Topic
Vulnerabilities
Critical and actively exploited zero-day vulnerabilities, prioritised for systems common in finance.
228 articles in this topic
Chrome CVE-2026-5281: Fourth Zero-Day of 2026 Is Under Active Exploitation — What Saudi Financial Institutions Must Do Now
Google's fourth Chrome zero-day of 2026 is actively exploited in the wild. CVE-2026-5281 — a use-after-free in the Dawn WebGPU layer — allows remote code execution and is now on CISA's KEV list. Saudi banks running unpatched Chrome deployments face immediate exposure.
VulnerabilitiesstrongSwan CVE-2026-25075: 15-Year-Old VPN Flaw That Can Bring Down Your Financial Network
A critical integer underflow in strongSwan's EAP-TTLS plugin — present for 15 years — lets unauthenticated attackers crash VPN gateways. Here is what Saudi financial institutions need to know and do right now.
VulnerabilitiesCisco IMC CVE-2026-20093: Critical 9.8 Auth Bypass Threatens Data Center Infrastructure
Cisco discloses CVE-2026-20093, a CVSS 9.8 authentication bypass in IMC affecting UCS servers. Saudi financial institutions must patch immediately — one HTTP request can hijack admin access to your data center hardware.
VulnerabilitiesCritical Mbed TLS RCE Flaw CVE-2026-34877: ATMs, POS Terminals, and IoT at Risk
A CVSS 9.8 remote code execution flaw in Mbed TLS threatens the cryptographic backbone of ATMs, payment terminals, and embedded banking systems across Saudi Arabia's financial sector.
Cloud & IdentityReact2Shell Exploits Breach 766 Hosts: Massive Credential Theft Campaign Targets Web Apps
A large-scale credential harvesting operation tracked as UAT-10608 is exploiting the React2Shell vulnerability to breach Next.js applications and steal AWS secrets, SSH keys, and database credentials at scale.
VulnerabilitiesOracle Identity Manager CVE-2026-21992: Pre-Auth RCE Threatens Saudi Financial IAM Systems
Oracle issued an emergency out-of-band patch for CVE-2026-21992, a CVSS 9.8 pre-authentication RCE flaw in Identity Manager. Saudi banks running Oracle Fusion Middleware face immediate risk.
VulnerabilitiesCVE-2026-25075: 15-Year strongSwan VPN Flaw Threatens Saudi Financial Remote Access
A critical integer underflow in strongSwan's EAP-TTLS plugin lets unauthenticated attackers crash VPN gateways. With 15 years of affected versions, Saudi financial institutions must patch immediately to protect remote access infrastructure.
VulnerabilitiesCVE-2026-32746: 32-Year-Old Telnetd Bug Gives Attackers Root Access — Why Saudi Financial Infrastructure Must Act Now
A 32-year-old buffer overflow in GNU telnetd now carries a CVSS 9.8 score and threatens every ICS, OT, and legacy network device still running Telnet on port 23 — including infrastructure inside Saudi financial institutions.
VulnerabilitiesChrome Zero-Day CVE-2026-5281: WebGPU Flaw Actively Exploited — What Saudi Financial Institutions Must Do Now
Google's fourth Chrome zero-day of 2026 is being exploited in the wild. CVE-2026-5281 targets the Dawn WebGPU engine and can lead to remote code execution — here's what SAMA-regulated organizations need to act on today.
Supply Chain & Third PartyTrivy Supply Chain Attack CVE-2026-33634: When Your Security Scanner Becomes the Threat
Attackers compromised Aqua Security's Trivy scanner to harvest CI/CD secrets from thousands of pipelines. Here's what happened, who's behind it, and why Saudi financial institutions running Trivy must act immediately.
VulnerabilitiesCisco SD-WAN Zero-Day CVE-2026-20127: CVSS 10 Flaw Exploited Since 2023 Threatens Saudi Network Infrastructure
A CVSS 10.0 zero-day in Cisco Catalyst SD-WAN has been exploited since 2023 by threat actor UAT-8616. CISA mandated emergency patching. Here's what Saudi financial institutions need to do now.
VulnerabilitiesLesson 24: Vulnerability Analysis — From Discovery to Assessment
Hands-On Cybersecurity Path — Lesson 4 of 10. Master the vulnerability analysis lifecycle: from scanning and discovery to risk-based prioritization aligned with SAMA and NCA requirements.
From reading to doing
Could your systems be exposed to a similar flaw?
A vulnerability assessment finds the weaknesses in your systems before attackers do, and ranks the fixes by risk.
Vulnerability Assessment
Systematic comprehensive scanning of your infrastructure vulnerabilities with a prioritized remediation report for immediate actio...
Internal Penetration Testing
Realistic internal attack simulation to measure your internal network resilience against insider threats
Web Application Penetration Testing
Deep security assessment of web applications following OWASP Top 10 to protect your data and customers