Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • MikroTrick PoC: RouterOS Admin Rights Exploited In Wild Do Son
    The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild AI Agent Coordination: The Unprecedented OpenAI Breakout Roundcube Security Update Fixes 12 Webmail Flaws The post MikroTrick PoC: RouterOS Admin Rights Exploited In Wild appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Firewall Daily – The Cyber Express
  • Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk Samiksha Jain
    Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gatew
     

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk

4 de Setembro de 2026, 03:21

Citrix NetScaler vulnerabilities

Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.

Citrix NetScaler Vulnerabilities Affect ADC and Gateway

The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration. The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway. The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.

Patches Released for Citrix NetScaler products

Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions. The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments. However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.

Organisations Urged to Assess Vulnerable Versions

The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable. Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated. Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity. This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.

Monitoring Remains Important After Patching

Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected. The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway. For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.
  • ✇Cybersecurity News
  • FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server Do Son
    FreeRDP 3.31.0 patches 5 server-role flaws, including a pre-auth remote code execution chain affecting GNOME Remote Desktop and KDE krdp. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild Do Son
    A public PoC now targets a Proxmox VE authentication bypass in EOL 7.x releases, and the pre-auth flaw is exploited in the wild for root access. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover Do Son
    A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed Cosmos EVM Flaw Triggers Multi-Chain Heist The post CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet Do Son
    CISA warns of 11 Ebyte NE2-D11 vulnerabilities, four rated 9.8, that allow full device takeover. No patch is confirmed available yet. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • RDK-B WebUI Vulnerabilities Let Attackers Bypass Login Do Son
    Five RDK-B WebUI vulnerabilities let attackers bypass authentication and gain admin access on broadband gateways. No patch is available yet. Related Posts: EverShop CVE-2026-72843 Flaw Allows Unauthenticated Account Takeover CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws Patched The post RDK-B WebUI Vulnerabilities Let Attackers Bypass Login appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10 Do Son
    Cisco patches Secure Workload flaws CVE-2026-20315 and CVE-2026-20317, an authentication bypass and privilege escalation pair scoring CVSS 10. Upgrade now. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
     
  • ✇Cybersecurity News
  • CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched Do Son
    CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-19490 (CVSS 9.3): NetScaler Authentication Bypass Flaw Patched appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9) Do Son
    IBM patches an IBM Db2 Mirror RCE flaw, CVE-2026-17186, rated CVSS 9.9, plus 17 more bugs in Db2 Mirror for i. Patch now. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post IBM Db2 Mirror for i Hit by CVE-2026-17186 RCE Flaw (CVSS 9.9) appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8) Do Son
    CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5 Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post CVE-2026-15826: User Profile Builder Bug Under Act
     
  • ✇Cybersecurity News
  • TP-Link Patches 5 Flaws in ISP-Managed Routers and Mesh Devices Do Son
    TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection. Related Posts: Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8) The post TP-Link Patches 5 Flaws in ISP-Managed Routers and Mesh Devices appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-63455: EdgeConnect Orchestrator Web Authentication Bypass Rated CVSS 9.8 Do Son
    CVE-2026-63455 and CVE-2026-63456 let attackers bypass web authentication on HPE EdgeConnect Orchestrator. CVSS 9.8. Patch now. Related Posts: Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8) The post CVE-2026-63455: EdgeConnect Orchestrator Web Authentication Bypass Rated CVSS 9.8 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-55040 PoC Released for SharePoint Authentication Bypass Do Son
    Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post CVE-2026-55040 PoC Released for SharePoint Authentication Bypass appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • MarkLogic Server Security Bulletin Patches 10 Vulnerabilities, With CVSS Scores Up to 9.9 Do Son
    Progress patched 10 MarkLogic Server vulnerabilities, including auth bypass and privilege escalation flaws rated up to CVSS 9.9. Details inside. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post MarkLogic Server Security Bulletin Patches 10 Vulnerabilities, With CVSS Scores Up to 9.9 appeared first on Dai
     
  • ✇Cybersecurity News
  • CVE-2026-5423: Authentication Bypass Hits Neo4j GraphQL Subscriptions Do Son
    CVE-2026-5423 is a Neo4j GraphQL authentication bypass letting unauthenticated clients forge JWT claims and read subscription data. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post CVE-2026-5423: Authentication Bypass Hits Neo4j GraphQL Subscriptions appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-5430: WSO2 Account Takeover Flaws Rated Up to CVSS 10 Do Son
    WSO2 patched four critical account takeover flaws, including CVE-2026-5430 at CVSS 10 via JWT auth bypass. Details and fixes inside. Related Posts: CVE-2026-43074: Linux Kernel eventpoll Use-After-Free Gives a Root Shell, PoC Exploit Code Publicly Disclosed CVE-2026-64564: SCTP Flaw Enables Container Escape PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild The post CVE-2026-5430: WSO2 Account Takeover Flaws Rated Up to CVSS 10 appeared first on Daily CyberSecurity.
     
❌
❌