> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
CVE-2026-88779: NetScaler SAML Memory Overflow Zero-Day Crashes Auth, Hits Freshly Patched Appliances
Citrix confirms exploitation of a NetScaler ADC/Gateway SAML memory overflow (CVSS 8.7) that crashes authentication services; honeypot data suggests appliances patched for the previous batch are also being hit.
AhsayCBS CVE-2026-105134: Unauthenticated OS Command Injection (CVSS 10) in Backup Server
A CVSS 10 OS command injection in the AhsayCBS Replication Receiver endpoint allows unauthenticated remote code execution on backup servers up to 10.3.2. Upgrade to 10.3.4.
Two Parsers, One URL: The Interpretation-Conflict Bug Is Eating Authentication in 2026
Cisco SD-WAN, UniFi OS, Starlette and Clerk all fell to the same flaw this year: the component that decides who gets in and the component that decides where the request goes read the URL differently. Here is why it keeps happening and how to stop shipping it.
Zammad CVE-2026-102489 and CVE-2026-102490: Session Hijack to Root Chain Exploited in DIVD Breach
Two Zammad zero-days chain a session hijack into RCE and local root; DIVD says an autonomous AI agent used them to breach its network, CISA added both to KEV, and the root flaw reportedly has no patch.
GitLab AI Gateway CVE-2026-90970: Prompt Template Sandbox Escape Gives Command Execution
GitLab patches CVE-2026-90970, a CVSS 9.9 Jinja2 prompt-template sandbox escape in self-hosted AI Gateway that lets an authenticated Duo Agent Platform user run arbitrary commands on the host.
Dell Container Storage Modules: Two CVSS 10 Missing-Authentication Flaws Expose Kubernetes Storage Admin Credentials
Dell's DSA-2026-448 fixes two maximum-severity missing-authentication bugs in the CSM Authorization module that let unauthenticated attackers take over storage arrays behind Kubernetes clusters.
MikroTik RouterOS CVE-2026-84411: Pre-Auth Integer Underflow in Web Management Gives Root RCE
CISA's ICS advisory ICSA-26-272-06 flags a CVSS 9.8 pre-authentication integer underflow in the RouterOS web management service that a single crafted HTTP request can turn into root code execution or a crash.
Warlock Ransomware Crew Keeps Breaking In Through SharePoint, Hits Water and Telecom Operators
Symantec ties the China-linked Storm-2603 (Longlegs) crew to new Warlock ransomware intrusions at a water utility and a telecom, using SharePoint access, a vulnerable K7 driver, VS Code tunnels and SYSVOL deployment.
FortiMail CVE-2026-104286: Unauthenticated Path Traversal Exploited as Zero-Day
Fortinet confirms in-the-wild exploitation of CVE-2026-104286, a CVSS 9.8 path traversal in FortiMail that lets unauthenticated attackers write arbitrary files. Patches are not yet released; CISA set a October 4 deadline.
TeamViewer Patches Five High-Severity Flaws, Including Remote Session Access Control Bypass to RCE
TeamViewer bulletin TV-2026-1010 fixes five high-severity client and host flaws, led by CVE-2026-92370, a remote-session access control bypass that can lead to code execution. Update to 15.82.
Cisco Catalyst SD-WAN Manager CVE-2026-76504: Unauthenticated Admin API Access Exploited
Cisco confirms in-the-wild exploitation of CVE-2026-76504, a CVSS 9.8 URL-encoding auth bypass that hands unauthenticated attackers admin API access on Catalyst SD-WAN Manager. No workaround; CISA added it to KEV.
CVE-2026-89775: KVM/arm64 Nested-Virtualization Bug Gives Guests Read-Write Access to Host Kernel Memory
A type-truncation bug in KVM/arm64's stage-1 page-table walk lets a guest keep a writable mapping to a freed host kernel page, enabling guest-to-host escape on ARM64 hosts with nested virtualization enabled.
Branch Target Reuse: New Spectre v2 Variant Leaks Linux Root Password Hash Through the cBPF JIT
VUSec's Branch Target Reuse abuses stale indirect-branch predictions over freed JIT memory to leak a root password hash from Linux in 3-5 minutes; kernel fixes for CVE-2026-64507 and CVE-2026-64508 are merged.
MemTensor MemOS Packages Backdoored with sckit, a Go Credential-Stealing Worm, on npm and PyPI
Malicious releases of MemTensor's MemOS OpenClaw plugin (npm) and MemoryOS (PyPI) deliver sckit, a cross-platform Go implant that steals 13 credential types and carries worm templates for npm, PyPI and GitHub Actions.
Cloudflare Containers Bug Let One Tenant Read Another Tenant's Disk Data
A misconfigured Linux dm-thin storage pool let any Cloudflare Workers Paid customer recover unzeroed residual disk blocks from other tenants' Containers, Sandboxes, and Browser Rendering instances — exposing SQLite databases, .env files, and credentials.
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
The Skeleton Key Problem: Why 2026's Worst RCEs All Trace Back to a String Literal
SolarWinds ARM, ManageEngine, ASUS Control Center, Cisco FMC, Dell SCG, and a Tenda router backdoor all failed the same way this year: a secret baked into shipped code instead of generated per install. CWE-798 isn't a legacy bug class — it's still how management planes get owned.
Two Malicious CPAN Modules Smuggle a Python Backdoor Inside a Fake Certificate File
Crypt::SelfCertificate and IO::Socket::SSL::SelfCertificate, two CPAN distributions for generating self-signed certs, shipped versions that hide obfuscated Python code inside a sample cert.pem and execute it as a remote-fetch loader.
CVE-2026-100706: Kyverno Path-Encoding Bug Lets Any Namespace Tenant Reach Cluster Admin
A validation/execution mismatch in Kyverno's apiCall path handling lets a low-privilege namespace tenant use percent-encoded traversal segments to register a cluster-wide mutating webhook and escalate to cluster admin. CVSS 9.9, fixed in 1.19.1.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.