Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

231 articles in this topic

Vulnerabilities

Google Detects First AI-Generated Zero-Day Exploit in the Wild

Google confirms the first zero-day exploit built using artificial intelligence was caught in the wild — a semantic logic flaw designed to bypass two-factor authentication. Here's what it means for Saudi financial institutions.

20 May 2026 5 min
Vulnerabilities

YellowKey & GreenPlasma: Unpatched Windows Zero-Days Bypass BitLocker and Escalate to SYSTEM

A disgruntled researcher dropped PoC exploits for two unpatched Windows zero-days — one bypasses BitLocker, the other grants SYSTEM privileges via CTFMON. No CVEs, no patches, full impact.

20 May 2026 5 min
Vulnerabilities

SEPPMail CVSS 10.0 RCE Chain: Four Flaws Turn Your Email Encryption Gateway into an Open Door

Four chained vulnerabilities in SEPPMail Secure E-Mail Gateway — headlined by a CVSS 10.0 path traversal to RCE — let attackers read every encrypted email and persist on the appliance indefinitely. Saudi financial institutions must patch immediately.

20 May 2026 4 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Actively Exploited — Sixth Zero-Day This Year

Cisco's sixth SD-WAN zero-day in 2026 carries a perfect CVSS 10.0 score and is already being exploited by an advanced threat actor. Saudi financial institutions running SD-WAN fabrics face immediate risk.

20 May 2026 5 min
Vulnerabilities

Drupal Highly Critical Zero-Auth Flaw Drops Today: Patch Your Portals Before Exploits Land

Drupal drops a severity-20 patch today — zero authentication, full database access. Saudi financial institutions must patch before exploits land within hours.

20 May 2026 5 min
Vulnerabilities

Four Word RCE Flaws Turn Outlook Preview Pane into an Attack Surface

Microsoft's May 2026 Patch Tuesday disclosed four Word RCE flaws exploitable through Outlook's preview pane — no clicks, no macros, no warnings. Here's what Saudi CISOs must do now.

20 May 2026 5 min
Vulnerabilities

CVE-2026-42945: Critical NGINX Heap Overflow Under Active Exploitation Threatens Every Saudi Enterprise

An 18-year-old flaw in NGINX's rewrite module — CVE-2026-42945 (CVSS 9.2) — is now actively exploited. With NGINX powering the majority of Saudi enterprise web infrastructure, here's what your security team must do immediately.

20 May 2026 5 min
Vulnerabilities

CVE-2026-41940: cPanel Zero-Day Authentication Bypass Exposes 1.5 Million Servers to Full Takeover

A CRLF injection flaw in cPanel & WHM let attackers forge root sessions for two months before anyone noticed. With 1.5 million exposed instances globally, Saudi financial institutions hosting client portals and payment gateways on cPanel infrastructure face immediate risk.

20 May 2026 5 min
Vulnerabilities

First AI-Generated Zero-Day Exploit Caught in the Wild: What Saudi Financial CISOs Must Know

Google confirms the first AI-generated zero-day exploit used by criminal hackers — a 2FA bypass built by an LLM. What this means for Saudi financial institutions and how CISOs should respond.

19 May 2026 5 min
Vulnerabilities

Windows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public

A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.

19 May 2026 5 min
Vulnerabilities

CVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence

A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.

19 May 2026 5 min
Vulnerabilities

CVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack

Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.

19 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality