Federal agencies face urgent remediation deadlines as CISA confirms active exploitation of CVE-2023-49105, allowing attackers to access and delete cloud storage files without credentials.
SAP released security updates for CVE-2026-58240, a CVSS 9.6 authentication bypass in NetWeaver AS Java/ABAP Message Server that permits enterprise takeover.
CISA and threat researchers warn that CVE-2026-19490 in Citrix NetScaler ADC and Gateway is under active exploitation, granting unauthenticated access to perimeter gateways.
Threat actors and Qilin ransomware affiliates are actively weaponizing CVE-2026-20079 in Cisco Secure FMC to bypass web authentication and achieve root command execution.
A newly catalogued authentication bypass in Palo Alto Networks PAN-OS lets an unauthenticated attacker reach management functionality. Here is the exposure and the fix.