Security news.
Major security developments include active attacks on critical enterprise infrastructure and an expansive breach of government registry data. In addition to widespread exploitation campaigns hitting Citrix and Rejetto appliances, administrators face high-severity flaws in self-hosted Atlassian and Microsoft Exchange deployments. Threat actors also continue to probe perimeter defenses using novel browser caching techniques and stealthy proxy backdoors.
Citrix NetScaler Flaw Added to CISA KEV Under Active Exploitation
CISA has added CVE-2026-88779 to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild attacks targeting memory buffer restrictions in NetScaler appliances.
Critical Atlassian Flaw Exposes Files Across 8 Data Center Products
Tracked as CVE-2026-21589 with a 9.3 CVSS rating, the vulnerability allows unauthenticated remote attackers to read known files directly from application root directories.
Attackers Actively Scan for Rejetto HFS RCE Vulnerability
Scanners are actively hunting for CVE-2026-61500, a weak session-cookie signing key flaw that enables complete session forgery and arbitrary code execution.
Microsoft Patches High-Severity Privilege Escalation Flaw in Exchange Server
An out-of-band update addresses CVE-2026-96940 (CVSS 8.8), an authorization weakness allowing authenticated attackers to access mailboxes belonging to other users.
Data Breach at Denmark CPR Exposes Records of 8.8 Million Citizens
Attackers abused a private organization's lawful query credentials to compromise personal registration data, impacting virtually the entire Danish population.
ClingSTUN Linux Backdoor Turns IoT Devices into Stealth Proxies
The malware leverages 24 known exploits to hijack IoT hardware and routes communications through public STUN servers to evade traffic inspection.
ClickFix Campaign Pre-Fetches Payloads via Browser Cache
Microsoft warns that attackers are disguising script payloads as PNG files within local browser caches to circumvent traditional execution boundaries.
LibreOffice and OpenOffice Flaw Enables Macro-Free Code Execution
Proof-of-concept research demonstrates that crafted spreadsheets can execute arbitrary code upon opening without user warnings if Java support is enabled.