Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

Apache HTTP/2 Double-Free CVE-2026-23918: Two Frames, Zero Auth, Full RCE

A double-free in Apache mod_http2 lets attackers crash or take over servers with just two HTTP/2 frames and zero authentication. Here's what Saudi financial institutions need to do immediately.

12 May 2026 6 min
Vulnerabilities

FortiClient EMS Zero-Day CVE-2026-35616: Pre-Auth API Bypass Hits Endpoint Management at Scale

A critical pre-authentication API bypass in FortiClient EMS was exploited as a zero-day before Fortinet disclosed it. Here's what SAMA-regulated institutions must do now.

12 May 2026 5 min
Vulnerabilities

Bleeding Llama: Critical Ollama Flaw Leaks AI Server Memory to Unauthenticated Attackers

A critical out-of-bounds read in Ollama's GGUF loader lets attackers siphon API keys, user prompts, and credentials from 300,000+ exposed AI servers — no authentication required.

12 May 2026 6 min
Vulnerabilities

Google Confirms First AI-Generated Zero-Day Exploit by Criminal Hackers

Google's Threat Intelligence Group has confirmed the first-ever detection of a criminal zero-day exploit built with AI assistance — a milestone that reshapes the threat landscape for Saudi financial institutions.

12 May 2026 5 min
Vulnerabilities

Dirty Frag: Linux Kernel Zero-Day Grants Root Access Across Cloud and Banking Infrastructure

Two chained Linux kernel flaws — CVE-2026-43284 and CVE-2026-43500 — let any unprivileged user reach root. Active exploitation confirmed. Here's what SAMA-regulated institutions must do now.

11 May 2026 5 min
Vulnerabilities

cPanel Auth Bypass CVE-2026-41940: 1.5M Servers at Risk, Ransomware in the Wild

A CVSS 9.8 authentication bypass in cPanel & WHM has been weaponized since February 2026. With 1.5 million exposed instances and ransomware already deploying, Saudi financial institutions must audit their hosting infrastructure now.

11 May 2026 5 min
Vulnerabilities

PAN-OS Zero-Day CVE-2026-0300: Root-Level RCE Threatens SAMA-Regulated Firewalls

A critical buffer overflow in Palo Alto PAN-OS (CVSS 9.3) is being exploited in the wild to achieve root-level code execution on firewalls — with no authentication required. SAMA-regulated institutions running PA-Series or VM-Series must mitigate immediately.

11 May 2026 5 min
Vulnerabilities

Defender Zero-Days BlueHammer & RedSun: SAMA Bank EDR Risk

Three Microsoft Defender zero-days are being actively exploited. BlueHammer (CVE-2026-33825) is in CISA KEV; RedSun and UnDefend remain unpatched. What SAMA banks must do this week.

10 May 2026 4 min
Vulnerabilities

Ivanti EPMM CVE-2026-6973 RCE Exploited: SAMA Bank MDM Risk

CISA added Ivanti EPMM CVE-2026-6973 to the KEV catalog after confirmed in-the-wild exploitation. Saudi banks running on-prem MDM face severe risk to mobile device fleets and corporate data.

10 May 2026 3 min
Vulnerabilities

SharePoint CVE-2026-32201 Zero-Day RCE: Critical Risk to SAMA Banks

A new SharePoint zero-day vulnerability (CVE-2026-32201) is being actively exploited, exposing more than 1,300 internet-facing servers to unauthenticated remote code execution. SAMA-regulated banks must act now.

10 May 2026 3 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918 Double-Free RCE: SAMA Bank Risk

Apache HTTP Server 2.4.66 contains a critical HTTP/2 double-free vulnerability (CVE-2026-23918) enabling unauthenticated RCE — a direct threat to SAMA-regulated banking web infrastructure.

10 May 2026 4 min
Vulnerabilities

D-Link CVE-2026-0625 Zero-Day: DNS Hijack Risk for SAMA Banks

An unauthenticated RCE in end-of-life D-Link DSL routers (CVE-2026-0625, CVSS 9.3) enables silent DNS redirection. SAMA-regulated banks now face customer-side credential theft and BEC fraud at scale.

10 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality