
Microsoft Entra ID: CVE-2026-69836 patched
Microsoft fixed CVE-2026-69836 in Entra ID, a critical deserialization flaw rated CVSS 10.0. No customer action is needed.
Aug 23, 2026 · 2 min
Up-to-date cyber intelligence coverage. Filter by category or browse the full archive.

Microsoft fixed CVE-2026-69836 in Entra ID, a critical deserialization flaw rated CVSS 10.0. No customer action is needed.
Aug 23, 2026 · 2 min

COLCERT warned on Operation Dream Job and CVE-2026-68820, a Windows flaw used to raise privileges and deploy malware.
Aug 22, 2026 · 3 min

CISA added four actively exploited flaws in Apple, Microsoft and VMware to its KEV catalog and set the federal deadline for Aug. 21.
Aug 22, 2026 · 3 min

INCIBE-CERT issued alerts on PLCnext, Red Hat Quay, and OpenShift components, including one critical flaw with no active exploitation seen.
Aug 20, 2026 · 2 min

CERT-PY issued an alert on critical Ubiquiti flaws, while CSIRT Panama also warned about a PAN-OS issue on August 13, 2026.
Aug 18, 2026 · 2 min

CISA added CVE-2026-20349 to its KEV catalog. The Cisco ASA and FTD flaw can trigger remote reboots, and hotfixes are available.
Aug 17, 2026 · 2 min

ShieldBreak targets CVE-2026-50656 and, according to multiple reports, can raise privileges to SYSTEM on fully patched Windows.
Aug 15, 2026 · 3 min

Telconet and Shadowserver confirmed active exploitation of CVE-2026-59310 in vCenter. Broadcom has issued patches and there is no workaround.
Aug 14, 2026 · 2 min

Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.
Aug 12, 2026 · 3 min

CISA added CVE-2026-34486 to KEV after active Apache Tomcat exploitation and set an Aug. 7 remediation deadline for federal agencies.
Aug 10, 2026 · 2 min

CISA confirmed exploitation of CVE-2026-8037 in Progress LoadMaster and ECS Connections Manager. Progress published fixed versions.
Aug 10, 2026 · 2 min

CSIRT Panama and Check Point warned about CVE-2026-18574, a critical flaw that can bypass authentication and run commands.
Aug 7, 2026 · 2 min

CISA added SharePoint and Check Point flaws to KEV as active exploitation continues. Latin America faces added pressure from ERP and firewall bugs.
Aug 4, 2026 · 3 min

N-able issued a hotfix for CVE-2026-18577, an active authentication bypass in N-central affecting MSPs.
Aug 4, 2026 · 3 min

INCIBE-CERT issued an alert for five VMware vulnerabilities, including three critical flaws. One can bypass authentication in vCenter.
Aug 3, 2026 · 2 min

CISA added Cisco FMC flaw CVE-2026-20316 to its KEV catalog after confirming active exploitation. Cisco has released hotfixes and no workarounds exist.
Jul 30, 2026 · 2 min

CISA added a critical, actively exploited flaw in Arista VeloCloud Orchestrator on-premises to its KEV catalog, with an urgent patch due.
Jul 28, 2026 · 2 min

Chile’s CSIRT warned of critical Ivanti and Citrix flaws with active exploitation, and urged patching, config review, and log monitoring.
Jul 27, 2026 · 2 min

CERT.br warned of active exploitation of CVE-2024-24919 in enterprise VPNs used in Brazil and urged immediate patching.
Jul 26, 2026 · 2 min

CSIRT Chile warned about critical OpenSSH flaw CVE-2024-6387 and confirmed active exploitation. Patch or mitigate now.
Jul 26, 2026 · 2 min

CISA, NSA and FBI warned on a Zimbra flaw abused by LAUNDRY BEAR to steal email, 2FA codes and passwords with a single message.
Jul 24, 2026 · 1 min

CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.
Jul 19, 2026 · 3 min

CTIR Gov and Costa Rica’s CSIRT are coordinating alerts over an active campaign targeting Joomla sites with outdated JCE.
Jul 16, 2026 · 2 min

Balbooa Forms for Joomla had a critical RCE abused as a zero-day. Patch 2.4.1 landed July 9, and CISA added it to KEV.
Jul 15, 2026 · 3 min

CVE-2019-1579 in GlobalProtect and CVE-2026-10520 in Ivanti Sentry are among July 2026's most actively exploited flaws.
Jul 15, 2026 · 2 min

ColCERT warned about the CHARLIE relay network, linked to APT5 and APT15, affecting telecom operators and providers in Colombia.
Jul 12, 2026 · 2 min

ColCERT, INCIBE, and ECUCERT flagged active malicious activity, including brute force in Colombia and an exploited ColdFusion flaw.
Jul 12, 2026 · 3 min

INCIBE warned about three flaws in Proteus and seven in ABB products, including one critical issue, and urged immediate patching.
Jul 9, 2026 · 2 min

CISA added CVE-2026-45659, a Microsoft SharePoint flaw, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Federal
Jul 6, 2026 · 2 min

Spain’s national cybersecurity institute warned on July 3, 2026 about six vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Jul 6, 2026 · 2 min