Snapshot 27502
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Experienced a Breach? Contact Us Blog Agentic SOC Agentic SOC Aurora Agentic SOC Partner with the world's largest commercial agentic SOC. Concierge Delivery Model Tailored security expertise and guided risk mitigation. Arctic Wolf Security Teams Security experts proactively protecting you 24x7. Incident Response In Action Learn how our IR team stops attacks and swiftly restores your organization to pre-incident operations. Explore the SOC Ready to get started? Request a Demo Platform Platform How It Works Delivering security operations outcomes. Aurora Superintelligence Platform Delivering AI outcomes you can trust. Aurora AI Leverage the power of scale and AI expertise. Platform Integrations Ecosystem integrations and technology partnerships. Journey Security Journey Build a resilient business by embracing Security Operations. Cyber Resilience Assessment Map your security posture against industry standard frameworks. Ready to get started? Request a Demo Solutions Reduce Attack Frequency Exposure Management Continuously discover, prioritize, and reduce exposure across your attack surface. Incident360 Retainer Receive end-to-end IR coverage for one incident, no matter the incident type. Security Awareness and Training Engage and prepare employees to recognize and neutralize social engineering attacks. Threat Intelligence Plus Curated by the world’s largest commercial SOC based on real-world attacks, emerging threats, and observed adversary behavior. Reduce Attack Severity Endpoint Security AI-driven prevention, detection, and response to stop endpoint threats before they disrupt your business. Managed Detection and Response Quickly detect, respond, and recover from advanced threats. Incident Response Recover quickly from cyber attacks and breaches, from threat containment to business restoration. Experienced a Breach? Transfer Risk Security Operations Warranty Stay covered at no cost with up to $3M in financial assistance for cybersecurity incidents. Cyber Insurance Increase the likelihood of insurability, and potentially lower your rates. Cyber JumpStart Access a complimentary suite of tools to reduce risk and improve insurability. Get Started View All Arctic Wolf Solutions Explore Arctic Wolf Bundles Calculate Your Security ROI Ready to get started? Request a Demo Why Arctic Wolf Why Arctic Wolf AI Defense Industry Analysis Awards & Recognition Customer Perspectives Security Operations Warranty Arctic Wolf Labs Expertise by Topic Compliance Solutions Ransomware Explained Incident Response Timelines Ransomware Attack & Containment Business Email Compromise Expertise by Industry Financial Services Healthcare State & Local Government Manufacturing Legal View All Ready to get started? Request a Demo Resources Resource Center ROI Calculator Blog Case Studies Events Analyst Reports Webinars Podcasts Glossary Technical Videos View All Trending Resources 2025 Arctic Wolf Threat Report The Arctic Wolf Threat Report draws upon the first-hand experience of our security experts, augmented by research from our threat intelligence team. The Arctic Wolf State of Cybersecurity: 2025 Trends Report The Arctic Wolf State of Cybersecurity: 2025 Trends Report serves as an opportunity for decision makers to share their experiences over the past 12 months and their perspectives on some of the most important issues shaping the IT and security landscape. Aurora: A New Dawn For Cybersecurity Join Arctic Wolf on an interactive journey to discover a better path past the hazards of the modern threat landscape. View All Resources Security Bulletins September 15, 2026 CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required September 14, 2026 Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103 September 14, 2026 CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk VIEW ALL View All Bulletins Ready to get started? Request a Demo Partners Partners Solution Providers Helping Solution Providers scale their business with a comprehensive portfolio of products and services. Cyber Insurance Providers Arctic Wolf provides the Insurance Partner Program for Brokers and Carriers to support them within the Cyber JumpStart portal. Technology Alliance Partners Ecosystem integrations and technology partnerships. Managed Service Providers Grow your business and solve your customers’ cybersecurity challenges with industry-leading turnkey security operations. OEM Solutions Arctic Wolf OEM Solutions enable ISVs, MSSPs, U.S. Federal Agencies, and security companies. Become a Partner Ready to get started? Request a Demo Company Company About Us Contact Us Leadership Authors Customers FAQ Careers Working at Arctic Wolf Open Jobs Our Values Pack Impact Press Newsroom Press Releases Brand Partnerships BWT Alpine Formula One Team Meyer Shank Racing Minnesota Wild Alabama Crimson Tide Ready to get started? Request a Demo EXPERIENCED A BREACH? REQUEST A DEMO < BACK TO BLOG CATEGORY: Security Bulletins CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required September 15, 2026 Threat Summary CVE-2026-76461 is a pre-authentication SQL injection vulnerability in the email parsing logic of Cisco Secure Email Gateway (AsyncOS). This vulnerability enables unauthenticated remote READ MORE Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103 September 14, 2026 Threat Summary Patches have now been released addressing two critical vulnerabilities: CVE-2026-85102, which affects Security Gateway and Spark Firewall, and CVE-2026-85103, which affects Security Gateway, READ MORE CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk September 14, 2026 Threat Summary A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper READ MORE CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability September 8, 2026 Threat Summary A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute READ MORE Microsoft Patch Tuesday Security Recap: September 2026 Edition September 8, 2026 Summary This bulletin covers Microsoft’s Sept 8, 2026 Patch Tuesday release, and prioritizes the two actively exploited zero-day vulnerabilities: CVE-2026-85880 in Windows Advanced Local Procedure READ MORE URGENT UPDATE: Active Exploitation of Two Chained PaperCut NG/MF Vulnerabilities CVE-2026-81578 and CVE-2026-82078 September 1, 2026 Summary This Security Bulletin details two chained vulnerabilities, an authentication bypass (CVE-2026-81578, CVSS 8.8 HIGH) and an unsafe dynamic class-loading flaw (CVE-2026-82078, CVSS 9.4 CRITICAL), READ MORE Ubiquiti UniFi Protect, OS, and Talk – Critical Remote Exploitation Vulnerabilities August 28, 2026 Threat Summary On August 26, 2026, Ubiquiti officially disclosed three maximum-severity vulnerabilities affecting core UniFi infrastructure: CVE-2026-77537 (UniFi Protect), CVE-2026-77550 (UniFi OS devices), and CVE-2026-77554 READ MORE Security Advisory: Active Exploitation of Unauthenticated Vulnerability in PaperCut NG/MF August 27, 2026 Threat Summary PaperCut Software has issued an urgent security bulletin confirming active, zero-day exploitation of a high-severity vulnerability impacting PaperCut NG and PaperCut MF application READ MORE Critical Remote Exploit in macOS Screen Sharing: CVE-2026-65400 August 21, 2026 Threat Summary On August 6, 2026, Apple released a security patch addressing CVE-2026-65400. This vulnerability is a pre-authentication authentication bypass in the macOS Screen Sharing READ MORE SAP Commerce Cloud Remote Code Execution Vulnerability (CVE-2026-58231) – Patch Immediately August 18, 2026 Threat Summary CVE-2026-58231 is a critical threat affecting SAP Commerce Cloud’s Data Hub Adapter (COM_CLOUD 2211 and 2211-JDK21). The flaw stems from missing authorization checks READ MORE Citrix NetScaler ADC & Gateway Critical RCE Vulnerability CVE-2026-8452 August 18, 2026 Threat Summary On August 14, 2026, WatchTowr released a full technical writeup on CVE-2026-8452. The vulnerability is a heap-based memory overflow flaw affecting Citrix NetScaler READ MORE Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak) August 12, 2026 Threat Summary A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to READ MORE Microsoft SharePoint Critical Vulnerability CVE-2026-55040: PoC and Active Exploitation August 12, 2026 Threat Summary On August 11, 2026, Rapid7 released a Proof-of-Concept (PoC) for CVE-2026-55040, a critical authentication bypass affecting Microsoft SharePoint Server Subscription Edition, SharePoint Enterprise READ MORE SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299 August 6, 2026 Summary On July 30th, 2026, SolarWinds released fixes for a critical Authentication-Bypass vulnerability in Web Help Desk (WHD) tracked as CVE-2026-28323, and a related high-severity READ MORE CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching August 3, 2026 Threat Summary Threat actors are actively exploiting two high-severity authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able N-Central, a widely deployed remote monitoring and management READ MORE CVE-2026-20316, CVE-2026-20079: Active Exploitation of Cisco Secure Firewall Management Center Zero-Day July 31, 2026 Threat Summary CVE-2026-20316 is a newly discovered zero-day vulnerability affecting Cisco Secure Firewall Management Center (FMC) software, allowing unauthenticated, remote attackers to log in using READ MORE UPDATE: Microsoft SharePoint Server Vulnerabilities – Immediate Patching Required July 21, 2026 Threat Summary Cybersecurity and Infrastructure Security Agency (CISA) has added several critical zero-day vulnerabilities targeting Microsoft SharePoint Server. CVE-2026-58644 is a deserialization flaw in SharePoint READ MORE CVE-2026-6875: Critical Remote Code Execution Vulnerability in ServiceNow AI Platform Urgent Mitigation Required July 20, 2026 Threat Summary CVE-2026-6875 is a critical remote code execution (RCE) vulnerability in the ServiceNow AI Platform. The flaw allows unauthenticated attackers to escape the sandbox READ MORE CVE-2026-39808: Critical Fortinet FortiSandbox OS Command Injection Vulnerability July 17, 2026 Threat Summary On April 14, 2026, Fortinet released fixes for a critical OS command injection vulnerability in FortiSandbox, tracked as CVE-2026-39808. The flaw allows remote READ MORE ClickFix Campaign Exploits PowerShell Loader with Identifier Obfuscation for Malicious Activity July 16, 2026 Threat Summary Arctic Wolf has observed a ClickFix-style intrusion pattern in which a user-executed PowerShell command downloads and runs remote content directly in memory. In READ MORE CVE-2026-15409, CVE-2026-15410: Security Bulletin: SonicWall SMA 1000 Series Zero-Day Vulnerabilities July 15, 2026 Threat Summary Two severe vulnerabilities affecting SonicWall Secure Mobile Access 1000 (SMA1000) series appliances have been confirmed as under active exploitation since their public disclosure READ MORE Apache Camel camel-pqc Unsafe Java Deserialization Vulnerability: Upgrade Required for Key Management Security July 13, 2026 Threat Summary On July 6, 2026, Apache disclosed CVE-2026-43867. Fixed releases (4.21.0 on July 1 and 4.18.3 on July 3) were available prior to public READ MORE Security Bulletin: GitHub Impersonation Deploys Information Stealer July 2, 2026 Overview Arctic Wolf Internal Security Operations (SecOps) recently identified a GitHub page impersonating Arctic Wolf to target our customers and prospects. The SecOps team immediately READ MORE CVE-2026-48558: Critical Authentication Bypass Vulnerability in SimpleHelp RMM Exploited for Credential Theft and Malware Delivery June 30, 2026 Summary CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software, caused by improper validation of OpenID Connect (OIDC) token READ MORE Critical Remote Code Execution Vulnerability in libssh2 Client Library Require Urgent Mitigation June 30, 2026 Threat Summary A suite of severe vulnerabilities has been disclosed in libssh2 (an SSH client library widely embedded in software such as curl, Git GUI READ MORE Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries June 17, 2026 Summary In mid-June 2026, security researchers identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, dubbed FortiBleed. Threat actors have been systematically extracting READ MORE CVE-2026-25089: Fortinet FortiSandbox Critical OS Command Injection Vulnerability Immediate Action Required June 15, 2026 Threat Summary CVE-2026-25089 is a critical OS command injection (CWE-78) vulnerability discovered in Fortinet FortiSandbox versions 4.4.0–4.4.8, 5.0.0–5.0.5, and corresponding Cloud and Platform as a READ MORE Microsoft Patch Tuesday Security Recap: June 2026 Edition June 11, 2026 Threat Summary On June 9, 2026, Microsoft released its regular Patch Tuesday security update, fixing 206 vulnerabilities (with 39 rated Critical) affecting a broad spectrum READ MORE Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign June 11, 2026 Summary A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, tracked as CVE-2026-35273, is under active exploitation by the ShinyHunters extortion group in READ MORE Ivanti Sentry Critical Vulnerabilities CVE-2026-10520 and CVE-2026-10523 Require Urgent Patching June 11, 2026 On June 9–10, 2026, Ivanti disclosed and patched two maximum-severity vulnerabilities in the Sentry appliance (formerly MobileIron Sentry): CVE-2026-10520 (OS command injection, CVSS 10.0) and READ MORE Categories Adversary Research Cyber Attacks and Breaches Cyber Insurance Endpoint Security Incident Response Managed Detection and Response Regulatory Compliance Security Awareness Security Bulletins Technical Briefs Threat Research Vulnerability Management Subscribe to our Monthly Newsletter GLOBAL HEADQUARTERS Arctic Wolf Networks 8939 Columbine Rd Eden Prairie, MN 55347 1.888.272.8429 𝕏 REQUEST A DEMO Solutions Managed Detection and Response Cloud Detection and Response Exposure Management Cloud Security Posture Management Security Awareness & Training Incident Response Aurora Endpoint Security Company Contact Us Careers Leadership Newsroom Partners Why Partner with Arctic Wolf? Resources Blog Case Studies Webinars Events Analyst Reports Newsletter © 2026 Arctic Wolf Networks Inc. All Rights Reserved. Privacy Notice Terms of Use Cookie Policy Accessibility Statement Information Security Sustainability Statement Cookies Settings