By industry

Government security news

All industries →

Wed, 9 Sept 2026

  1. Citrix security advisory (AV26-833) - Update 1

    Serial Number: AV26-833 Date: August 19, 2026 Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP Prior to 13.1-37.277 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-19490 to their Known Exploited Vulnerabilities (KEV) Database. NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 Citrix Security Advisories CISA KEV: CVE-2026-19490

    Canadian Centre for Cyber SecurityCitrix
  2. Cisco security advisory (AV26-197) – Update 3

    Serial number: AV26-197 Date: March 5, 2026 Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Cisco Security Cloud Control (SCC) Firewall Management – all versions Cisco Secure Firewall Management Center (FMC) – all versions Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions Update 1 On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited. Update 2 On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database. Update 3 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Secure Firewal

    CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco
  3. Fortinet security advisory (AV26-023) - Update 1

    Serial number: AV26-023 Date: January 13, 2026 Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to 6.4.16 FortiSASE 25.2 – version 25.2.b FortiSASE 25.1.a – version 25.1.a.2 FortiSIEM 7.4 – version 7.4.0 FortiSIEM 7.3 – versions 7.3.0 to 7.3.4 FortiSIEM 7.2 – versions 7.2.0 to 7.2.6 FortiSIEM 7.1 – versions 7.1.0 to 7.1.8 FortiSIEM 7.0 – versions 7.0.0 to 7.0.4 FortiSIEM 6.7 – versions 6.7.0 to 6.7.10 FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6 FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5 Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Heap-based

    Canadian Centre for Cyber SecurityFortinet
  4. US disrupts Xinbi Guarantee marketplace fueling the cyber scam economy

    The U.S. government also carried out a seizure of $52.8 million from 52 wallets connected to the platform.

    The Record
  5. Google security advisory (AV26-904)

    Serial Number: AV26-904 Date: September 9, 2026 As of September 8, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.37 Google is aware that an exploit for CVE-2026-87491 exists in the wild. On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87491 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Stable Channel Update for Desktop CISA KEV: CVE-2026-87491

    Canadian Centre for Cyber SecurityGoogle, Chrome
  6. US Government Accuses Chinese AI Firms of Distilling Frontier Models

    US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.

    Dark ReadingGoogle
  7. N-able security advisory (AV26-885) – Update 2

    Serial Number: AV26-885 Date: September 8, 2026 Updated: September 9, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page CISA KEV: CVE-2026-86218

    CriticalUsed in attacksCanadian Centre for Cyber SecurityN-able
  8. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

    CriticalUsed in attacksThe Hacker NewsN-able

Tue, 8 Sept 2026

  1. [Control Systems] Inductive Automation security advisory (AV26-892)

    Serial Number: AV26-892 Date: September 8, 2026 As of September 4, 2026, Inductive Automation is affected by a vulnerability in the following product: Ignition Prior to or equal to 8.1.53 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CSAF/csaf_files/OT/white/2026/icsa-26-246-06.json at develop · cisagov/CSAF · GitHub Inductive Automation Ignition | CISA

    Canadian Centre for Cyber SecurityGitHub
  2. The US military just turned off ad tracking on its phones. Maybe you should too

    Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog.

    Graham Cluley

Latest government briefing

Government Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

40 stories affecting government tracked in the last seven days, 5 rated critical, 2 vulnerabilities added to the CISA Known Exploited catalogue.

About government news

135
Stories
56
In the last 7 days
6
Critical in the last 7 days