Tag: network security

a man sitting in front of a computer monitor
Security

CISA orders federal patching by July 17, 2026 after two chained SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410)

SonicWall’s SMA1000 appliances are the subject of active exploitation via two linked zero-days: an unauthenticated SSRF (CVE-2026-15409) and an authenticated code-injection (CVE-2026-15410). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities list and set a federal remediation deadline of July 17, 2026 — a signal that agencies must patch […]

admin 
black laptop computer turned on near black and white electronic devices
Security

Active, unauthenticated RCE in Ivanti EPMM — interim RPMs stop attacks but 12.8.0.0 (Q1 2026) is the real fix

Two critical Ivanti EPMM zero-days (CVE-2026-1281 and CVE-2026-1340) are being exploited in the wild to achieve unauthenticated remote code execution. Interim RPM patches stop the immediate attacks, but they must be re-applied after upgrades; a permanent fix is scheduled for EPMM 12.8.0.0 in Q1 2026. Observed exploitation and its immediate effects Attackers are sending simple, […]

admin 
Digital screens display data on a circuit board background
Security

CVE-2026-0300: If your Palo Alto User-ID Authentication Portal is internet-exposed, lock it down now — patches start May 13

A critical PAN-OS zero-day, CVE-2026-0300, is being actively exploited but only when Palo Alto Networks’ User-ID Authentication Portal is reachable from untrusted networks. Patches begin rolling out on May 13, 2026; until your appliances are updated, restricting or disabling the portal is the practical defense that changes your immediate risk profile. Portal-exposed versus default deployments: […]

admin 
Team of hackers with Guy Fawkes masks coding in a dark room with computers.
Security

CVE-2025-53521: F5 BIG-IP APM reclassified as critical RCE — what distinguishes active exploitation from earlier DoS assessments

F5‘s BIG-IP Access Policy Manager vulnerability CVE-2025-53521—originally treated as a denial-of-service issue—was reclassified as an unauthenticated remote code execution (RCE) after March 2026 intelligence showed active exploitation. The change forced CISA into the Known Exploited Vulnerabilities (KEV) list and triggered federal patch mandates; organizations must treat this as an immediate compromise risk, not a mere […]

admin