Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
vm2 Sandbox Escape (CVE-2026-24118): RCE Risk for SAMA Banks
Twelve critical vm2 Node.js sandbox escape vulnerabilities, including CVE-2026-24118 (CVSS 9.8), let attackers execute arbitrary code on host servers. Saudi banks and fintechs running Node.js platforms face urgent SAMA CSCC remediation pressure.
VulnerabilitiescPanel CVE-2026-41940: Vendor Risk for SAMA-Regulated Banks
A pre-auth cPanel bypass (CVE-2026-41940) exposes 1.5M internet-facing servers — including those running Saudi bank marketing sites and vendor portals. Here is what SAMA-regulated CISOs must act on now.
VulnerabilitiesCVE-2026-0300: PAN-OS Captive Portal RCE Threat to SAMA Banks
A critical PAN-OS Captive Portal buffer overflow lets unauthenticated attackers gain root on Palo Alto firewalls. SAMA-regulated banks must patch and isolate User-ID portals immediately.
VulnerabilitiesMOVEit CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks
A CVSS 9.8 authentication bypass flaw in MOVEit Automation (CVE-2026-4670) lets unauthenticated attackers seize full administrative control of file transfer servers. Saudi financial institutions must act now.
VulnerabilitiesCVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks
A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.
VulnerabilitiesCopy Fail CVE-2026-31431: Linux Root Threat to SAMA Banks
A 732-byte exploit grants root on every major Linux distribution since 2017. Saudi banks running RHEL, Ubuntu, or Amazon Linux face urgent SAMA CSCC patching obligations.
Cloud & IdentityOracle Identity Manager CVE-2026-21992: Critical IAM Threat to SAMA Banks
A pre-authentication RCE in Oracle Identity Manager (CVSS 9.8) gives attackers direct control of the IAM core that Saudi banks rely on for SAMA CSCC compliance. Here is how to detect, patch, and respond.
VulnerabilitiesFortiClient EMS CVE-2026-35616: Critical RCE Threat to SAMA Banks
Fortinet disclosed a critical pre-authentication RCE flaw in FortiClient EMS (CVSS 9.1). For SAMA-regulated Saudi banks running Fortinet endpoint management, immediate patching is non-negotiable.
VulnerabilitiesAndroid Zero-Click CVE-2026-0073: Mobile Banking Threat to SAMA Banks
A critical zero-click flaw in Android's wireless ADB daemon (CVE-2026-0073) allows attackers in Wi-Fi proximity to obtain a remote shell without any user interaction — a direct threat to Saudi mobile banking and BYOD fleets under SAMA CSCC.
VulnerabilitiesLangflow CVE-2026-33017 RCE: AI Pipeline Threat to SAMA Banks
An unauthenticated RCE in Langflow's public flow endpoint puts AI orchestration pipelines at Saudi financial institutions in the crosshairs. Here is what SAMA-regulated banks must do this week.
VulnerabilitiesMOVEit Automation CVE-2026-4670: Critical Auth Bypass Threatens SAMA Banks
Progress disclosed CVE-2026-4670 — a CVSS 9.8 authentication bypass in MOVEit Automation. Here is what SAMA-regulated banks must do this week to protect interbank file transfers and meet third-party risk obligations.
VulnerabilitiesArgo CD CVE-2026-43824: Read-Only RBAC Bypass Threatens SAMA Banks
A new Argo CD flaw (CVE-2026-43824) lets read-only users extract plaintext Kubernetes secrets via the ServerSideDiff API. Saudi banks running GitOps must patch and audit RBAC immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers