Critical
Advisory
A NetScaler bug that Citrix documented as a crash in June turned out to be unauthenticated remote code execution as root. Exploitation began days after a public write-up, and CISA…
CBN-2026-020/ 27 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
A path traversal in the vCenter syslog server went from vendor advisory to mass exploitation in five days. Researchers counted 361 victim addresses across 47 countries, and the implant left…
CBN-2026-022/ 13 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
A six-agency advisory documents Gunra actors deleting backup and archive data on backup infrastructure at both the production data centre and the disaster recovery centre. The same administrative credentials reached…
CBN-2026-025/ 11 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Operators spoof your help-desk number, call employees on personal phones, and tell them to enrol a passkey immediately. The page is a reverse proxy. Once inside they register their own…
CBN-2026-031/ 7 Aug 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Attackers ask Microsoft for a device code, send it to your user, and the user types it into the genuine login page. No password prompt, no MFA challenge, no phishing…
CBN-2026-030/ 5 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Two chained flaws gave unauthenticated root on SonicWall's SMA1000 VPN appliances three weeks before a patch existed. Attackers took user credentials and TOTP seeds, which means patching alone does not…
CBN-2026-021/ 3 Aug 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
Attackers are chaining a missing-authentication bug, a deserialisation bug and a spoofing bug against on-premises SharePoint, then stealing IIS machine keys so they can forge their own payloads afterwards. One…
CBN-2026-023/ 16 Jul 2026
/
Cyber_Reporter
Read advisory
High
Advisory
Veeam Backup & Replication took seven critical vulnerabilities in March and another remote code execution flaw in June. Every one of them needs only a low-privilege authenticated domain account —…
CBN-2026-026/ 10 Jun 2026
/
Cyber_Reporter
Read advisory
Critical
Advisory
A certificate-validation flaw in Check Point's IKEv1 handling let attackers establish remote-access VPN sessions without a password. Exploitation predated the fix by a month, and a Qilin affiliate is the…
CBN-2026-024/ 9 Jun 2026
/
Cyber_Reporter
Read advisory
High
Advisory
No malware in the identity phase. A phone call impersonating IT support, a triggered SSPR, an approved MFA prompt — and then dozens of secrets pulled from a single Key…
CBN-2026-032/ 20 May 2026
/
Cyber_Reporter
Read advisory