Security news
Latest security news
Wed, 9 Sept 2026
- Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
CyberScoop - AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 - Update 1
Number: AL26-019 Date: September 4, 2026 Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) Footnote 1 . In response to the vendor advisory released on August 19, 2026, the Cyber Centre released AV26-833 on August 19, 2026 Footnote 2 . Tracked as CVE-2026-19490 Footnote 3 , this vulnerability is an Authentication Bypass Using an Alternate Path vulnerability (CWE-288) Footnote 4 . The vulnerability may allow a remote, unauthenticated attacker to circumvent authentication controls on NetScaler appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, or RDP Proxy, or as an AAA virtual server. Tracked as CVE-2026-19489 Footnote 5
Canadian Centre for Cyber SecurityCitrix - Citrix security advisory (AV26-833) - Update 1
Serial Number: AV26-833 Date: August 19, 2026 Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories CISA KEV: CVE-2026-19490
Canadian Centre for Cyber SecurityCitrix - Cisco security advisory (AV26-197) – Update 3
Serial number: AV26-197 Date: March 5, 2026 Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Cisco Security Cloud Control (SCC) Firewall Management – all versions Cisco Secure Firewall Management Center (FMC) – all versions Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions Update 1 On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited. Update 2 On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database. Update 3 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Secure Firewal
CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco - Fortinet security advisory (AV26-023) - Update 1
Serial number: AV26-023 Date: January 13, 2026 Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to 6.4.16 FortiSASE 25.2 – version 25.2.b FortiSASE 25.1.a – version 25.1.a.2 FortiSIEM 7.4 – version 7.4.0 FortiSIEM 7.3 – versions 7.3.0 to 7.3.4 FortiSIEM 7.2 – versions 7.2.0 to 7.2.6 FortiSIEM 7.1 – versions 7.1.0 to 7.1.8 FortiSIEM 7.0 – versions 7.0.0 to 7.0.4 FortiSIEM 6.7 – versions 6.7.0 to 6.7.10 FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6 FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5 Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Heap-based
Canadian Centre for Cyber SecurityFortinet - Google security advisory (AV26-904)
Serial Number: AV26-904 Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit for CVE-2026-87491 exists in the wild. On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Stable Channel Update for Desktop CISA KEV: CVE-2026-87491
Canadian Centre for Cyber SecurityGoogle, Chrome - ConnectWise security advisory (AV26-903)
Serial number: AV26-903 Date: September 9, 2026 As of September 8, 2026, ConnectWise is affected by a vulnerability in the following product: ScreenConnect versions prior to 26.6.5 Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. ScreenConnect 26.6.5 Security Patch ConnectWise - Security Bulletins
Canadian Centre for Cyber Security - Check Point security advisory (AV26-902)
Serial Number: AV26-902 Date: September 9, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution Check Point Security
Canadian Centre for Cyber Security - N-able security advisory (AV26-885) – Update 2
Serial Number: AV26-885 Date: September 8, 2026 Updated: September 9, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page CISA KEV: CVE-2026-86218
CriticalUsed in attacksCanadian Centre for Cyber SecurityN-able - FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
CyberScoop
About this news
- 1,265
- Stories
- 33
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets