Tuesday , September 29 2026

Vulnerabilities

CISA Flags Actively Exploited SolarWinds RCE Flaw to KEV 

SolarWinds

CISA announced on Tuesday that a security flaw in SolarWinds Web Help Desk is now listed in its Known Exploited Vulnerabilities catalog, indicating it is actively being targeted in attacks. The vulnerability, CVE-2025-40551 (CVSS score: 9.8), allows untrusted data deserialization that could enable remote code execution. Web Help Desk is …

Read More »

Hackers Exploiting Microsoft Office 0-day Vuln to Deploy Malware: CERT warn

Microsoft Office

The Russia-linked group UAC-0001, or APT28, is exploiting a zero-day vulnerability in Microsoft Office. The group exploits this flaw to install advanced malware targeting Ukrainian government and EU organizations. The vulnerability, identified as CVE-2026-21509, was disclosed by Microsoft on January 26, 2026, with warnings about active exploitation in the wild. …

Read More »

Researchers Identify 175,000 Exposed Ollama AI Servers in 130 Countries

175,000

A joint investigation by SentinelOne SentinelLABS and Censys found that open-source AI deployment has led to a large “unmanaged, publicly accessible AI compute infrastructure” with 175,000 unique Ollama hosts in 130 countries. These systems operate outside the usual safety and monitoring measures set by platform providers. According to the company, …

Read More »

Fortinet discloses actively exploited flaw in FortiOS, FortiAnalyzer and FortiManager

Fortinet

Fortinet has revealed a critical vulnerability affecting its products. The company issued a Public Advisory on January 27 after noticing initial attacks on January 23, when it disabled two malicious accounts exploiting the single sign-on feature in FortiOS. In December 2025, an advisory was issued about two previous SSO bypass …

Read More »

Urgently Patch
ALERT! Microsoft patches actively exploited Office zero-day vuln

office

Microsoft has issued emergency security updates to fix a critical zero-day vulnerability in Microsoft Office that has been actively exploited. The vulnerability, CVE-2026-21509, affects several Office versions: Microsoft Office 2016, 2019, LTSC 2021, LTSC 2024, and Microsoft 365 Apps for Enterprise (the company’s cloud-based subscription service). “Reliance on untrusted inputs …

Read More »

GitLab Releases Critical Patches for High-Severity Vulnerabilities

Gitlab

GitLab has released a new patch to fix security vulnerabilities and stability issues in versions 18.8.2, 18.7.2, and 18.6.4 for both Community and Enterprise Editions. These updates are ready for self-managed installations and include crucial bug fixes and security improvements. Administrators should upgrade as soon as possible. The GitLab patch …

Read More »

CISA Adds Actively Exploited VMware vCenter Flaw to KEV Catalog

VMware vCenter

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a serious security flaw in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities catalog on Friday, noting it was actively being exploited despite a patch released in June 2024. CVE-2024-37079 (CVSS score: 9.8) is a vulnerability related to a heap …

Read More »

CVE-2026-20045
Cisco discloses Unified Communications RCE zero day flaw exploited in attacks

Secure Email Gateway

Cisco revealed a zero-day RCE vulnerability, CVE-2026-20045, that is being actively exploited. The vulnerability in key Unified Communications products lets unauthenticated attackers execute arbitrary commands on the OS, risking root access. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability …

Read More »