Tuesday , September 29 2026

Vulnerabilities

ALERT
Critical Fortinet Forticlient and Citrix NetScaler memory flaws now under attack

Threat intelligence company Defused said attackers are now actively exploiting a critical vulnerability in Fortinet’s FortiClient EMS platform. This SQL injection flaw, known as CVE-2026-21643, lets attackers run any code on systems that aren’t fixed. They can do this with simple attacks aimed at the FortiClient EMS web interface using …

Read More »

ALERT
CISA Alerts of F5 BIG-IP Flaw Actively Exploited in Attacks

F5 BIG-IP

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a new flaw in F5 BIG-IP systems to its Known Exploited Vulnerabilities (KEV) list. They warned that this flaw is being used in real-world attacks. The vulnarability, known as CVE-2025-53521, was officially noted on March 27, 2026, and federal agencies must …

Read More »

ALERT
CISA warns to patch DarkSword iOS flaws exploited in attacks

flaws

An urgent warning about three important Apple flaws that are being used by hackers. These security flaws, known as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were added to CISA’s list of Known Exploited Vulnerabilities (KEV). Security experts have connected this group of three flaws to the advanced DarkSword iOS attack method. Hackers …

Read More »

ALERT
Chrome update fixes 26 vulnerabilities enabling remote code execution

Chrome

Google has launched a major security update for its Chrome browser. This update fixes 26 unique vulnerabilities that might let attackers run harmful code from a distance. The new Stable channel update brings versions 146.0.7680.153 and 146.0.7680.154 for Windows and macOS. Linux users will get version 146.0.7680.153. This important update is …

Read More »

CISA warns feds to patch max-severity Cisco flaw by Sunday

Secure Firewall

Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to fix a serious flaw, CVE-2026-20131, in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22. Cisco released a security bulletin about the flaw on March 4. They told system managers to install the security updates quickly and said there …

Read More »

Bishop Fox Unveils Critical Pre-Auth SQL Injection in FortiClient EMS

Bishop Fox

Cybersecurity experts at Bishop Fox have unveiled an in-depth look at a critical vulnerability in FortiClient EMS, which is Fortinet’s central tool for managing endpoint security. This issue lets an attacker who is not logged in run any SQL commands, which could completely take over the management server and its …

Read More »

Google Alert Zero-Day For 3.5 billion Chrome Users: Forbes

zero-day

Google has released a second Chrome security update just 48 hours after the first, confirming two zero-day vulnerabilities that are being actively exploited. Google has issued an urgent security update for two zero-day vulnerabilities, CVE-2026-3909 and CVE-2026-3910. Google Confirms CVE-2026-3909 And CVE-2026-3910 are already being exploited. Although full access to the …

Read More »

ALERT
Chrome fix 29 vulnerabilities, must update immediately

Chrome

Google has released Chrome version 146 with important security updates for Windows, Mac, and Linux users. If the flaw remains unpatched, attackers run arbitrary code, compromise systems, or cause denial-of-service issues. The critical vulnerability in this release is CVE-2026-3913, which is a severe heap buffer overflow in the WebML component. …

Read More »

ALERT
Zoom Windows Workplace Vulnerabilities Allow Privilege Escalation

windows client

Zoom has issued four security bulletins detailing several vulnerabilities in its windows client suite. The critical vulnerability CVE-2026-30903 (ZSB-26005) affects the Mail feature in Zoom Workplace for Windows. The issue arises from External Control of File Name or Path, which allows attackers to manipulate file references and carry out unauthorized …

Read More »