Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns. Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that… Read More "GitLab Vulnerability Exploited One Day After Disclosure"
Critical NetScaler Vulnerability Exploited in Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks. Tracked as CVE-2026-19490 (CVSS score of 9.3), the security defect impacts all NetScaler ADC and NetScaler Gateway… Read More "Critical NetScaler Vulnerability Exploited in Attacks"
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated… Read More "Organizations Warned of Cisco Secure FMC Exploitation"
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug… Read More "Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks"
Android’s September 2026 Updates Patch 180 Vulnerabilities
After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security updates. As usual, the updates are split into two parts. The… Read More "Android’s September 2026 Updates Patch 180 Vulnerabilities"
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection… Read More "Adobe Commerce Zero-Day Exploited to Backdoor Online Stores"