Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
231 articles in this topic
CVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now
A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.
VulnerabilitiesCVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now
A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.
VulnerabilitiesF5 BIG-IP APM CVE-2025-53521: Unauthenticated RCE Puts 14,000+ Exposed Instances at Risk — What Saudi Banks Must Do Now
A critical F5 BIG-IP APM flaw reclassified from DoS to unauthenticated RCE is being actively exploited — with 14,000+ instances still exposed globally. Here is what Saudi financial institutions must patch immediately.
VulnerabilitiesChrome CVE-2026-5281: Fourth Zero-Day of 2026 Is Under Active Exploitation — What Saudi Financial Institutions Must Do Now
Google's fourth Chrome zero-day of 2026 is actively exploited in the wild. CVE-2026-5281 — a use-after-free in the Dawn WebGPU layer — allows remote code execution and is now on CISA's KEV list. Saudi banks running unpatched Chrome deployments face immediate exposure.
VulnerabilitiesstrongSwan CVE-2026-25075: 15-Year-Old VPN Flaw That Can Bring Down Your Financial Network
A critical integer underflow in strongSwan's EAP-TTLS plugin — present for 15 years — lets unauthenticated attackers crash VPN gateways. Here is what Saudi financial institutions need to know and do right now.
VulnerabilitiesCisco IMC CVE-2026-20093: Critical 9.8 Auth Bypass Threatens Data Center Infrastructure
Cisco discloses CVE-2026-20093, a CVSS 9.8 authentication bypass in IMC affecting UCS servers. Saudi financial institutions must patch immediately — one HTTP request can hijack admin access to your data center hardware.
VulnerabilitiesCritical Mbed TLS RCE Flaw CVE-2026-34877: ATMs, POS Terminals, and IoT at Risk
A CVSS 9.8 remote code execution flaw in Mbed TLS threatens the cryptographic backbone of ATMs, payment terminals, and embedded banking systems across Saudi Arabia's financial sector.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.
VulnerabilitiesCVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access
A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.
VulnerabilitiesCVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now
A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.
VulnerabilitiesChrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now
Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.