Cisco disclosed CVE-2026-20212 (CVSS 9.8), an unauthenticated root code execution flaw on Silicon One-based Nexus 9000 datacenter switches due to open debugging ports.
An August attack compromised multiple VMware ESXi nodes at hosting provider HostDZire, encrypting virtual disks beyond recovery across India, the Netherlands and the US.
Adversary-in-the-middle phishing now defeats standard MFA at industrial scale. Microsoft tracked a single April 2026 campaign spanning 26 countries in 72 hours.