Today’s newsletter highlights a series of particularly severe security vulnerabilities, many of which are already actively exploited in cyber attacks. The CyberSec Intelligence team recommends immediate analysis of the affected systems and the application of appropriate patches to protect the IT infrastructure.
Actively Exploited Vulnerabilities
- Fortinet FortiMail (CVE-2026-104286): A path traversal vulnerability and incorrect neutralization of NULL characters allows unauthenticated attackers to write arbitrary files on the system through modified HTTP/HTTPS requests. Source: NVD.
- Cisco Catalyst SD-WAN Manager (CVE-2026-76504): A hexadecimal decoding error in URI handling allows unauthenticated attackers to access the system with administrator privileges. Source: NVD.
- Apple Multiple Products (CVE-2026-86950): An out-of-bounds write vulnerability in the CoreGraphics component can lead to arbitrary code execution on iOS, macOS, and iPadOS. Source: NVD.
- Citrix NetScaler (CVE-2026-88772): Improper restriction of operations within memory bounds in NetScaler ADC and Gateway allows remote code execution or causing a denial of service (DoS). Source: NVD.
- Citrix NetScaler (CVE-2026-88771): An input validation error in NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands. Source: NVD.
- MikroTik RouterOS (CVE-2026-67279): Incorrect application of logical flow allows an unauthenticated client to open a session and send execution requests, and the vulnerability can be chained with CVE-2026-86060. Source: NVD.
- Microsoft SharePoint (CVE-2026-65660): A code injection vulnerability allows an authorized attacker to execute code over the network. Source: NVD.
- WordPress Core (CVE-2026-87902): A Remote File Inclusion (RFI) vulnerability in page template resolution allows attackers to include local PHP files and execute remote code. Source: NVD.
New Critical Vulnerabilities
- Joomla OrdaSoft CCK Extension (CVE-2026-102427): Allows unauthenticated remote code execution (RCE) due to an unsecured file uploader that accepts polyglot image/PHP files. Source: NVD.
- Mooncake Transfer Engine (CVE-2026-103764): An untrusted pointer dereference in ServerSession allows unauthenticated attackers to read and write process memory via TCP port. Source: NVD.
- Mooncake (CVE-2026-103765): Lack of authentication in the HTTP /metadata API allows attackers to delete, read, or overwrite transfer engine keys. Source: NVD.
- 389-ds-base (CVE-2026-86345): Failure to flush the connection buffer during StartTLS negotiation allows LDAP message injection and bypass of authentication mechanisms. Source: NVD.
- WordPress DevKit Pro Plugin (CVE-2026-14378): Authentication bypass by trusting attacker-controlled cookies, allowing complete administrative takeover of the site. Source: NVD.
From the Security Press
- AI Threats and Exposed Secrets: An analysis highlights how seemingly harmless elements like the cache or inspection processes of AI models can be used to launch complex cyber attacks. Source: The Hacker News.
- Massive Attack on Bitget: Cryptocurrency exchange platform Bitget confirmed a theft of 387.5 million dollars caused by the exploitation of a zero-day vulnerability in a third-party security product. Source: The Hacker News.
- Post-Exploitation Payloads on Citrix NetScaler: Active attacks have been observed where NetScaler vulnerabilities are used to drop web shells disguised as CSS style files to steal configuration data. Source: The Hacker News.
What We Recommend
- Immediate Patch Management: Prioritize updating affected Fortinet, Citrix, Cisco systems and MikroTik routers impacted by actively exploited vulnerabilities.
- Auditing Plugins and Extensions: Urgently disable or update the DevKit Pro plugin for WordPress and the OrdaSoft CCK extension for Joomla in all production environments.
- Rigorous Network Monitoring: Configure IDS/IPS systems to block unusual traversal-type requests and code injection attempts on exposed ports.
- Securing Directory Services: Apply correct security configurations for LDAP and StartTLS to prevent interception and message collision attacks.
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




