Cybersecurity news and vulnerability intelligence

Cybersecurity news from leading outlets and government advisories in one place, linked to the CVEs they cover, with patch priority, exploitation data and spike alerts.

Latest stories

CVEs in the news

  • CVE-2026-88771 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-65660 CVSS 8.8 high · actively exploited Microsoft SharePoint Code Injection Vulnerability
  • CVE-2026-76504 CVSS 9.8 critical · actively exploited Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
  • CVE-2026-94127 CVSS 9.3 critical · actively exploited F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
  • CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-88778 CVSS 8.8 high Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC…
  • CVE-2026-35273 CVSS 9.8 critical · actively exploited Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
  • CVE-2026-104286 CVSS 9.8 critical · actively exploited Fortinet FortiMail Path Traversal Vulnerability
  • CVE-2026-88779 CVSS 8.7 high · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-87902 CVSS 8.1 high · actively exploited WordPress Core Remote File Inclusion Vulnerability
  • CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability

Recently exploited

  • CVE-2026-88779 CVSS 8.7 high · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
  • CVE-2026-102489 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Session Fixation Vulnerability
  • CVE-2026-102490 CVSS 9.4 critical · actively exploited Zammad GmbH Zammad Improper Privilege Management Vulnerability
  • CVE-2026-104286 CVSS 9.8 critical · actively exploited Fortinet FortiMail Path Traversal Vulnerability
  • CVE-2026-76504 CVSS 9.8 critical · actively exploited Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
  • CVE-2026-86950 CVSS 8.8 high · actively exploited Apple Multiple Products Out-of-Bounds Write Vulnerability
  • CVE-2026-88771 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Input Validation Vulnerability
  • CVE-2026-88772 CVSS 9.5 critical · actively exploited Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability