Skip to main content

WordPress Core Path Traversal Flaw Remains Under Active Scanning a Week After Disclosure (CVE-2026-87902)

Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7)

Oracle PeopleSoft Sees Renewed Mass Exploitation as Attackers Bypass WAF Protections (CVE-2026-35273)

Scope: Oracle PeopleSoft (Internet-Facing Deployments, Particularly Those Relying on WAF R

Citrix NetScaler Flaw Now Confirmed Deployed for Root Access and Web Shells in Real Attacks (CVE-2026-88772)

Scope: Citrix NetScaler ADC and NetScaler Gateway with DTLS Enabled (On by Default on VPN

F5 BIG-IP APM OAuth Remote Code Execution Remains a Priority Past Its Federal Deadline (CVE-2026-94127)

Scope: F5 BIG-IP Systems Where APM Is Configured as an OAuth Authorization Server on the S

Apple Patches CoreGraphics Flaw Possibly Exploited Against Specific Targeted Individuals (CVE-2026-86950)

Scope: iOS, iPadOS, and macOS Devices Running Versions Prior to iOS 27 and macOS Tahoe 26.

Citrix NetScaler Two Zero-Day Vulnerabilities Exploited Before Patches Existed (CVE-2026-88771 / CVE-2026-88772)

Scope: Citrix NetScaler ADC and NetScaler Gateway, Including Devices Already Running the A

Microsoft SharePoint Code Injection Flaw Exploited After Being Mislabeled as Low Risk for 45 Days (CVE-2026-65660)

Scope: Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Sub

Subscribe to Advisories