbitrary database commands — a direct threat to the financial planning systems of Saudi SAMA-regulated institutions running SAP.

18 Apr 2026 5 min
Compliance & Regulation

NIST Stops Enriching Most CVEs: Saudi Financial Institutions Must Rebuild Their Vulnerability Management Strategy Now

On April 15, 2026, NIST quietly changed the rules of vulnerability management. Most CVEs will no longer receive severity scores or product details from NVD — and Saudi financial institutions that rely on NVD enrichment for SAMA CSCC compliance are directly exposed.

18 Apr 2026 5 min
Vulnerabilities

CVE-2026-32201: Microsoft SharePoint Zero-Day Added to CISA KEV — Saudi Financial Institutions Must Patch Now

Microsoft's April 2026 Patch Tuesday confirmed active exploitation of CVE-2026-32201, a SharePoint Server spoofing zero-day now on CISA's KEV list. Saudi banks and financial firms relying on SharePoint for document management face credential theft and phishing risk until patched.

18 Apr 2026 5 min
Vulnerabilities

CVE-2026-34197: A 13-Year-Old Apache ActiveMQ RCE Now on CISA's Most-Wanted List — Saudi Financial Middleware at Risk

CISA has added CVE-2026-34197 — a 13-year-old RCE flaw in Apache ActiveMQ Classic — to its Known Exploited Vulnerabilities catalog. Active exploitation is peaking now, and Saudi financial institutions running ActiveMQ in payment or integration middleware must act before April 30.

17 Apr 2026 5 min
Vulnerabilities

CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Under Active Exploitation — A Direct Risk for Saudi Financial Endpoint Security

A critical pre-authentication bypass in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.1) is being actively exploited in the wild. Saudi financial institutions relying on Fortinet for endpoint management must act now — CISA already mandated a patch deadline that has passed.

17 Apr 2026 5 min
Vulnerabilities

April 2026 Patch Tuesday: The Wormable Windows TCP/IP Flaw (CVE-2026-33827) Saudi Financial Teams Cannot Delay

Microsoft's second-largest Patch Tuesday ever drops 168 fixes, including a wormable TCP/IP RCE (CVSS 9.8) and an Active Directory flaw targeting every Windows Server from 2012 R2 to 2025. Here's what Saudi financial CISOs must patch first and why.

16 Apr 2026 5 min
Vulnerabilities

Cisco Patches Four Critical Flaws (CVSS 9.9) in ISE and Webex — Saudi Financial Networks Face Immediate NAC and Collaboration Risk

Cisco has disclosed four critical vulnerabilities — CVSS scores reaching 9.9 — in Identity Services Engine and Webex. For Saudi financial institutions running Cisco ISE as their NAC backbone, these flaws represent a direct path to full network compromise and unauthorized user impersonation.

16 Apr 2026 5 min
Vulnerabilities

EngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps

Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.

16 Apr 2026 6 min
Vulnerabilities

CVE-2026-5281: Chrome's Fourth Zero-Day of 2026 Targets WebGPU — Every Saudi Financial Institution's Browser Is at Risk

Google's fourth Chrome zero-day of 2026 exploits Dawn's WebGPU layer to escape the browser sandbox. Every unpatched Chromium-based browser in your environment is a live threat vector.

16 Apr 2026 5 min
Vulnerabilities

CVE-2026-34621: Adobe Acrobat Zero-Day Exploited Since November 2025 — A Wake-Up Call for Saudi Financial PDF Workflows

Adobe's emergency patch for CVE-2026-34621 revealed five months of silent exploitation inside your PDF reader. For Saudi banks and financial institutions that live and breathe PDF documents, the risk is immediate and regulatory implications are real.

16 Apr 2026 6 min
Vulnerabilities

Critical FortiSandbox Flaws CVE-2026-39808 & CVE-2026-39813: Unauthenticated RCE That Saudi Financial Teams Cannot Afford to Miss

Fortinet disclosed two CVSS 9.1 vulnerabilities in FortiSandbox on April 15, 2026 — CVE-2026-39808 and CVE-2026-39813 — enabling unauthenticated code execution and privilege escalation. Saudi banks relying on FortiSandbox for SAMA CSCC-mandated malware detection must patch now.

16 Apr 2026 5 min
Vulnerabilities

Microsoft April 2026 Patch Tuesday: CVE-2026-33824 Windows IKE CVSS 9.8 Demands Immediate Action from Saudi Financial Institutions

167 vulnerabilities patched in one update cycle — including a CVSS 9.8 unauthenticated RCE in Windows IKE. Here's exactly what SAMA-regulated institutions must prioritize before this week ends.

15 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality