Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

Weaver E-cology CVE-2026-22679: Unauthenticated RCE Risk to SAMA Banks

A CVSS 9.8 unauthenticated RCE flaw in Weaver E-cology is being actively exploited via an exposed Dubbo debug endpoint. SAMA-regulated banks running this enterprise collaboration platform face direct threats to integrity and availability obligations under CSCC.

9 May 2026 4 min
Vulnerabilities

cPanel CVE-2026-41940 Auth Bypass: Risk to SAMA Banks

A critical CRLF-injection auth bypass in cPanel & WHM (CVSS 9.8) is under mass exploitation, putting Saudi banks' supply chains and PCI-DSS scope at risk.

9 May 2026 4 min
Vulnerabilities

VM2 Sandbox Escape (CVE-2026-44008): Node.js Risk for SAMA Banks

A new vm2 sandbox breakout (CVE-2026-44008, CVSS 9.8) gives attackers a clean path from untrusted JavaScript to the host. Here is what SAMA-regulated banks running Node.js fintech APIs and AI agents must do this week.

9 May 2026 4 min
Artificial Intelligence

FastGPT SSRF (CVE-2026-44286): AI Agent Risk to SAMA Banks

Two new FastGPT vulnerabilities disclosed May 8, 2026 (CVE-2026-44286 unauthenticated SSRF and CVE-2026-44284 MCP toolset bypass) put Saudi banks experimenting with AI agents at risk of internal network pivoting and metadata theft.

9 May 2026 4 min
Vulnerabilities

Ni8mare (CVE-2026-21858): Critical n8n RCE Threatens SAMA Banks

A maximum-severity (CVSS 10.0) flaw in n8n — the AI workflow platform many Saudi banks use to automate KYC, fraud, and ticketing — lets attackers seize servers without authentication. Patch now.

9 May 2026 4 min
Vulnerabilities

CVE-2026-31431 "Copy Fail": Linux Root Bug Threatens SAMA Banks

A nine-year-old Linux kernel flaw, now in CISA KEV, gives any unprivileged local user root on Ubuntu, RHEL, and Amazon Linux — the core stack for SAMA bank workloads. Here is what Saudi CISOs must act on now.

8 May 2026 4 min
Vulnerabilities

CVE-2026-41940: cPanel Auth Bypass Threatens SAMA Banks

A critical CRLF-injection authentication bypass in cPanel and WHM (CVE-2026-41940, CVSS 9.8) gives unauthenticated attackers root-level access. Saudi banks and their hosting vendors must act now.

8 May 2026 4 min
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973: RCE Risk for SAMA Banks

An actively exploited zero-day in Ivanti Endpoint Manager Mobile (CVE-2026-6973) enables admin-level remote code execution on the MDM controller — a direct threat to mobile device estates across SAMA-regulated banks.

8 May 2026 4 min
Vulnerabilities

Dirty Frag Linux Zero-Day (CVE-2026-43500): Risk to SAMA Banks

On May 8, 2026, an unpatched Linux kernel flaw dubbed Dirty Frag (CVE-2026-43500) surfaced with a public PoC granting unprivileged-to-root escalation — a critical exposure for SAMA-regulated banks.

8 May 2026 5 min
Vulnerabilities

PAN-OS CVE-2026-0300: Critical RCE Threat to SAMA Banks

CISA added Palo Alto PAN-OS CVE-2026-0300 to its KEV catalog after limited in-the-wild exploitation. Saudi banks exposing the User-ID Authentication Portal face an unauthenticated root RCE on the perimeter — here is what SAMA CSCC requires you to do now.

8 May 2026 4 min
Vulnerabilities

Apache HTTP/2 CVE-2026-23918: Critical RCE Risk to SAMA Banks

Apache HTTP Server 2.4.66 contains CVE-2026-23918, a double-free in mod_http2 enabling DoS and potential RCE via early stream reset. SAMA-regulated banks running Apache must patch to 2.4.67 immediately.

8 May 2026 4 min
Vulnerabilities

CitrixBleed 3 (CVE-2026-3055): Critical Risk for SAMA Banks

A critical Citrix NetScaler memory overread (CVE-2026-3055) is being actively exploited against SAML-enabled appliances. Saudi banks must patch and rotate session tokens before attackers harvest more.

8 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality