Thread · Developing story

Edge software under attack

Routers, appliances, control panels and storefronts sit where the internet reaches, are usually run by organisations with nobody on call, and keep being exploited before their vendors ship a fix. We track each disclosure and how long the attackers were already inside.

34 stories · Updated 17 Sep 2026

17 Sep 2026 · Latest Forged Admin Tokens Are Hitting WSO2 API Gateways Patched Five Months Ago

A token signed with an algorithm the gateway does not support is accepted anyway. WSO2 scored it 10.0 and shipped the fix in April; the forged tokens started arriving on 13 Septemb...

16 Sep 2026 A Crafted Email Is Enough to Get Root on Cisco's Secure Email Gateway

A mail gateway reads every message a company receives. Cisco's can be taken over by one of them, and the flaw was already being exploited when it was disclosed.

15 Sep 2026 A Plesk Backup Restore Lets a Hosting Customer Get Root on the Whole Server

CVE-2026-68488 needs only a customer's own panel login and FTP access. On shared hosting, that turns one account into every site on the machine. It scores 9.9.

15 Sep 2026 A PAN-OS Flaw Gives Root on Palo Alto Hardware, and There Is No Workaround

CVE-2026-0310 is reachable through a dataplane interface, not only the management plane, and Palo Alto lists no mitigation but the patch. Nobody has exploited it yet.

14 Sep 2026 The Dutch Warned About Check Point's VPN Flaws Before Anyone Exploited Them

Two pre-authentication flaws in Check Point VPN were patched on 9 September. Three days later the Dutch NCSC said attempts are coming. That order is the unusual part.

13 Sep 2026 CISA Added Five Exploited Flaws, All in Software That Manages Other Machines

JFrog Artifactory builds your software, ConnectWise ScreenConnect reaches into your machines and MikroTik RouterOS routes your traffic. A catalogue entry is a claim about attackers...

12 Sep 2026 Three Unrelated Groups Walked Through the Same Cisco Flaw

Talos found Sandworm's implant, Qilin ransomware and a third intruder inside Secure Firewall Management Center. The espionage-or-crime question no longer filters anything.

12 Sep 2026 Attackers Are Minting Artifactory Admin Tokens. The Log Says Anonymous.

Two flaws chain an unauthenticated request into administrator scope in under five minutes, and the audit trail records the actions without naming an actor.

12 Sep 2026 GitLab Patched a 10.0 File-Read Flaw. Probes Appeared the Next Day.

An unauthenticated attacker could read any file on a self-managed server. What sits on that server is every credential the build system can reach.

11 Sep 2026 One in Ten Exposed LiteLLM Gateways Answers to the Key in the Documentation

Wiz found 9.6 per cent of 3,074 public LiteLLM proxies accepting sk-1234 or no key at all — which is why LiteLLM scoring a post-authentication flaw at 2.1 is contested.

11 Sep 2026 CISA Has Logged 37 Newly Exploited Flaws in 30 Days

CISA's exploited-vulnerability catalogue has taken 37 new entries in 30 days, including this week's Citrix NetScaler authentication bypass and a 2025 Fortinet flaw.

9 Sep 2026 A cPanel Account With Mail Privileges Can Reach Root. On Shared Hosting You Can Buy One.

CVE-2026-67401 is SQL injection in EmailTrack, disclosed 8 September with no reported exploitation. It is the second cPanel tenant-isolation failure in five weeks.

9 Sep 2026 The Magento Hotfix Is the Easy Half. Rotating the Encryption Key Is the Rest.

CVE-2026-75650 is unauthenticated RCE at CVSS 10.0, exploited three days before the fix. The payload runs when the store renders its own reminder email.

8 Sep 2026 N-able's Fourth N-central Hotfix in Five Weeks, and Hotfix 3 Does Not Cover It

CVE-2026-86218 is a pre-auth RCE at CVSS 10.0, already exploited. The customer notice calls it a zero-day observed in the wild; the release notes call exploitation unconfirmed.

7 Sep 2026 Two Chained Flaws Give Full Control of a MikroTik Router, and the Attacks Came First

CERT Polska confirms exploitation from 2 September; the fixes landed on the 5th. The giveaway is a log entry recording a failed login for user "-2".

7 Sep 2026 Cisco Found Seven Flaws in Every IOS XR Release, and Says AI Models Helped

Two at CVSS 9.8, unauthenticated and network-reachable, none known to be exploited. The advisory names frontier AI models as part of how they were found, which vendors do not usual...

4 Sep 2026 CISA Added Seven Exploited Flaws. Five Due in Three Days, Two in Fourteen.

Five carry a three-day federal clock, two carry fourteen days, in a single batch. Three of the seven sit in AI and build infrastructure: LiteLLM, Kestra and Artifactory.

3 Sep 2026 SonicWall SMA1000's July Fix Is the Build This Advisory Now Calls Vulnerable

Two new zero-days are being chained on SMA1000 appliances, in the same two components as the June pair. The July fix builds sit at the top of the vulnerable range.

2 Sep 2026 A 33-Hour BGP Hijack Worked Because the Updates Were Not Signed

Softaculous says an attacker announced routes for its Hetzner-hosted addresses for about 33 hours and served a malicious Virtualizor update. The packages were not signed.

2 Sep 2026 The Sixth Exploited Langflow Flaw This Year Is Not a Vulnerability Story

VulnCheck has recorded 360 attacks on a Langflow flaw fixed in January. It is the sixth separately identified Langflow vulnerability exploited during 2026.

2 Sep 2026 Fire Ant Took the Routers. The TACACS Server Is What It Was After.

Sygnia has documented an espionage group running fake services on Cisco routers during alternating hours. The authentication server compromised alongside them is where the value si...

1 Sep 2026 PaperCut's First Emergency Patch Was Bypassable. Here Is the Second One.

PaperCut has shipped a second emergency patch after researchers walked around the first. A vendor under active exploitation ships something today, which usually blocks a request pa...

31 Aug 2026 Five Critical WordPress Flaws, and None of Them Needs an Account

Most WordPress advisories describe flaws that need an account first. These five do not, which is what a 9.8 is actually saying, and one of them scores a full 10.

15 Aug 2026 One Malformed Request Crashes the Firewall. CISA Gave Three Days.

CVE-2026-20349 lets an unauthenticated attacker reload a Cisco ASA or FTD firewall through the remote-access SSL VPN. There is no workaround, the federal deadline was three days, a...

9 Aug 2026 A Zero-Day in a Dashboard Tool Took Framework's Entire Customer List

Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence tool they used. The bug needed nothing but the UUID in a shared dashboa...

5 Aug 2026 Three Days to Patch N-able. A Year Ago 92% of KEV Entries Got Three Weeks

CISA gave three days to fix an actively exploited N-able bypass. Across the catalogue, the three-week remediation window has stopped being the norm.

1 Aug 2026 A Password Was Built Into Cisco's Firewall Manager. It Is Being Exploited, and Agencies Had Three Days to Fix It

CVE-2026-20316 scores 5.3 — a medium. CISA still gave federal agencies three days and told them to check for compromise. The gap between those two facts is the story.

26 Jul 2026 Check Point Confirms an Exploited SmartConsole Bypass — Its Second KEV Entry in Forty-Four Days

The advisory is exemplary and the hotfix shipped the same day. The pattern behind it is the story: two of Check Point's three all-time KEV entries landed this summer, both authenti...

6 Jul 2026 SharePoint RCE CVE-2026-45659 Added to CISA KEV: A 'Less Likely' May Patch Is Now Actively Exploited

CISA added CVE-2026-45659, a CVSS 8.8 deserialization remote-code-execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on 1 Jul...

19 Jun 2026 Joomla JCE Flaw CVE-2026-48907 (CVSS 10.0) Is Being Actively Exploited — Patch and Check for Compromise

CISA added CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor extension (JCE / JCE Pro), to its KEV catalog on 16 June 2026, citing active exploita...

16 Jun 2026 Oracle Patches Actively Exploited PeopleSoft Zero-Day (CVE-2026-35273) as Data-Theft Campaign Hits Universities

Oracle issued an out-of-band alert on 10 June for CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution flaw in PeopleSoft PeopleTools that Mandiant says was exploited a...

7 Jun 2026 SolarWinds Serv-U Enters CISA KEV After Active Exploitation Warning

SolarWinds Serv-U CVE-2026-28318 is now in CISA’s Known Exploited Vulnerabilities catalogue after a June 2026 hotfix. This is an availability-risk threat intel update: patch Serv-U...

7 Jun 2026 CSA Flags GlobalProtect Auth-Bypass CVE-2026-0257 as Critical While Attackers Forge VPN Cookies in the Wild

Singapore's CSA rates a GlobalProtect authentication-bypass flaw critical (9.1) — sterner than Palo Alto's own HIGH rating — as Rapid7 confirms attackers forging VPN cookies since...

8 May 2026 Critical Palo Alto Firewall Zero-Day Actively Exploited by State-Sponsored Hackers — CISA Orders Patch by 9 May

CVE-2026-0300, a critical PAN-OS buffer overflow enabling unauthenticated root-level RCE, is being actively exploited by state-sponsored actors. CISA has ordered federal agencies t...