Critical
Advisory
A NetScaler bug that Citrix documented as a crash in June turned out to be unauthenticated remote code execution as root. Exploitation began days after a public write-up, and CISA…
CBN-2026-020/ 27 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
A path traversal in the vCenter syslog server went from vendor advisory to mass exploitation in five days. Researchers counted 361 victim addresses across 47 countries, and the implant left…
CBN-2026-022/ 13 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Two chained flaws gave unauthenticated root on SonicWall's SMA1000 VPN appliances three weeks before a patch existed. Attackers took user credentials and TOTP seeds, which means patching alone does not…
CBN-2026-021/ 3 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Attackers are chaining a missing-authentication bug, a deserialisation bug and a spoofing bug against on-premises SharePoint, then stealing IIS machine keys so they can forge their own payloads afterwards. One…
CBN-2026-023/ 16 Jul 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
A certificate-validation flaw in Check Point's IKEv1 handling let attackers establish remote-access VPN sessions without a password. Exploitation predated the fix by a month, and a Qilin affiliate is the…
CBN-2026-024/ 9 Jun 2026
/
Cyber_Reporter
Read advisory