Intelligence Center

Actionable cybersecurity intelligence for municipalities, SMBs, and critical infrastructure.

27ADVISORIES
10VENDORS
172CVES
9KNOWN EXPLOITED

Latest Intelligence

Search and filter the advisory library. Sorted newest first by default.

Showing 27 of 27 advisories

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Aug 6, 2026 Google
Medium
CVE-2026-19137CVE-2026-19138CVE-2026-19139CVE-2026-19140CVE-2026-19141CVE-2026-19142+35 more

MS-ISAC Advisory 2026-078 (issued 8/6/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution in the context of the logged-on user via drive-by compromise. There are currently no reports of these vulnerabilities being exploited in the wild.

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Aug 3, 2026 SolarWinds
High
CVE-2026-28299CVE-2026-28323

MS-ISAC Advisory 2026-077 (issued 7/30/2026): multiple vulnerabilities in SolarWinds Web Help Desk, the most severe of which could allow authentication bypass. A SAML authentication bypass vulnerability (CVE-2026-28323) affects deployments with the SAML 2.0 authentication method enabled, and a denial-of-service vulnerability (CVE-2026-28299) could cause the Web Help Desk server to crash due to insufficient memory. There are currently no reports of these vulnerabilities being exploited in the wild.

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

Jul 30, 2026 Unattributed
Unspecified

CISA is observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the internet. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected PLCs by changing IP addresses, resulting in boil water notices and sustained manual operations. Water entities of all sizes are targeted, including through undocumented cellular modems.

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle Quarterly Critical Patches Issued July 21, 2026

Jul 22, 2026 Oracle
High

MS-ISAC Advisory 2026-071 (issued 7/22/2026): Oracle issued its quarterly Critical Patch Update on July 21, 2026, covering a wide range of Oracle products. The most severe vulnerabilities could allow for remote code execution in the context of the logged-on user. A full list of all vulnerabilities is contained in the Oracle announcement referenced in the advisory. There are currently no reports of these vulnerabilities being exploited in the wild.

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Jul 14, 2026 Adobe
High
CVE-2026-34690CVE-2026-47967CVE-2026-47968CVE-2026-47969CVE-2026-47971CVE-2026-47976+81 more

MS-ISAC Advisory 2026-067 (issued 7/14/2026): multiple vulnerabilities in Adobe products (After Effects, Animate, Audition, Bridge, Commerce/Magento, Experience Manager, Media Encoder, and others) could allow for arbitrary code execution. There are currently no reports of these vulnerabilities being exploited in the wild. Updates are provided across Adobe Security Bulletins APSB26-71 through APSB26-83.

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

Jul 1, 2026 Mozilla
High
CVE-2026-14241CVE-2026-57962CVE-2026-57963

MS-ISAC Advisory 2026-065 (issued 7/1/2026): multiple vulnerabilities in Mozilla products (Firefox, Thunderbird), the most severe of which could allow for arbitrary code execution. Includes a denial-of-service via malicious LDAP address-book server (CVE-2026-57962), chat UI manipulation by injection (CVE-2026-57963), and memory safety bugs fixed in Firefox 152.0.4 (CVE-2026-14241). There are currently no reports of these vulnerabilities being exploited in the wild.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Jun 25, 2026 Google
Medium
CVE-2026-13281CVE-2026-13282CVE-2026-13283

MS-ISAC Advisory 2026-062 (issued 6/25/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution in the context of the logged-on user via drive-by compromise. There are currently no reports of these vulnerabilities being exploited in the wild.

Oracle PeopleSoft PeopleTools Vulnerability Could Allow for Remote Code Execution (CVE-2026-35273)

Jun 11, 2026 Oracle
HighKnown Exploited
CVE-2026-35273

MS-ISAC Advisory 2026-059 (issued 6/11/2026): a vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools allows an attacker with network access via HTTP to completely take over the software, resulting in remote code execution and potential full system compromise without authentication or user interaction. Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

Cisco Unified Communications Manager Vulnerability Could Allow for Server-Side Request Forgery (CVE-2026-20230)

Jun 5, 2026 Cisco
Medium
CVE-2026-20230

MS-ISAC Advisory 2026-053 (issued 6/5/2026): a vulnerability in Cisco Unified Communications Manager and Session Management Edition is remotely exploitable without authentication and could allow for Server-Side Request Forgery, allowing an attacker to write arbitrary files to the system, including auto-executed locations, and potentially run remote commands or access the device remotely. Exploitation requires the WebDialer service to be enabled (disabled by default). There are currently no reports of exploitation in the wild, but public proof-of-concept code appears to exist.

Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens

May 22, 2026 Unattributed
Unspecified

The FBI issued a Public Service Announcement warning the public about an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, first seen in April 2026. Kali365 has primarily been distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user's credentials.

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

May 18, 2026 F5 (NGINX)
HighKnown Exploited
CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946

MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.

Adobe Acrobat Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-34621)

Apr 11, 2026 Adobe
MediumKnown Exploited
CVE-2026-34621

MS-ISAC Advisory 2026-033 (issued 4/11/2026): a vulnerability in Adobe Acrobat could allow for arbitrary code execution in the context of the logged-on user. The flaw is an Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) issue; exploitation requires user interaction, as a victim must open a malicious file. Adobe is aware of this vulnerability being exploited in the wild.

Fortinet FortiClientEMS Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-35616)

Apr 4, 2026 Fortinet
MediumKnown Exploited
CVE-2026-35616

MS-ISAC Advisory 2026-031 (issued 4/4/2026): an improper access control vulnerability in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows unauthenticated attackers to execute unauthorized code or commands via crafted network requests, which could allow for arbitrary code execution in the context of the affected service account. Fortinet has observed this vulnerability being exploited in the wild.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution (CVE-2026-5281 Actively Exploited)

Apr 1, 2026 Google
HighKnown Exploited
CVE-2026-5272CVE-2026-5273CVE-2026-5274CVE-2026-5275CVE-2026-5276CVE-2026-5277+15 more

MS-ISAC Advisory 2026-028 (issued 4/1/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution via drive-by compromise. Flaws include use-after-free, heap buffer overflow, integer overflow, object corruption, out-of-bounds read, and inappropriate implementation issues across CSS, GPU, Codecs, ANGLE, WebUSB, Web MIDI, V8, WebCodecs, Dawn, WebGL, PDF, WebView, Navigation, and Compositing. Google is aware that an exploit for CVE-2026-5281 exists in the wild.

CISA and FBI Warn of Russian Intelligence Services Targeting Commercial Messaging Apps

Mar 20, 2026 Unattributed
Unspecified

CISA and the FBI released a Public Service Announcement warning the public about ongoing phishing campaigns by cyber actors associated with Russian Intelligence Services targeting commercial messaging applications (CMAs). Targeted individuals include current and former U.S. government officials, military personnel, political figures, and journalists.

Multiple Vulnerabilities in Google Android OS Could Allow for Remote Code Execution

Nov 10, 2025 Google
High
CVE-2025-48581CVE-2025-48593

MS-ISAC Advisory 2025-103 (issued 11/10/2025): multiple vulnerabilities in Google Android OS, the most severe of which could allow for remote code execution in the context of the affected component, and privilege escalation. Google highlighted a severe zero-click vulnerability in the system's core components (CVE-2025-48593) that could allow attackers to execute malicious code remotely without any user interaction, requiring no additional privileges or user engagement.

CISA Emergency Directive 26-01: Mitigate Vulnerabilities in F5 Devices

Oct 15, 2025 F5
HighKnown Exploited

CISA issued Emergency Directive ED 26-01 directing Federal Civilian Executive Branch agencies to inventory F5 BIG-IP products, evaluate whether networked management interfaces are accessible from the public internet, and apply newly released F5 updates. A nation-state affiliated cyber threat actor has compromised F5 systems and exfiltrated data, including portions of the BIG-IP proprietary source code and vulnerability information, posing an imminent threat to networks using F5 devices and software.

Joint Cybersecurity Advisory on Countering Chinese State-Sponsored Actors Compromising Networks Worldwide

Aug 28, 2025 Unattributed
Unspecified

CISA, in partnership with the NSA, FBI, Canadian Centre for Cyber Security, UK National Cyber Security Centre, and other international partners, released a joint cybersecurity advisory (AA25-239A) detailing ongoing activity by People's Republic of China state-sponsored APT actors targeting critical infrastructure networks globally. These actors are exploiting vulnerabilities in backbone telecommunications infrastructure, specifically provider edge and customer edge routers, to establish long-term, covert access to sensitive systems. The actors have been observed modifying router firmware, leveraging trusted inter-provider connections, and using stealthy techniques to evade detection.

Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments

Aug 7, 2025 Microsoft
High
CVE-2025-53786

CISA is aware of the newly disclosed high-severity vulnerability CVE-2025-53786, which allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations. If not addressed, the vulnerability could impact the identity integrity of an organization's Exchange Online service. Microsoft has stated there is no observed exploitation as of the time of the alert's publication. CISA strongly urges organizations to implement Microsoft's guidance or risk hybrid cloud and on-premises total domain compromise.

CISA and USCG Issue Joint Advisory to Strengthen Cyber Hygiene in Critical Infrastructure

Aug 5, 2025 Unattributed
Unspecified

CISA, in partnership with the U.S. Coast Guard (USCG), released a joint Cybersecurity Advisory aimed at helping critical infrastructure organizations improve their cyber hygiene. This follows a proactive threat hunt engagement at a U.S. critical infrastructure facility. During the engagement, CISA and USCG did not find evidence of malicious cyber activity or actor presence but identified several cybersecurity risks. Mitigations include not storing passwords or credentials in plaintext, avoiding sharing local administrator account credentials, and implementing comprehensive logging.

CISA and Partners Release Updated Advisory on Scattered Spider Group

Jul 30, 2025 Unattributed
Unspecified

CISA, the FBI, the Canadian Centre for Cyber Security, the Royal Canadian Mounted Police, the Australian Cyber Security Centre, and other partners released an updated joint Cybersecurity Advisory on Scattered Spider, a cybercriminal group targeting commercial facilities sectors and subsectors. The advisory provides updated tactics, techniques, and procedures (TTPs) obtained through FBI investigations conducted through June 2025. Scattered Spider actors have used various ransomware variants in data extortion attacks, most recently including DragonForce ransomware, and frequently use social engineering such as phishing, push bombing, and SIM swap attacks to obtain credentials, install remote access tools, and bypass multi-factor authentication.

CISA: Microsoft Releases Guidance on Exploitation of SharePoint "ToolShell" Vulnerability (CVE-2025-53770)

Jul 24, 2025 Microsoft
HighKnown Exploited
CVE-2025-53770

CISA is aware of active exploitation of a remote code execution vulnerability enabling unauthorized access to on-premise SharePoint servers. Publicly reported as "ToolShell", the activity provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network. CISA later released an update to the alert adding indicators of compromise (IOCs) and new detection guidance, as well as information on post-exploit actions such as the deployment of ransomware. (This record merges the original July 20, 2025 alert with the July 24, 2025 update.)

Threat Actors Target U.S. Critical Infrastructure with LummaC2 Malware

May 22, 2025 Unattributed
Unspecified

CISA and the FBI released a joint cybersecurity advisory, LummaC2 Malware Targeting U.S. Critical Infrastructure Sectors (AA25-141B), detailing the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) linked to threat actors deploying LummaC2 malware. The malware is capable of infiltrating networks and exfiltrating sensitive information across U.S. critical infrastructure sectors. Threat actors were observed using LummaC2 as recently as May 2025, and the advisory includes IOCs tied to infections from November 2023 through May 2025.

Primary Mitigations to Reduce Cyber Threats to Operational Technology

May 8, 2025 Unattributed
Unspecified

CISA, the FBI, and other U.S. government partners published a fact sheet urging critical infrastructure entities with operational technology (OT) and industrial control systems (ICS) to implement five primary mitigations to improve their cybersecurity posture and reduce risk to unsophisticated cyber threat activity. CISA and partners also published an operational alert warning of unsophisticated cyber actors targeting ICS/SCADA systems within U.S. critical infrastructure sectors, specifically Energy and Transportation Systems. Poor cyber hygiene and exposed public-facing devices can escalate threats, leading to defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.

Critical / High Severity

Advisories rated High or Critical severity.

View all (13)

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Aug 3, 2026 SolarWinds
High
CVE-2026-28299CVE-2026-28323

MS-ISAC Advisory 2026-077 (issued 7/30/2026): multiple vulnerabilities in SolarWinds Web Help Desk, the most severe of which could allow authentication bypass. A SAML authentication bypass vulnerability (CVE-2026-28323) affects deployments with the SAML 2.0 authentication method enabled, and a denial-of-service vulnerability (CVE-2026-28299) could cause the Web Help Desk server to crash due to insufficient memory. There are currently no reports of these vulnerabilities being exploited in the wild.

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle Quarterly Critical Patches Issued July 21, 2026

Jul 22, 2026 Oracle
High

MS-ISAC Advisory 2026-071 (issued 7/22/2026): Oracle issued its quarterly Critical Patch Update on July 21, 2026, covering a wide range of Oracle products. The most severe vulnerabilities could allow for remote code execution in the context of the logged-on user. A full list of all vulnerabilities is contained in the Oracle announcement referenced in the advisory. There are currently no reports of these vulnerabilities being exploited in the wild.

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

Jul 14, 2026 Adobe
High
CVE-2026-34690CVE-2026-47967CVE-2026-47968CVE-2026-47969CVE-2026-47971CVE-2026-47976+81 more

MS-ISAC Advisory 2026-067 (issued 7/14/2026): multiple vulnerabilities in Adobe products (After Effects, Animate, Audition, Bridge, Commerce/Magento, Experience Manager, Media Encoder, and others) could allow for arbitrary code execution. There are currently no reports of these vulnerabilities being exploited in the wild. Updates are provided across Adobe Security Bulletins APSB26-71 through APSB26-83.

Known Exploited

Advisories flagged as exploited in the wild.

View all (9)

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle PeopleSoft PeopleTools Vulnerability Could Allow for Remote Code Execution (CVE-2026-35273)

Jun 11, 2026 Oracle
HighKnown Exploited
CVE-2026-35273

MS-ISAC Advisory 2026-059 (issued 6/11/2026): a vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools allows an attacker with network access via HTTP to completely take over the software, resulting in remote code execution and potential full system compromise without authentication or user interaction. Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

May 18, 2026 F5 (NGINX)
HighKnown Exploited
CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946

MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.

Adobe Acrobat Vulnerability Could Allow for Arbitrary Code Execution (CVE-2026-34621)

Apr 11, 2026 Adobe
MediumKnown Exploited
CVE-2026-34621

MS-ISAC Advisory 2026-033 (issued 4/11/2026): a vulnerability in Adobe Acrobat could allow for arbitrary code execution in the context of the logged-on user. The flaw is an Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) issue; exploitation requires user interaction, as a victim must open a malicious file. Adobe is aware of this vulnerability being exploited in the wild.

Vendor Advisories

Advisories attributed to a specific vendor.

View all (19)

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Aug 6, 2026 Google
Medium
CVE-2026-19137CVE-2026-19138CVE-2026-19139CVE-2026-19140CVE-2026-19141CVE-2026-19142+35 more

MS-ISAC Advisory 2026-078 (issued 8/6/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution in the context of the logged-on user via drive-by compromise. There are currently no reports of these vulnerabilities being exploited in the wild.

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Aug 3, 2026 SolarWinds
High
CVE-2026-28299CVE-2026-28323

MS-ISAC Advisory 2026-077 (issued 7/30/2026): multiple vulnerabilities in SolarWinds Web Help Desk, the most severe of which could allow authentication bypass. A SAML authentication bypass vulnerability (CVE-2026-28323) affects deployments with the SAML 2.0 authentication method enabled, and a denial-of-service vulnerability (CVE-2026-28299) could cause the Web Help Desk server to crash due to insufficient memory. There are currently no reports of these vulnerabilities being exploited in the wild.

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle Quarterly Critical Patches Issued July 21, 2026

Jul 22, 2026 Oracle
High

MS-ISAC Advisory 2026-071 (issued 7/22/2026): Oracle issued its quarterly Critical Patch Update on July 21, 2026, covering a wide range of Oracle products. The most severe vulnerabilities could allow for remote code execution in the context of the logged-on user. A full list of all vulnerabilities is contained in the Oracle announcement referenced in the advisory. There are currently no reports of these vulnerabilities being exploited in the wild.

Municipal Relevance

Guidance prioritized for municipalities and SLTT organizations.

View all (27)

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle PeopleSoft PeopleTools Vulnerability Could Allow for Remote Code Execution (CVE-2026-35273)

Jun 11, 2026 Oracle
HighKnown Exploited
CVE-2026-35273

MS-ISAC Advisory 2026-059 (issued 6/11/2026): a vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools allows an attacker with network access via HTTP to completely take over the software, resulting in remote code execution and potential full system compromise without authentication or user interaction. Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

May 18, 2026 F5 (NGINX)
HighKnown Exploited
CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946

MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution (CVE-2026-5281 Actively Exploited)

Apr 1, 2026 Google
HighKnown Exploited
CVE-2026-5272CVE-2026-5273CVE-2026-5274CVE-2026-5275CVE-2026-5276CVE-2026-5277+15 more

MS-ISAC Advisory 2026-028 (issued 4/1/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution via drive-by compromise. Flaws include use-after-free, heap buffer overflow, integer overflow, object corruption, out-of-bounds read, and inappropriate implementation issues across CSS, GPU, Codecs, ANGLE, WebUSB, Web MIDI, V8, WebCodecs, Dawn, WebGL, PDF, WebView, Navigation, and Compositing. Google is aware that an exploit for CVE-2026-5281 exists in the wild.

SMB Relevance

Guidance relevant to small and mid-sized businesses.

View all (27)

Cisco Secure Firewall Management Center Software Vulnerabilities Could Allow for Authentication Bypass

Jul 30, 2026 Cisco
HighKnown Exploited
CVE-2026-20079CVE-2026-20316

MS-ISAC Advisory 2026-075 (issued 7/30/2026): multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the most severe of which could allow authentication bypass. CVE-2026-20079 could allow an unauthenticated, remote attacker to execute script files and obtain root access to the underlying operating system; CVE-2026-20316 could allow login using a low-privileged account to access sensitive data. Cisco PSIRT is aware of active exploitation of CVE-2026-20316, and CISA added it to the Known Exploited Vulnerability Catalog.

Oracle PeopleSoft PeopleTools Vulnerability Could Allow for Remote Code Execution (CVE-2026-35273)

Jun 11, 2026 Oracle
HighKnown Exploited
CVE-2026-35273

MS-ISAC Advisory 2026-059 (issued 6/11/2026): a vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools allows an attacker with network access via HTTP to completely take over the software, resulting in remote code execution and potential full system compromise without authentication or user interaction. Bleeping Computer reports Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.

Multiple Vulnerabilities in NGINX Could Allow for Remote Code Execution

May 18, 2026 F5 (NGINX)
HighKnown Exploited
CVE-2026-40701CVE-2026-42934CVE-2026-42945CVE-2026-42946

MS-ISAC Advisory 2026-051 (issued 5/18/2026): multiple vulnerabilities in NGINX, the most severe of which could allow for remote code execution. Issues include a heap buffer overflow in ngx_http_rewrite_module (CVE-2026-42945), an excessive memory allocation issue in ngx_http_scgi_module and ngx_http_uwsgi_module (CVE-2026-42946), a use-after-free in ngx_http_ssl_module (CVE-2026-40701), and an out-of-bounds read in ngx_http_charset_module (CVE-2026-42934). A proof-of-concept exploit has been published by DepthFirst, and VulnCheck reported CVE-2026-42945 has been exploited in the wild.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution (CVE-2026-5281 Actively Exploited)

Apr 1, 2026 Google
HighKnown Exploited
CVE-2026-5272CVE-2026-5273CVE-2026-5274CVE-2026-5275CVE-2026-5276CVE-2026-5277+15 more

MS-ISAC Advisory 2026-028 (issued 4/1/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution via drive-by compromise. Flaws include use-after-free, heap buffer overflow, integer overflow, object corruption, out-of-bounds read, and inappropriate implementation issues across CSS, GPU, Codecs, ANGLE, WebUSB, Web MIDI, V8, WebCodecs, Dawn, WebGL, PDF, WebView, Navigation, and Compositing. Google is aware that an exploit for CVE-2026-5281 exists in the wild.

Need help responding to these threats?

Contact Grey Matter to assess, harden, or respond to threats in your environment.

Contact Grey Matter