Tag: critical

security

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778.  CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received […]

Mehr lesen →
soc

CVE-2026-94545: Critical Next.js ImageResponse Flaw Enables Remote Code Execution

A critical vulnerability in Next.js could allow remote attackers to execute arbitrary code on vulnerable servers through the framework’s ImageResponse functionality. Tracked as CVE-2026-94545, the flaw affects the Node.js implementation of ImageResponse in next/og and carries a CVSS score of 9.5. Vercel addressed the issue on September 22, 2026, with the release of Next.js 16.3.6. […]

Mehr lesen →
soc

CVE-2026-87902: Critical WordPress Core Flaw Enables Unauthenticated RCE Under Certain Conditions

WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS […]

Mehr lesen →
soc

CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Exploited for Remote Code Execution

F5 has disclosed a critical zero-day vulnerability affecting BIG-IP Access Policy Manager (APM) that is already being exploited in the wild. Tracked as CVE-2026-94127, the flaw can allow an unauthenticated remote attacker to execute arbitrary code on vulnerable BIG-IP systems by sending specially crafted traffic to an affected OAuth configuration. The vulnerability is a heap-based […]

Mehr lesen →