Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

TrueConf CVE-2026-3502: Video Conferencing Update Hijack Exploited by State-Sponsored Hackers

CISA flags TrueConf Client CVE-2026-3502 after Chinese-linked hackers weaponize its update mechanism. Saudi banks relying on video conferencing must audit software integrity controls immediately.

6 Apr 2026 5 min
Vulnerabilities

Ivanti EPMM Zero-Days CVE-2026-1281 & CVE-2026-1340: Mass Exploitation Threatens Saudi Bank Mobile Fleets

Two chained Ivanti EPMM zero-days scored CVSS 9.8 are under mass exploitation, giving attackers unauthenticated remote code execution on MDM servers that manage thousands of corporate mobile devices — including those in Saudi financial institutions.

6 Apr 2026 6 min
Vulnerabilities

Chrome Zero-Day CVE-2026-5281: WebGPU Exploit Chain Threatens Saudi Financial Institutions

Google's fourth zero-day of 2026 targets Chrome's WebGPU layer via a use-after-free in Dawn. CISA added it to the KEV catalog — here's what Saudi banks and financial institutions must do now.

6 Apr 2026 5 min
Vulnerabilities

Progress ShareFile Pre-Auth RCE Chain: 30,000 Servers Exposed and Saudi Banks Must Patch Now

Two chained ShareFile flaws give attackers full server control without credentials. With 30,000 instances exposed globally, Saudi financial institutions running on-premise ShareFile must act before exploitation campaigns begin.

6 Apr 2026 6 min
Vulnerabilities

Cisco IMC CVE-2026-20093: CVSS 9.8 Auth Bypass Puts Saudi Bank Server Infrastructure at Risk

A single crafted HTTP request can hand an attacker full admin access to your Cisco UCS servers. CVE-2026-20093 scores 9.8 CVSS and has no workaround — only a firmware update. Here's what Saudi bank infrastructure teams must do right now.

5 Apr 2026 6 min
Vulnerabilities

Interlock Ransomware Exploited Cisco FMC Zero-Day for 36 Days Before Disclosure — Saudi Banks Must Audit Now

Interlock ransomware weaponized a CVSS 10.0 Cisco Firewall Management Center flaw for over a month before Cisco disclosed it. Saudi banks relying on Cisco firewalls face immediate exposure — here is what your SOC team must do today.

5 Apr 2026 6 min
Vulnerabilities

Microsoft Patches Four Critical Azure Flaws at CVSS 10.0 — Saudi Banks on Azure Must Act Now

Microsoft disclosed four critical Azure vulnerabilities — two scoring a perfect CVSS 10.0 — affecting AI Foundry, Kubernetes Service, Custom Locations, and MCP Server. Saudi banks running workloads on Azure face urgent remediation requirements under SAMA CSCC.

5 Apr 2026 6 min
Vulnerabilities

FortiClient EMS Zero-Day CVE-2026-35616: CVSS 9.1 Pre-Auth RCE Under Active Exploitation

Fortinet's emergency hotfix for CVE-2026-35616 confirms active zero-day exploitation of FortiClient EMS. Saudi banks running versions 7.4.5–7.4.6 face unauthenticated remote code execution risk.

5 Apr 2026 5 min
Vulnerabilities

Cisco IMC CVE-2026-20093: CVSS 9.8 Authentication Bypass Puts Saudi Bank Data Centers at Risk — Patch Now

A critical authentication bypass in Cisco IMC (CVE-2026-20093, CVSS 9.8) lets unauthenticated remote attackers seize admin access with no workaround available. Saudi financial institutions relying on Cisco UCS infrastructure must patch firmware immediately.

4 Apr 2026 6 min
Vulnerabilities

CVE-2026-3055: Citrix NetScaler's SAML IDP Flaw Is Being Actively Probed — What Saudi Banks Must Act On Now

A CVSS 9.3 memory overread in Citrix NetScaler is being actively probed by threat actors. Saudi banks using NetScaler as a SAML Identity Provider face credential exposure without any authentication required. Patch or isolate today.

4 Apr 2026 5 min
Vulnerabilities

CVE-2026-23813: Critical HPE Aruba AOS-CX Flaw Grants Unauthenticated Admin Access — What Saudi Banks Must Do Now

A CVSS 9.8 authentication bypass in HPE Aruba AOS-CX switches lets any remote attacker reset admin credentials — no authentication required. Saudi banks running this hardware in branch or data-center networks need to act before this changes exploitation status.

4 Apr 2026 5 min
Vulnerabilities

F5 BIG-IP APM CVE-2025-53521: Unauthenticated RCE Puts 14,000+ Exposed Instances at Risk — What Saudi Banks Must Do Now

A critical F5 BIG-IP APM flaw reclassified from DoS to unauthenticated RCE is being actively exploited — with 14,000+ instances still exposed globally. Here is what Saudi financial institutions must patch immediately.

3 Apr 2026 5 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality