Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
CVE-2026-40361: Zero-Click Outlook RCE Lets Attackers Compromise Executives by Simply Sending an Email
A critical zero-click use-after-free vulnerability in Microsoft Outlook lets attackers achieve remote code execution through the Preview Pane alone. Learn why Saudi financial institutions must patch CVE-2026-40361 immediately.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials
Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.
VulnerabilitiesCVE-2026-42897: Actively Exploited Exchange Server Zero-Day Hits On-Prem Email with No Patch Available
Microsoft confirms active exploitation of CVE-2026-42897 in Exchange Server OWA — no patch available yet. Here's what Saudi financial institutions must do now to protect their on-prem email infrastructure.
VulnerabilitiesGoogle Catches First AI-Generated Zero-Day Exploit: A New Era of Cyber Threats
Google detected the first confirmed AI-generated zero-day exploit — a 2FA bypass built by the OpenClaw model. Here's why Saudi CISOs need to rethink their threat models immediately.
VulnerabilitiesFragnesia CVE-2026-46300: Linux Kernel Root Exploit Threatens Every Server in Saudi Financial Infrastructure
A new Linux kernel vulnerability lets any unprivileged user gain root access in a single command. Saudi financial institutions running Linux-based core banking, SOC platforms, and API gateways face immediate risk.
VulnerabilitiesNGINX Rift CVE-2026-42945: An 18-Year-Old Zero-Click RCE Flaw Threatening Every API Gateway in Saudi Finance
A single HTTP request can give attackers full control of your NGINX server. CVE-2026-42945 has lurked in NGINX's rewrite module since 2008 — here's what Saudi financial institutions must do immediately.
VulnerabilitiesCVE-2026-40403: Win32K Graphics RCE Lets Attackers Gain Kernel Access Through a Single Malicious Image
A single malicious image or font file can hand attackers full kernel privileges on any unpatched Windows system. CVE-2026-40403 demands immediate action from every Saudi financial institution.
VulnerabilitiesCVE-2026-41940: cPanel Authentication Bypass Exposes 1.5M Hosting Servers to Full Root Takeover
A CRLF injection in cPanel & WHM session handling lets unauthenticated attackers promote themselves to root — bypassing passwords and 2FA entirely. With 1.5 million servers exposed, Saudi organizations must act now.
Network & InfrastructureCVE-2026-0300: Palo Alto PAN-OS Zero-Day Gives Attackers Root on Your Perimeter Firewall
A critical buffer overflow in Palo Alto PAN-OS User-ID Authentication Portal is being exploited in the wild—giving attackers root-level code execution on PA-Series and VM-Series firewalls without any credentials.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Turns Two Frames into Full Server Takeover
A single TCP connection and two HTTP/2 frames can crash — or fully compromise — Apache web servers running mod_http2. CVE-2026-23918 scored 8.8 CVSS and demands immediate patching across Saudi financial infrastructure.
VulnerabilitiesDead.Letter CVE-2026-45185: Critical Exim RCE Threatens Every Mail Server in Your Financial Infrastructure
A single malformed TLS handshake can give attackers root access to your Exim mail server. CVE-2026-45185 scores 9.8 CVSS and requires no authentication — here's what SAMA-regulated institutions must do now.
VulnerabilitiesCritical SAP Commerce Cloud and S/4HANA Flaws CVE-2026-34263 & CVE-2026-34260: CVSS 9.6 Threats to Saudi ERP Infrastructure
SAP's May 2026 Patch Day fixes two critical CVSS 9.6 vulnerabilities — an unauthenticated RCE in Commerce Cloud and a SQL injection in S/4HANA. Here's why Saudi financial institutions running SAP must patch immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers