Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
TrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers
CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.
VulnerabilitiesIvanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340: Mass Exploitation Threatens Saudi Bank Mobile Fleets
Two chained Ivanti EPMM zero-days scored CVSS 9.8 are under mass exploitation, giving attackers unauthenticated remote code execution on MDM servers that manage thousands of corporate mobile devices — including those in Saudi financial institutions.
VulnerabilitiesChrome Zero-Day CVE-2026-5281: WebGPU Exploit Chain Threatens Saudi Financial Institutions
Google's fourth zero-day of 2026 targets Chrome's WebGPU layer via a use-after-free in Dawn. CISA added it to the KEV catalog — here's what Saudi banks and financial institutions must do now.
VulnerabilitiesProgress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now
Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Auth Bypass Puts Saudi Bank Server Infrastructure at Risk
A single crafted HTTP request can hand an attacker full admin access to your Cisco UCS servers. CVE-2026-20093 scores 9.8 CVSS and has no workaround — only a firmware update. Here's what Saudi bank infrastructure teams must do right now.
VulnerabilitiesInterlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure — Saudi Banks Must Audit Now
Interlock ransomware weaponized a CVSS 10.0 Cisco Firewall Management Center flaw for over a month before Cisco disclosed it. Saudi banks relying on Cisco firewalls face immediate exposure — here is what your SOC team must do today.
VulnerabilitiesMicrosoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now
Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.
VulnerabilitiesFortiClient EMS Zero-Day CVE-2026-35616: CVSS 9.1 Pre-Auth RCE Under Active Exploitation
Fortinet's emergency hotfix for CVE-2026-35616 confirms active zero-day exploitation of FortiClient EMS. Saudi banks running versions 7.4.5–7.4.6 face unauthenticated remote code execution risk.
VulnerabilitiesCisco IMC CVE-2026-20093: CVSS 9.8 Authentication Bypass Puts Saudi Bank Data Centers at Risk — Patch Now
A critical authentication bypass in Cisco IMC (CVE-2026-20093, CVSS 9.8) lets unauthenticated remote attackers seize admin access with no workaround available. Saudi financial institutions relying on Cisco UCS infrastructure must patch firmware immediately.
VulnerabilitiesCVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now
A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.
VulnerabilitiesCVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now
A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.
VulnerabilitiesF5 BIG-IP APM CVE-2025-53521: Unauthenticated RCE Puts 14,000+ Exposed Instances at Risk — What Saudi Banks Must Do Now
A critical F5 BIG-IP APM flaw reclassified from DoS to unauthenticated RCE is being actively exploited — with 14,000+ instances still exposed globally. Here is what Saudi financial institutions must patch immediately.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers