Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
231 articles in this topic
CVE-2026-35616: The Fortinet FortiClient EMS Zero-Day That CISA Just Added to Its Most-Wanted List
CISA added CVE-2026-35616 to its Known Exploited Vulnerabilities catalog on April 6, 2026. This CVSS-9.1 Fortinet FortiClient EMS flaw has been under active attack since March 31 — Saudi financial institutions must act before the window closes.
RansomwareStorm-1175 Deploys Medusa Ransomware in 24 Hours Using Zero-Days in GoAnywhere and SmarterMail
Microsoft's April 2026 alert: Storm-1175 weaponized zero-days in GoAnywhere MFT and SmarterMail to encrypt victim networks within 24 hours — a direct threat to Saudi financial institutions relying on MFT platforms for SAMA-regulated data transfers.
VulnerabilitiesReact2Shell (CVE-2025-55182): The CVSS-10 Flaw Silently Draining API Keys from Financial Web Apps
A CVSS-10 flaw in React Server Components has enabled threat actor UAT-10608 to silently harvest credentials from 766+ hosts. Saudi financial institutions running Next.js-based portals face immediate exposure.
VulnerabilitiesTrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers
CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.
VulnerabilitiesIvanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340: Mass Exploitation Threatens Saudi Bank Mobile Fleets
Two chained Ivanti EPMM zero-days scored CVSS 9.8 are under mass exploitation, giving attackers unauthenticated remote code execution on MDM servers that manage thousands of corporate mobile devices — including those in Saudi financial institutions.
VulnerabilitiesChrome Zero-Day CVE-2026-5281: WebGPU Exploit Chain Threatens Saudi Financial Institutions
Google's fourth zero-day of 2026 targets Chrome's WebGPU layer via a use-after-free in Dawn. CISA added it to the KEV catalog — here's what Saudi banks and financial institutions must do now.
VulnerabilitiesProgress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now
Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Auth Bypass Puts Saudi Bank Server Infrastructure at Risk
A single crafted HTTP request can hand an attacker full admin access to your Cisco UCS servers. CVE-2026-20093 scores 9.8 CVSS and has no workaround — only a firmware update. Here's what Saudi bank infrastructure teams must do right now.
VulnerabilitiesInterlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure — Saudi Banks Must Audit Now
Interlock ransomware weaponized a CVSS 10.0 Cisco Firewall Management Center flaw for over a month before Cisco disclosed it. Saudi banks relying on Cisco firewalls face immediate exposure — here is what your SOC team must do today.
VulnerabilitiesMicrosoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now
Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.
VulnerabilitiesFortiClient EMS Zero-Day CVE-2026-35616: CVSS 9.1 Pre-Auth RCE Under Active Exploitation
Fortinet's emergency hotfix for CVE-2026-35616 confirms active zero-day exploitation of FortiClient EMS. Saudi banks running versions 7.4.5–7.4.6 face unauthenticated remote code execution risk.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Authentication Bypass Puts Saudi Bank Data Centers at Risk — Patch Now
A critical authentication bypass in Cisco IMC (CVE-2026-20093, CVSS 9.8) lets unauthenticated remote attackers seize admin access with no workaround available. Saudi financial institutions relying on Cisco UCS infrastructure must patch firmware immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers