Wednesday, 30 September, 2026

Category: Vulnerability Alerts

Latest CVEs and vulnerability disclosures


Citrix called CVE-2026-8452 a denial-of-service risk in June. In August, watchTowr proved it was a pre-auth heap overflow giving root on NetScaler ADC and Gateway. Exploitation followed within days. The flaw, the web shells, and why severity labels shouldn’t drive your patch queue.


CVE-2026-73570 is an unauthenticated command-injection flaw in Zimbra Collaboration, exploitable by a crafted email via the optional zimbra-snmp package. At least 274 servers are already compromised. The flaw, the campaign, the IoCs, and what to do.


VMware vCenter CVE-2026-59310 RCE

CVE-2026-59310 is an unauthenticated CVSS 9.8 RCE in VMware vCenter’s Syslog Server — already mass-exploited across 361 victims in 47 countries, dropping cron-based reverse_ssh persistence. Affected builds, the attack chain, and what to do.


Adobe ColdFusion CVE-2026-48362 command injection

Adobe ColdFusion has an unauthenticated, CVSS 10.0 OS command injection (CVE-2026-48362) that hands attackers full server takeover with no login. Affected versions, how to tell if your ColdFusion is exposed, and how to patch (APSB26-90).


SAP Commerce Cloud CVE-2026-58231

A CVSS 10.0 flaw in SAP Commerce Cloud (CVE-2026-58231) lets unauthenticated attackers run arbitrary code — and it was exploited three days after the patch. The catch most teams miss: applying the note is not enough, you must rebuild and redeploy.


Unisoc VoLTE Android kernel exploit

Researchers disclosed a two-stage Unisoc VoLTE exploit chain that turns a VoLTE video call into full Android kernel access — with no patch from the chipset maker. Here is the real threat model, who is actually affected, and what to do.