Network-Appliance
HPE Aruba AOS-CX: Two Independent Unauthenticated RCE Paths in the Same Switch OS (CVE-2026-73749, CVE-2026-73782)
HPE's September security bulletin for ArubaOS-CX patches 24 flaws, including two unrelated bugs that each let an unauthenticated attacker fully compromise a switch with a single crafted packet.
CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE
SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.
Fire Ant Expands From VMware Hypervisors to Cisco IOS XR Routers and TACACS Servers
China-nexus actor Fire Ant has moved beyond VMware ESXi hosts to implant Cisco IOS XR routers and TACACS+ authentication servers, using purpose-built tooling to hijack GRE tunnels, hide commands from admins, and intercept credentials at the network's control plane.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account
CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.
CISA, NSA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs
A joint advisory from NSA, CISA, FBI, DOE, and EPA warns that threat actors are pairing AI-assisted scripting with snap7 libraries to build custom reconnaissance and exploitation tools against internet-exposed Siemens S7 PLCs.
CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely
A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.
Evooo1Bot: New Mirai-Derived Linux Botnet Chains Eight CVEs Spanning 2007–2025 Against Routers and Edge Devices
Evooo1Bot, a modular Mirai-derived Linux botnet tracked by FortiGuard Labs, exploits eight known CVEs dating back to 2007 across routers, firewalls, and industrial gateways to build a SOCKS5 proxy and DDoS network.
Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE
An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.
Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws
CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.
Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)
CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.
First-of-Its-Kind Attack Pivots Through a Private Cellular APN to Sabotage Siemens PLCs at a Polish Power Plant
CERT Polska details a December 2025 attack that pivoted through a distribution operator's private cellular APN — from a compromised wind farm firewall to Siemens PLCs at a combined heat and power plant, halting a turbine.
CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation
A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.
15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path
Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem — hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.
Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day
Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs — the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.
N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover
N-able's emergency fix for an N-central authentication bypass proved incomplete — a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi — no workarounds exist for either critical vCenter bug.
N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels
An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.
CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV
Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data — CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.