Security news.
Today's security roundup features critical advisories across enterprise infrastructure, including an arbitrary file read flaw affecting several Atlassian products and an actively exploited Citrix NetScaler vulnerability added to CISA's KEV catalog. Meanwhile, massive breaches have surfaced involving Denmark's national registry and retailer ASOS, alongside major research and zero-day demonstrations at Pwn2Own Ireland.
Critical Atlassian Flaw Exposes Files Across Data Center Suite
Atlassian disclosed a critical 9.3-severity vulnerability (CVE-2026-21589) enabling unauthenticated attackers to read arbitrary files across self-hosted products including Jira, Confluence, and Bitbucket.
CISA Adds Actively Exploited Citrix NetScaler Flaw to KEV
CISA has mandated federal agencies patch CVE-2026-88779, a buffer restriction flaw in Citrix NetScaler that threat actors are actively exploiting in the wild.
Researchers Chain 32 Zero-Days on Day One of Pwn2Own Ireland
Security researchers claimed $388,500 after demonstrating 32 zero-day vulnerabilities on opening day, successfully hacking the Samsung Galaxy S26 multiple times alongside other consumer devices.
Denmark Population Register Compromise Impacts 8.8 Million
Threat actors abused a third-party company's legitimate access credentials to central register systems to harvest personal records, addresses, and ID numbers across Denmark.
ASOS Confirms Breach After Rogue Push Notifications
UK retailer ASOS acknowledged a security incident after attackers hijacked in-app mobile push notifications and claimed the theft of customer records from the company's Snowflake environment.
Microsoft Patches Privilege Escalation Bug in Exchange Server
Microsoft shipped an out-of-band update for CVE-2026-96940, an 8.8-severity authorization flaw allowing authenticated attackers to access mailboxes across the organization.
Threat Actors Actively Scan for Rejetto HFS RCE Flaw
Scanners are targeting CVE-2026-61500, a cryptographic key flaw in Rejetto HTTP File Server that permits session forgery, account hijacking, and remote code execution.