Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
CVE-2026-41940: cPanel Zero-Day Exploited for Months Puts 1.5 Million Servers at Risk
A CVSS 9.8 authentication bypass in cPanel & WHM was exploited as a zero-day for two months before patching. With 1.5M servers exposed, Saudi financial institutions must act now.
VulnerabilitiesMiniPlasma Zero-Day: A Six-Year-Old Windows Flaw Returns to Grant SYSTEM Access on Fully Patched Machines
A weaponized PoC exploit dubbed MiniPlasma grants SYSTEM privileges on fully patched Windows 11 by abusing a Cloud Filter driver flaw Microsoft supposedly fixed in 2020. No patch exists today.
VulnerabilitiesSEPPmail Gateway Flaws CVE-2026-2743: When Your Email Security Becomes the Attack Vector
Seven critical SEPPMail flaws — including CVSS 10.0 RCE — turn secure email gateways into wiretaps. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-21858: Critical n8n RCE Flaw Gives Attackers Full Control of Your Automation Pipelines
A perfect CVSS 10.0 unauthenticated RCE in n8n lets attackers hijack automation pipelines and every system they connect to. Here's what Saudi institutions must do now.
VulnerabilitiesYellowKey BitLocker Bypass CVE-2026-45585: A USB Drive Is All It Takes to Unlock Your Encrypted Data
A researcher's frustration with Microsoft's bug bounty process led to the public release of YellowKey — a BitLocker bypass that decrypts protected volumes with nothing more than a USB stick and a reboot. Here's what Saudi financial institutions need to do right now.
VulnerabilitiesCVE-2026-23918: Apache HTTP/2 Double-Free Flaw Crashes Servers and Opens the Door to RCE
Critical Apache HTTP/2 double-free vulnerability CVE-2026-23918 is actively exploited for DoS with RCE potential. Saudi financial institutions must patch to 2.4.67 immediately to meet SAMA CSCC and NCA ECC requirements.
VulnerabilitiesCVE-2026-31431 Copy Fail: 732 Bytes to Root on Every Linux Server Since 2017
A 732-byte Python script can root nearly every Linux distribution shipped since 2017. CVE-2026-31431 exploits a logic flaw in the kernel's crypto API — and it escapes containers too.
VulnerabilitiesDrupal SA-CORE-2026-004: No-Auth SQL Injection Threatens Every PostgreSQL-Backed Site
Drupal released emergency patches for a highly critical SQL injection that requires zero authentication. If your organization runs Drupal on PostgreSQL, you have hours — not days — before weaponized exploits hit the wild.
VulnerabilitiesCVE-2026-42897: Exchange Server Zero-Day Turns Your Inbox Into an Attack Surface
Microsoft confirms active exploitation of CVE-2026-42897, a zero-day XSS flaw in Exchange Server OWA. No patch available yet — here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41096: Windows DNS Client RCE Lets Attackers Hijack Every Endpoint Without a Click
Microsoft's May 2026 Patch Tuesday disclosed CVE-2026-41096, a CVSS 9.8 heap overflow in the Windows DNS Client enabling unauthenticated RCE on every Windows endpoint. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-0073: Android Zero-Click RCE Lets Attackers Hijack Devices Over Wi-Fi
A CVSS 9.8 zero-click flaw in Android's wireless ADB lets nearby attackers gain full shell access — no tap required. Saudi financial institutions running BYOD and mobile banking must patch immediately.
VulnerabilitiesCVE-2026-41103: Critical Microsoft SSO Plugin Flaw Lets Attackers Forge Identities in Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin for Jira and Confluence lets unauthenticated attackers forge identities and gain admin access — bypassing Entra ID entirely. Here's what Saudi CISOs must do now.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers