Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Enables Remote Code Execution on Millions of Servers

A critical double-free vulnerability in Apache HTTP Server 2.4.66's HTTP/2 module lets attackers crash workers or achieve full RCE — and millions of internet-facing servers remain unpatched.

17 May 2026 5 min
Vulnerabilities

Google Confirms First AI-Written Zero-Day Exploit: 2FA Bypass Weaponized for Mass Exploitation

Google GTIG confirms the first AI-written zero-day exploit bypassing 2FA on a widely used admin tool. Learn what this means for Saudi financial institutions and how to defend against AI-accelerated threats.

17 May 2026 5 min
Vulnerabilities

FunnelKit WooCommerce Checkout Skimmer: How a Plugin Flaw Turns Online Stores Into Card-Harvesting Traps

Attackers exploit a flaw in FunnelKit's WooCommerce plugin to inject invisible payment skimmers on 40,000+ checkout pages. Learn how this impacts PCI-DSS compliance and what Saudi merchants must do now.

17 May 2026 5 min
Vulnerabilities

OpenAI Daybreak: How AI-Powered Vulnerability Detection Changes the Game for Financial CISOs

OpenAI's Daybreak initiative uses GPT-5.5 to detect and patch vulnerabilities in minutes. Here's what Saudi financial CISOs need to know about AI-powered security operations.

17 May 2026 4 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction

An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.

17 May 2026 6 min
Vulnerabilities

CVE-2026-0073: Android Zero-Click RCE Lets Nearby Attackers Gain Shell Access Without User Interaction

Google patches a CVSS 9.8 zero-click RCE in Android's wireless ADB that lets nearby attackers gain full shell access — a direct threat to BYOD-enabled financial institutions.

17 May 2026 4 min
Artificial Intelligence

Critical Microsoft 365 Copilot Vulnerabilities: AI Assistants Become Data Exfiltration Vectors

Three critical CVEs in Microsoft 365 Copilot allow unauthorized data disclosure through AI injection attacks. Saudi financial institutions face compounded SAMA CSCC and PDPL compliance risks as AI assistants bypass traditional DLP controls.

17 May 2026 4 min
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN Zero-Day Gives Attackers Full Admin Access Without Credentials

A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller is under active exploitation, letting attackers seize full admin control of enterprise network fabrics without any credentials.

16 May 2026 4 min
Vulnerabilities

CVE-2026-42897: Actively Exploited Exchange Server Zero-Day Demands Immediate Action

Microsoft confirms active exploitation of CVE-2026-42897 in on-premises Exchange Server. Learn how this OWA XSS zero-day impacts Saudi financial institutions and what immediate mitigations to apply.

16 May 2026 5 min
Vulnerabilities

NGINX Rift: 18-Year-Old Critical RCE Bug Hiding in Every Reverse Proxy

An 18-year-old heap buffer overflow in NGINX's rewrite module (CVE-2026-42945, CVSS 9.2) enables unauthenticated RCE on every unpatched reverse proxy. Here's what Saudi financial institutions must do now.

16 May 2026 5 min
Vulnerabilities

CVE-2026-32201: Unpatched SharePoint Servers Expose Saudi Financial Institutions to Unauthenticated Spoofing

CISA added CVE-2026-32201 to its KEV catalog, yet over 1,300 SharePoint servers remain exposed. For Saudi banks running SharePoint on-prem, the window to patch is closing fast.

16 May 2026 5 min
Vulnerabilities

CVE-2026-41096: Critical Windows DNS Client RCE Threatens Every Endpoint

CVE-2026-41096 scores CVSS 9.8—a heap overflow in Windows DNS Client allows unauthenticated RCE on every Windows machine via a single malicious DNS response. Here's what Saudi financial institutions must do now.

16 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality