Skip to main content

CYBERVOC / Blog

Insights for a Safer Digital World.

Security research, practical guidance and a closer look at the code and dependencies we build with.

Developer Security

GitLab Urges Immediate Patch for Critical AI Gateway RCE (CVE-2026-90970)

GitLab disclosed a critical flaw in its AI Gateway that can allow command execution in self-hosted deployments under specific conditions. Security teams running self-managed gateways should prioritize upgrades, validate exposure, and monitor authentication and gateway logs for suspicious activity.

#gitlab#cve#aisecurity#devsecops#vulnerability#patchmanagement#appsec
GitLab Urges Immediate Patch for Critical AI Gateway RCE (CVE-2026-90970)

Patch Management

Critical FortiMail Flaw CVE-2026-104286 Under Active Exploitation

Fortinet disclosed a critical FortiMail vulnerability (CVE-2026-104286) reported as actively exploited. Organizations should rapidly patch exposed mail gateways, reduce internet exposure where possible, and review logs for suspicious file-write or post-compromise activity.

#fortimail#fortinet#cve#kev#zeroDay#patchmanagement#emailsecurity
Critical FortiMail Flaw CVE-2026-104286 Under Active Exploitation

Cloud Security

Dell CSM Critical CVEs Expose Kubernetes Storage Control Planes

Dell patched multiple severe vulnerabilities in Container Storage Modules (CSM), including max-severity issues affecting authorization paths and privilege boundaries. Kubernetes operators using Dell-backed storage should patch quickly and validate cluster-level blast radius and access controls.

#dell#kubernetes#cve#cloudsecurity#containers#devsecops#patchmanagement
Dell CSM Critical CVEs Expose Kubernetes Storage Control Planes

Threat Intelligence

Warlock Ransomware Campaign Expands SharePoint Exploitation in Critical Infrastructure

Researchers report continued Warlock activity abusing SharePoint vulnerabilities against critical infrastructure and public-sector targets. Defenders should prioritize SharePoint hardening, patch hygiene, identity controls, and rapid detection of post-exploitation behavior.

#sharepoint#ransomware#threatintel#criticalinfrastructure#microsoft#incidentresponse
Warlock Ransomware Campaign Expands SharePoint Exploitation in Critical Infrastructure

Vulnerabilities

Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation

Security firm watchTowr says two new remote-code-execution zero-days in Citrix NetScaler ADC and Gateway are being exploited in the wild, with no vendor advisory or patch yet available. Some administrators are taking edge appliances offline; a fix is reportedly expected early next week.

#citrix#netscaler#zeroday#rce#vpn#networksecurity#kev
Two Unpatched Citrix NetScaler Zero-Days Under Active Exploitation

Supply Chain Security

Compromised GitHub Actions Resurface, Silently Resume Serving Malware

Two GitHub Actions compromised in the May 2026 Mini Shai-Hulud campaign were re-enabled for over a week without their malicious release tags being cleaned up, causing referencing workflows to silently re-download and execute the original credential-stealing payload. Pin dependencies to commit SHAs and rotate any exposed CI/CD secrets.

#supplychain#github#cicd#shaihulud#devsecops#malware#npm
Compromised GitHub Actions Resurface, Silently Resume Serving Malware

Threat Intelligence

ShinyHunters Bypasses WAFs to Resume Mass Exploitation of Oracle PeopleSoft

Google reports the ShinyHunters-linked group UNC6240 is using a URL-encoding trick to bypass WAF rules protecting Oracle PeopleSoft's CVE-2026-35273 flaw, deploying web shells and a stealer backdoor across dozens of organizations worldwide. Patching, not WAF rules alone, is required to close the exposure.

#oracle#peoplesoft#shinyhunters#cve#databreach#webshells#wafbypass
ShinyHunters Bypasses WAFs to Resume Mass Exploitation of Oracle PeopleSoft

Patch Management

CISA Flags SharePoint and MikroTik RouterOS Flaws as Actively Exploited

CISA has added a SharePoint code-injection flaw (CVE-2026-65660) and a MikroTik RouterOS authentication flaw (CVE-2026-67279) to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. The RouterOS flaw is chained into the "MikroTrick" exploit for full unauthenticated router takeover — patch both immediately.

#cisa#kev#sharepoint#mikrotik#routeros#cve#patchmanagement
CISA Flags SharePoint and MikroTik RouterOS Flaws as Actively Exploited

Patch Management

CVE Volume Is Exploding, But Remediation Speed Is the Real Vulnerability Crisis

Critical and high-severity CVE disclosures across major vendors have jumped roughly sixfold since spring 2026, but rising counts are not the real risk indicator. Industry data shows only a minority of actively exploited, KEV-listed vulnerabilities get fully patched, and median remediation time is increasing — teams should prioritize fix speed over raw CVE volume.

#vulnerabilitymanagement#cve#patchmanagement#kev#cisa#appsec#devsecops
CVE Volume Is Exploding, But Remediation Speed Is the Real Vulnerability Crisis

Vulnerabilities

Check Point Patches Two Critical VPN Certificate Flaws Amid Exploitation Warning

Check Point has patched two 9.8-rated VPN certificate vulnerabilities (CVE-2026-85102, CVE-2026-85103) that could allow unauthenticated remote code execution on Security Gateways and Management Servers. The Dutch NCSC warns exploitation is imminent even though no public proof-of-concept exists yet — apply Live Patch or Jumbo Hotfixes now.

#checkpoint#vpn#cve#rce#networksecurity#patchmanagement#ncsc
Check Point Patches Two Critical VPN Certificate Flaws Amid Exploitation Warning

Supply Chain Security

CISA Adds Five Actively Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV

CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog. Attackers are chaining Artifactory flaws to seize admin control and plant backdoors on unpatched build-pipeline servers. Federal patch deadlines fall between September 13 and 25.

#supplychain#cisa#kev#jfrog#artifactory#screenconnect#routeros
CISA Adds Five Actively Exploited Artifactory, ScreenConnect, RouterOS Flaws to KEV

Ransomware

Cisco Secure FMC Flaws Exploited by Ransomware and State-Sponsored Hackers

Cisco Talos confirms three separate threat clusters — including Qilin ransomware affiliates and a group whose tooling overlaps with the Russian Sandworm actor — are exploiting two Secure Firewall Management Center flaws (CVE-2026-20079, CVE-2026-20316) for root access, credential theft, and ransomware deployment. Hotfixes are available; apply immediately.

#cisco#ransomware#qilin#sandworm#cve#firewallsecurity#threatintel
Cisco Secure FMC Flaws Exploited by Ransomware and State-Sponsored Hackers

Developer Security

GitLab CVSS 10 Path Traversal Flaw Draws In-the-Wild Probes Within Hours

GitLab has patched a maximum-severity path traversal flaw (CVE-2026-85706, CVSS 10.0) in its repository commits API that lets unauthenticated attackers read arbitrary files, including credentials and secrets. In-the-wild scanning began within hours of disclosure — self-managed instances should be patched immediately.

#gitlab#cve202685706#pathtraversal#devsecops#patchmanagement#sourcecode#kev
GitLab CVSS 10 Path Traversal Flaw Draws In-the-Wild Probes Within Hours

Vulnerability Management

CVE-2026-82329: JFrog Artifactory Already Exploited, Priority Patching for DevSecOps Teams

The critical CVE-2026-82329 flaw (CVSS 9.8) in JFrog Artifactory is already being exploited just days after disclosure. This briefing covers impacted versions, supply-chain risk, and an actionable containment plan.

#CVE202682329#JFrog#Artifactory#DevSecOps#SupplyChainSecurity#PatchManagement
CVE-2026-82329: JFrog Artifactory Already Exploited, Priority Patching for DevSecOps Teams

AI Security

Langflow CVE-2026-0768: Active Key-Theft Campaign Demands Immediate Cloud Secret Rotation

Attackers are exploiting CVE-2026-0768 in Langflow to extract OpenAI and AWS credentials. This update summarizes the current threat, likely blast radius, and urgent defensive actions for platform and SecOps teams.

#Langflow#CVE20260768#AISecurity#CloudSecurity#ThreatDetection#SecretManagement
Langflow CVE-2026-0768: Active Key-Theft Campaign Demands Immediate Cloud Secret Rotation

Supply Chain Security

Virtualizor: BGP Hijack Targeted the Update Chain, Trust Controls Need Hardening

A BGP routing hijack enabled delivery of a malicious Virtualizor update during a limited exposure window. Here is a defensive analysis and a practical risk-reduction plan for hosting and operations teams.

#Virtualizor#BGPHijacking#SupplyChainSecurity#ThreatDetection#DevSecOps#IncidentResponse
Virtualizor: BGP Hijack Targeted the Update Chain, Trust Controls Need Hardening

Cloud Security

ServiceNow AI Platform: Three CVSS 10.0 Flaws Require Immediate Patching

ServiceNow disclosed three unauthenticated, low-complexity vulnerabilities in its AI Platform, each rated CVSS 10.0. Hosted instances were patched by the vendor, but self-hosted customers should urgently deploy the released hotfixes and validate exposure paths for code and SQL injection risks.

#servicenow#cve#cloudsecurity#patchmanagement#sqlinjection#codeinjection
ServiceNow AI Platform: Three CVSS 10.0 Flaws Require Immediate Patching

Vulnerabilities

PaperCut NG/MF Zero-Day Chain: Emergency Patch Release 2 Is Now Required

PaperCut confirmed active exploitation and issued a second emergency update after researchers found bypasses in the first fix. Organizations running PaperCut NG/MF should deploy Release 2 immediately, restrict web admin exposure, and review indicators tied to pre-auth compromise attempts.

#papercut#cve#zeroday#rce#patchmanagement#printsecurity
PaperCut NG/MF Zero-Day Chain: Emergency Patch Release 2 Is Now Required

Patch Management

Citrix NetScaler CVE-2026-8452: KEV Listing Signals Urgent Remediation

CVE-2026-8452 in Citrix NetScaler is now in CISA KEV after reports of in-the-wild exploitation. Teams using affected AAA or Gateway VPN configurations should patch immediately and investigate appliances for unauthorized changes and suspicious command execution patterns.

#citrix#netscaler#cve#kev#rce#patchmanagement
Citrix NetScaler CVE-2026-8452: KEV Listing Signals Urgent Remediation

Developer Security

Next.js Security Update: Critical AVIF and Windows RCE Risks Patched

Vercel patched two critical Next.js vulnerabilities that can lead to unauthenticated remote code execution under specific conditions, including Windows-hosted deployments and AVIF optimization paths. Engineering teams should upgrade immediately to patched LTS versions and review image-processing exposure.

#nextjs#cve#rce#websecurity#developers#patchmanagement
Next.js Security Update: Critical AVIF and Windows RCE Risks Patched

Vulnerabilities

GitLab CVE-2026-19478: Active Exploitation Targets Public Projects

A critical GitLab code-injection flaw (CVE-2026-19478) is already being exploited against internet-facing instances. Organizations should urgently patch affected versions, review GraphQL access controls, and hunt for suspicious requests tied to exploitation attempts.

#gitlab#cve#vulnerability#patchmanagement#devsecops#threatintelligence
GitLab CVE-2026-19478: Active Exploitation Targets Public Projects

Patch Management

CISA Orders Emergency Patching for Actively Exploited Zimbra RCE

CISA added CVE-2026-73570 to KEV and required rapid mitigation due to active exploitation of Zimbra Collaboration Suite. Security teams should prioritize upgrades to fixed versions, validate SNMP exposure, and investigate signs of compromise on mail servers.

#zimbra#cve#kev#rce#patchmanagement#emailsecurity
CISA Orders Emergency Patching for Actively Exploited Zimbra RCE

Developer Security

Critical Keycloak CVE-2026-18963 Enables Account Takeover via Reset Flow

A critical Keycloak password-reset vulnerability (CVE-2026-18963) may allow unauthenticated account takeover in vulnerable deployments. Teams should upgrade to fixed releases immediately and disable 'Forgot password' temporarily if patching cannot be completed at once.

#keycloak#identitysecurity#cve#accounttakeover#patchmanagement#iam
Critical Keycloak CVE-2026-18963 Enables Account Takeover via Reset Flow