Security news.
Threat actors are actively leveraging zero-day flaws across enterprise appliances and collaboration tools, prompting emergency updates and federal warnings. Significant infrastructure attacks have hit cryptocurrency services and defense systems, alongside the weaponization of zero-day exploits in network edge devices. Defenders are urged to prioritize patching critical vulnerabilities in Cisco, Zimbra, and Citrix appliances immediately.
CISA Adds Cisco Catalyst SD-WAN Zero-Day to KEV Catalog
CISA has added CVE-2026-76504 (CVSS 9.8), an actively exploited authentication bypass vulnerability allowing remote attackers administrative access, to its Known Exploited Vulnerabilities catalog.
Zimbra Flaw CVE-2026-73570 Exploited Prior to Disclosure
An unauthenticated command injection bug in Zimbra Collaboration Suite was exploited in the wild via malicious emails to deploy web shells and harvest mailbox data.
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Heist
Cryptocurrency exchange Bitget revealed that a zero-day vulnerability in third-party security software enabled the massive theft of digital assets.
Pentagon Personnel Data of Over 3 Million People Stolen in Breach
The Defense Manpower Data Center is notifying service members after hackers breached the Pentagon's human resources database.
Zammad Zero-Days Exploited in Attack Against DIVD
Attackers chained two zero-day flaws in the open-source Zammad ticketing system to achieve remote code execution and root privilege escalation on the Dutch Institute for Vulnerability Disclosure's network.
MetaMask Responds to Ongoing Infrastructure Security Incident
Crypto wallet provider MetaMask disclosed an infrastructure security incident that prompted the targeted exit of affected Ethereum validators, though no user wallets have been compromised.
PoC Released for Actively Exploited Apple CoreGraphics Vulnerability
Researchers published a proof-of-concept for CVE-2026-86950, a flaw triggered by crafted fonts in PDF files that has been used in targeted attacks against macOS and iOS devices.
Citrix NetScaler Flaws Weaponized for Superuser Persistence
Threat actors are actively exploiting recent command injection flaws (CVE-2026-88771 and CVE-2026-88772) in NetScaler ADC and Gateway appliances to drop web shells disguised as CSS files.