Security news

Latest security news

Thu, 10 Sept 2026

  1. 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

    On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

    CERT-EUCitrix
  2. 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

    On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.

    CERT-EUSAP
  3. 2026-012: Critical Vulnerabilities in Check Point Products

    On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

    CERT-EU
  4. Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers

    Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.

    The Record
  5. UK appoints new commander of National Cyber Force

    The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.

    The Record
  6. Fortra security advisory (AV26-906)

    Serial number: AV26-906 Date: September 10, 2026 As of September 9, 2026, Fortra is affected by a vulnerability in the following product: GoAnywhere MFT Endpoint Prior to 7.10.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Path Traversal in Fortra's GoAnywhere MFT Endpoint Product Security Advisories | Fortra

    Canadian Centre for Cyber Security
  7. Critical NetScaler Vulnerability Exploited in Attacks

    Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

    SecurityWeek
  8. Palo Alto Networks security advisory (AV26-905)

    Serial number: AV26-905 Date: September 10, 2026 As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products: Cloud NGFW All on AWS*, All on Azure* PAN-OS Multiple versions Prisma Access Multiple versions Prisma Browser Prior to 151.26.5.170 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) Palo Alto Networks Security Advisories

    Canadian Centre for Cyber SecurityAWS, Palo Alto
  9. Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

    Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

    The Hacker News
  10. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

    The Hacker NewsPaperCut

About this news

1,264
Stories
36
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets