Topic

Vulnerabilities

Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.

228 articles in this topic

Vulnerabilities

Chrome CVE-2026-5281: Fourth Zero-Day of 2026 Is Under Active Exploitation — What Saudi Financial Institutions Must Do Now

Google's fourth Chrome zero-day of 2026 is actively exploited in the wild. CVE-2026-5281 — a use-after-free in the Dawn WebGPU layer — allows remote code execution and is now on CISA's KEV list. Saudi banks running unpatched Chrome deployments face immediate exposure.

3 Apr 2026 5 min
Vulnerabilities

strongSwan CVE-2026-25075: 15-Year-Old VPN Flaw That Can Bring Down Your Financial Network

A critical integer underflow in strongSwan's EAP-TTLS plugin — present for 15 years — lets unauthenticated attackers crash VPN gateways. Here is what Saudi financial institutions need to know and do right now.

3 Apr 2026 5 min
Vulnerabilities

Cisco IMC CVE-2026-20093: Critical 9.8 Auth Bypass Threatens Data Center Infrastructure

Cisco discloses CVE-2026-20093, a CVSS 9.8 authentication bypass in IMC affecting UCS servers. Saudi financial institutions must patch immediately — one HTTP request can hijack admin access to your data center hardware.

3 Apr 2026 5 min
Vulnerabilities

Critical Mbed TLS RCE Flaw CVE-2026-34877: ATMs, POS Terminals, and IoT at Risk

A CVSS 9.8 remote code execution flaw in Mbed TLS threatens the cryptographic backbone of ATMs, payment terminals, and embedded banking systems across Saudi Arabia's financial sector.

3 Apr 2026 6 min
Cloud & Identity

React2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps

A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.

3 Apr 2026 5 min
Vulnerabilities

Oracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems

Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.

3 Apr 2026 5 min
Vulnerabilities

CVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access

A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.

1 Apr 2026 6 min
Vulnerabilities

CVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now

A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.

1 Apr 2026 5 min
Vulnerabilities

Chrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now

Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.

1 Apr 2026 5 min
Supply Chain & Third Party

Trivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat

Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.

1 Apr 2026 5 min
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure

A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.

1 Apr 2026 6 min
Vulnerabilities

Lesson 24: Vulnerability Analysis — From Discovery to Assessment

Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.

1 Apr 2026 8 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality