Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
CVE-2026-35616: Fortinet FortiClient EMS Zero-Day Now Actively Exploited — Urgent Action Required for Saudi Financial Institutions
A CVSS 9.1 zero-day in Fortinet FortiClient EMS allows unauthenticated attackers to execute code on your endpoint management server — and exploitation has been recorded in the wild since March 31, 2026.
VulnerabilitiesSharePoint Zero-Day CVE-2026-32201: CISA KEV Alert Hits Saudi Banks
CISA's April 14 double-alert: a SharePoint zero-day (CVE-2026-32201) and a resurrected 2009 Office flaw prove old vulnerabilities never die. Saudi banks have a 13-day patch window — here's your action plan.
VulnerabilitiesCVE-2026-40261 & CVE-2026-40176: PHP Composer's Hidden Command Injection Risk — What Saudi Fintech Dev Teams Must Patch Now
Two command injection flaws in PHP Composer's Perforce VCS driver allow arbitrary code execution — no Perforce installation required. Saudi financial development teams still running Composer 2.0–2.9.5 are exposed right now.
VulnerabilitiesCVE-2026-25075: The 15-Year strongSwan Flaw That Can Crash Saudi Banks' VPN With One Packet
A single malformed EAP-TTLS packet can crash strongSwan VPN servers across 15+ years of releases. Saudi banks relying on IPsec/IKEv2 tunnels for branch and remote-access connectivity must patch CVE-2026-25075 to avoid an unauthenticated denial-of-service that SAMA CSCC classifies as a critical availability risk.
Malware & Threat ActorsCVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys
Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.
VulnerabilitiesCVE-2026-21643: Fortinet FortiClient EMS Pre-Auth SQL Injection — CISA's 72-Hour Deadline and What Saudi Financial CISOs Must Do Before April 16
CISA confirmed active exploitation of CVE-2026-21643, a CVSS 9.1 pre-auth SQL injection in FortiClient EMS 7.4.4, on April 13 — giving organizations just 72 hours to patch or mitigate. Saudi banks running multi-tenant Fortinet EMS deployments are directly in the crosshairs.
VulnerabilitiesSeven in One Blow: CISA's April 13 KEV Update Targets Exchange, Fortinet & Adobe — Saudi Bank Patch Roadmap
CISA added 7 actively exploited vulnerabilities to its KEV catalog on April 13, 2026 — including Fortinet SQL injection, Adobe Acrobat prototype pollution, and Microsoft Exchange deserialization. Saudi financial institutions have until May 4 to comply.
VulnerabilitiesCVE-2026-39987: Marimo's Pre-Auth RCE Was Weaponized in Under 10 Hours — What Saudi AI Analytics Teams Must Do Now
A critical pre-authenticated RCE in Marimo (CVE-2026-39987, CVSS 9.3) was actively exploited just 9 hours 41 minutes after public disclosure — before any PoC existed. Saudi financial institutions using AI analytics pipelines must act immediately.
VulnerabilitiesCVE-2026-3502: The TrueConf Flaw Saudi Banks Must Patch by April 16
CISA added CVE-2026-3502 to its KEV catalog on April 2. The TrueConf Client flaw allows attackers to hijack software updates and deploy the Havoc C2 framework — a critical risk for Saudi banks using TrueConf for communications.
VulnerabilitiesCVE-2026-35616: The Fortinet FortiClient EMS Zero-Day That CISA Just Added to Its Most-Wanted List
CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on April 6, 2026. This CVSS-9.1 Fortinet FortiClient EMS flaw has been under active attack since March 31 — Saudi financial institutions must act before the window closes.
RansomwareStorm-1175 Deploys Medusa Ransomware in 24 Hours Using Zero-Days in GoAnywhere and SmarterMail
Microsoft's April 2026 alert: Storm-1175 weaponized zero-days in GoAnywhere MFT and SmarterMail to encrypt victim networks within 24 hours — a direct threat to Saudi financial institutions relying on MFT platforms for SAMA-regulated data transfers.
VulnerabilitiesReact2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps
A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers