Skip to main content

F5 BIG-IP APM OAuth Remote Code Execution Remains a Priority Past Its Federal Deadline (CVE-2026-94127)

Scope: F5 BIG-IP Systems Where APM Is Configured as an OAuth Authorization Server on the S

Apple Patches CoreGraphics Flaw Possibly Exploited Against Specific Targeted Individuals (CVE-2026-86950)

Scope: iOS, iPadOS, and macOS Devices Running Versions Prior to iOS 27 and macOS Tahoe 26.

Citrix NetScaler Two Zero-Day Vulnerabilities Exploited Before Patches Existed (CVE-2026-88771 / CVE-2026-88772)

Scope: Citrix NetScaler ADC and NetScaler Gateway, Including Devices Already Running the A

Microsoft SharePoint Code Injection Flaw Exploited After Being Mislabeled as Low Risk for 45 Days (CVE-2026-65660)

Scope: Microsoft SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Sub

MikroTik RouterOS "MikroTrick" Chain Confirmed to Enable Full Administrative Takeover (CVE-2026-67279)

Scope: MikroTik RouterOS Version 7.x

WordPress Core Path Traversal Flaw Moves From Patch to Active Payload Delivery Within Hours (CVE-2026-87902)

Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7.37)

WordPress Core Unauthenticated Path Traversal Affects Every Version Since 2016, Can Enable Code Execution (CVE-2026-87902)

Scope: WordPress Core, All Versions 4.7.0 Through 7.1.1

Subscribe to Advisories