A maximum‑severity flaw in Cisco Catalyst SD‑WAN Controller’s DTLS peering lets unauthenticated attackers claim a “vHub” device type to bypass certificate checks, then persist by injecting SSH keys and issuing privileged NETCONF commands. Exploitation has been observed; CISA added the CVE to KEV and Cisco has shipped fixes—admins should patch immediately, restrict UDP/12346 exposure, and hunt for anomalous DTLS/NETCONF traffic or unexpected changes to vmanage-admin authorized_keys.
Source: Rapid7
PAN‑OS auth bypass disputed as higher risk; patch CAS‑enabled portals now (CVE-2026-0265)
Palo Alto Networks disclosed a signature‑verification bug enabling authentication bypass when Cloud Authentication Service is attached to a login interface. While the vendor rated it High (7.2), the reporting researcher says GlobalProtect portals can be bypassed and plans to publish technical details—organizations with CAS enabled should fast‑track available fixes, limit interface exposure, and consider temporarily disabling CAS until patched.
Source: Rapid7
‘NGINX Rift’: 18‑year‑old rewrite module overflow threatens vast web footprint (CVE-2026-42945)
A heap buffer overflow in ngx_http_rewrite_module—present for nearly two decades—can trigger remote DoS and potentially RCE on affected NGINX and NGINX Plus deployments. Given NGINX’s ubiquity as reverse proxy/load balancer, teams should prioritize vendor guidance, audit rewrite rules, and deploy compensating WAF rules while patching.
Source: Security Affairs
OpenAI confirms data theft amid TanStack npm supply‑chain intrusions
An expanding npm/PyPI campaign abusing the popular TanStack ecosystem led to compromises of two OpenAI employee devices and theft of repository credentials. While production and user data weren’t impacted, the incident underscores the need to pin dependencies, scan SBOMs, rotate tokens/keys, and rapidly quarantine known‑bad package versions across CI/CD.
Source: SecurityWeek
Third Linux kernel LPE in two weeks: ‘Fragnesia’ grants local root (CVE-2026-46300)
Fragnesia abuses page‑cache corruption in the XFRM ESP‑in‑TCP subsystem to escalate local privileges to root, following closely on Dirty Frag and Copy Fail. Patch as distributions release updates, restrict untrusted local code execution (e.g., desktop/VDI, CI runners), and enhance EDR detections for suspicious kernel‑adjacent activity.
Source: SecurityWeek
Windows zero‑days dropped: BitLocker bypass and SYSTEM‑level EoP
Researcher “Chaotic Eclipse” released PoCs for YellowKey (BitLocker recovery bypass requiring physical access) and GreenPlasma (privilege escalation via CTFMON), with Microsoft investigating. Enforce strong pre‑boot authentication (TPM+PIN), harden physical access, monitor CTF‑related process abuse, and be prepared to deploy mitigations once vendor advisories land.
Source: SecurityWeek
On‑prem Microsoft Exchange flaw exploited via crafted emails (CVE-2026-42897)
Microsoft reported in‑the‑wild exploitation of an Exchange Server spoofing issue rooted in XSS that can be triggered by a specially crafted email. Administrators should apply Microsoft’s guidance and updates, tighten exposure of OWA/ECP, and increase monitoring for anomalous mailbox actions and token misuse.
Source: The Hacker News
You May Also Be Interested In...
CISA adds Cisco SD‑WAN CVE‑2026‑20182 to KEV
Broadcom patches high‑severity VMware Fusion local privilege escalation
US intelligence names leads to coordinate response to foreign election threats