Security news
Latest security news
Thu, 10 Sept 2026
- 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.
CERT-EUCitrix - 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
CERT-EUSAP - 2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.
CERT-EU - Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
The Record - Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate.
SecurityWeek - ShinyHunters expose 6.4M in attack on medical supplier McKesson
Have I Been Pwned logs leaked records spanning patients, staff, and providers
The Register - MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
Infosecurity MagazineAndroid - Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center - UK appoints new commander of National Cyber Force
The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.
The Record - Fortra security advisory (AV26-906)
Serial number: AV26-906 Date: September 10, 2026 As of September 9, 2026, Fortra is affected by a vulnerability in the following product: GoAnywhere MFT Endpoint Prior to 7.10.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Path Traversal in Fortra's GoAnywhere MFT Endpoint Product Security Advisories | Fortra
Canadian Centre for Cyber Security
About this news
- 1,371
- Stories
- 78
- Added in the last 24 hours
- 11
- Critical in the last 7 days
- 4
- Reported by several outlets