Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

231 articles in this topic

Vulnerabilities

Pwn2Own Berlin 2026: 47 Zero-Days in Enterprise Tech Expose What Scanners Miss

47 zero-days across Exchange, SharePoint, VMware ESXi, and AI platforms — $1.3M in bounties at Pwn2Own Berlin 2026. What the results mean for Saudi financial institutions and their 90-day patch window.

19 May 2026 6 min
Vulnerabilities

Microsoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action

Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.

19 May 2026 6 min
Vulnerabilities

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables RCE on Millions of Servers

A critical double-free vulnerability in Apache HTTP Server's HTTP/2 module lets attackers crash or hijack servers with just two network frames. Here's what Saudi financial institutions need to do now.

18 May 2026 6 min
Vulnerabilities

Funnel Builder WordPress Exploit: How Attackers Steal Payment Data from 40,000+ WooCommerce Stores

A critical flaw in the Funnel Builder WordPress plugin is being actively exploited to plant JavaScript skimmers on WooCommerce checkout pages, stealing cardholder data in real time. Here's what Saudi merchants and financial institutions need to know.

18 May 2026 5 min
Vulnerabilities

Google Confirms First AI-Built Zero-Day Exploit: 2FA Bypass Signals a New Threat Era

Google's Threat Intelligence Group has confirmed the first real-world zero-day exploit built entirely by AI — a 2FA bypass that rewrites the rules for Saudi financial institutions relying on multi-factor authentication as a compliance checkbox.

18 May 2026 5 min
Artificial Intelligence

Claw Chain: Four OpenClaw Flaws Let Attackers Hijack AI Agents from Inside the Sandbox

Four chainable vulnerabilities in OpenClaw AI agent platform — dubbed Claw Chain — allow sandbox escape, data theft, and persistent backdoors across 245,000 exposed servers. Critical implications for Saudi financial institutions under SAMA CSCC.

18 May 2026 5 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN CVSS 10.0 Auth Bypass Under Active Exploitation

A perfect-score CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN is being actively exploited by UAT-8616. If your WAN fabric runs on Cisco, this is not optional reading.

18 May 2026 5 min
Vulnerabilities

NGINX Rift (CVE-2026-42945): 18-Year-Old RCE Flaw Now Actively Exploited in the Wild

CVE-2026-42945 — an 18-year-old heap buffer overflow in NGINX's rewrite module — is now actively exploited with a public PoC. Here's what Saudi financial CISOs must do before attackers reach the DMZ.

18 May 2026 4 min
Network & Infrastructure

CVE-2026-0300: Critical PAN-OS Buffer Overflow Grants Root Access to Palo Alto Firewalls

A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild, giving attackers root-level code execution on PA-Series and VM-Series firewalls. Here is what Saudi financial CISOs must do now.

18 May 2026 6 min
Vulnerabilities

YellowKey and GreenPlasma: Unpatched Windows Zero-Days That Bypass BitLocker and Grant SYSTEM Access

A disgruntled researcher dropped two unpatched Windows zero-days with public PoCs: YellowKey defeats BitLocker with a USB stick, and GreenPlasma escalates any user to SYSTEM. Here's what Saudi CISOs need to act on immediately.

18 May 2026 5 min
Software Engineering

Grafana GitHub Token Breach: CI/CD Pipeline Flaw Exposes Source Code to Extortion

Grafana Labs lost its entire source code after an attacker exploited a GitHub Actions misconfiguration. Learn how CI/CD pipeline vulnerabilities threaten Saudi financial institutions and what SAMA CSCC demands.

18 May 2026 5 min
Vulnerabilities

Fragnesia (CVE-2026-46300): Linux Kernel Flaw Grants Root Access via Page Cache Corruption

A new Linux kernel privilege escalation vulnerability, Fragnesia (CVE-2026-46300), grants root access via page cache corruption with a public PoC. Learn why Saudi financial institutions must patch immediately.

18 May 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality