Third Party Index

Snapshot 27502

Document
Security advisories
URL
https://arcticwolf.com/resources/tag/security-bulletins/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
318116 bytes
SHA-256 (raw)
87d721d216090501abd1e7a7c24f008b5667017630b145fafebc06f33c12a6d9
SHA-256 (normalized text)
75d4ec03dcc5807957684f8333527e6aee07fe8268d8bb83f08d4f137bfa432f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Experienced a Breach?	Contact Us	Blog
Agentic SOC
Agentic SOC
Aurora Agentic SOC
Partner with the world's largest commercial agentic SOC.
Concierge Delivery Model
Tailored security expertise and guided risk mitigation.
Arctic Wolf Security Teams
Security experts proactively protecting you 24x7.
Incident Response In Action
Learn how our IR team stops attacks and swiftly restores your organization to pre-incident operations.
Explore the SOC
Ready to get started? Request a Demo
Platform
Platform
How It Works
Delivering security operations outcomes.
Aurora Superintelligence Platform
Delivering AI outcomes you can trust.
Aurora AI
Leverage the power of scale and AI expertise.
Platform Integrations
Ecosystem integrations and technology partnerships.
Journey
Security Journey
Build a resilient business by embracing Security Operations.
Cyber Resilience Assessment
Map your security posture against industry standard frameworks.
Ready to get started? Request a Demo
Solutions
Reduce Attack Frequency
Exposure Management
Continuously discover, prioritize, and reduce exposure across your attack surface.
Incident360 Retainer
Receive end-to-end IR coverage for one incident, no matter the incident type.
Security Awareness and Training
Engage and prepare employees to recognize and neutralize social engineering attacks.
Threat Intelligence Plus
Curated by the world’s largest commercial SOC based on real-world attacks, emerging threats, and observed adversary behavior.
Reduce Attack Severity
Endpoint Security
AI-driven prevention, detection, and response to stop endpoint threats before they disrupt your business.
Managed Detection and Response​
Quickly detect, respond, and recover from advanced threats.
Incident Response
Recover quickly from cyber attacks and breaches, from threat containment to business restoration.
Experienced a Breach?
Transfer Risk
Security Operations Warranty
Stay covered at no cost with up to $3M in financial assistance for cybersecurity incidents.
Cyber Insurance
Increase the likelihood of insurability, and potentially lower your rates.
Cyber JumpStart
Access a complimentary suite of tools to reduce risk and improve insurability.
Get Started
View All Arctic Wolf Solutions Explore Arctic Wolf Bundles Calculate Your Security ROI
Ready to get started? Request a Demo
Why Arctic Wolf
Why Arctic Wolf
AI Defense
Industry Analysis
Awards & Recognition
Customer Perspectives
Security Operations Warranty
Arctic Wolf Labs
Expertise by Topic
Compliance Solutions
Ransomware Explained
Incident Response Timelines
Ransomware Attack & Containment
Business Email Compromise
Expertise by Industry
Financial Services
Healthcare
State & Local Government
Manufacturing
Legal
View All
Ready to get started? Request a Demo
Resources
Resource Center
ROI Calculator
Blog
Case Studies
Events
Analyst Reports
Webinars
Podcasts
Glossary
Technical Videos
View All
Trending Resources
2025 Arctic Wolf Threat Report
The Arctic Wolf Threat Report draws upon the first-hand experience of our security experts, augmented by research from our threat intelligence team.
The Arctic Wolf State of Cybersecurity: 2025 Trends Report
The Arctic Wolf State of Cybersecurity: 2025 Trends Report serves as an opportunity for decision makers to share their experiences over the past 12 months and their perspectives on some of the most important issues shaping the IT and security landscape.
Aurora: A New Dawn For Cybersecurity
Join Arctic Wolf on an interactive journey to discover a better path past the hazards of the modern threat landscape.
View All Resources
Security Bulletins
September 15, 2026
CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required
September 14, 2026
Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103
September 14, 2026
CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk
VIEW ALL
View All Bulletins
Ready to get started? Request a Demo
Partners
Partners
Solution Providers
Helping Solution Providers scale their business with a comprehensive portfolio of products and services.
Cyber Insurance Providers
Arctic Wolf provides the Insurance Partner Program for Brokers and Carriers to support them within the Cyber JumpStart portal.
Technology Alliance Partners
Ecosystem integrations and technology partnerships.
Managed Service Providers
Grow your business and solve your customers’ cybersecurity challenges with industry-leading turnkey security operations.
OEM Solutions
Arctic Wolf OEM Solutions enable ISVs, MSSPs, U.S. Federal Agencies, and security companies.
Become a Partner
Ready to get started? Request a Demo
Company
Company
About Us
Contact Us
Leadership
Authors
Customers
FAQ
Careers
Working at Arctic Wolf
Open Jobs
Our Values
Pack Impact
Press
Newsroom
Press Releases
Brand Partnerships
BWT Alpine Formula One Team
Meyer Shank Racing
Minnesota Wild
Alabama Crimson Tide
Ready to get started? Request a Demo
EXPERIENCED A BREACH?
REQUEST A DEMO
< BACK TO BLOG
CATEGORY: Security Bulletins
CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required
September 15, 2026
Threat Summary CVE-2026-76461 is a pre-authentication SQL injection vulnerability in the email parsing logic of Cisco Secure Email Gateway (AsyncOS). This vulnerability enables unauthenticated remote
READ MORE
Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103
September 14, 2026
Threat Summary Patches have now been released addressing two critical vulnerabilities: CVE-2026-85102, which affects Security Gateway and Spark Firewall, and CVE-2026-85103, which affects Security Gateway,
READ MORE
CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk
September 14, 2026
Threat Summary A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper
READ MORE
CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability
September 8, 2026
Threat Summary A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute
READ MORE
Microsoft Patch Tuesday Security Recap: September 2026 Edition
September 8, 2026
Summary This bulletin covers Microsoft’s Sept 8, 2026 Patch Tuesday release, and prioritizes the two actively exploited zero-day vulnerabilities: CVE-2026-85880 in Windows Advanced Local Procedure
READ MORE
URGENT UPDATE: Active Exploitation of Two Chained PaperCut NG/MF Vulnerabilities CVE-2026-81578 and CVE-2026-82078
September 1, 2026
Summary This Security Bulletin details two chained vulnerabilities, an authentication bypass (CVE-2026-81578, CVSS 8.8 HIGH) and an unsafe dynamic class-loading flaw (CVE-2026-82078, CVSS 9.4 CRITICAL),
READ MORE
Ubiquiti UniFi Protect, OS, and Talk – Critical Remote Exploitation Vulnerabilities
August 28, 2026
Threat Summary On August 26, 2026, Ubiquiti officially disclosed three maximum-severity vulnerabilities affecting core UniFi infrastructure: CVE-2026-77537 (UniFi Protect), CVE-2026-77550 (UniFi OS devices), and CVE-2026-77554
READ MORE
Security Advisory: Active Exploitation of Unauthenticated Vulnerability in PaperCut NG/MF
August 27, 2026
Threat Summary PaperCut Software has issued an urgent security bulletin confirming active, zero-day exploitation of a high-severity vulnerability impacting PaperCut NG and PaperCut MF application
READ MORE
Critical Remote Exploit in macOS Screen Sharing: CVE-2026-65400
August 21, 2026
Threat Summary On August 6, 2026, Apple released a security patch addressing CVE-2026-65400. This vulnerability is a pre-authentication authentication bypass in the macOS Screen Sharing
READ MORE
SAP Commerce Cloud Remote Code Execution Vulnerability (CVE-2026-58231) – Patch Immediately
August 18, 2026
Threat Summary CVE-2026-58231 is a critical threat affecting SAP Commerce Cloud’s Data Hub Adapter (COM_CLOUD 2211 and 2211-JDK21). The flaw stems from missing authorization checks
READ MORE
Citrix NetScaler ADC & Gateway Critical RCE Vulnerability CVE-2026-8452
August 18, 2026
Threat Summary On August 14, 2026, WatchTowr released a full technical writeup on CVE-2026-8452. The vulnerability is a heap-based memory overflow flaw affecting Citrix NetScaler
READ MORE
Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak)
August 12, 2026
Threat Summary A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to
READ MORE
Microsoft SharePoint Critical Vulnerability CVE-2026-55040: PoC and Active Exploitation
August 12, 2026
Threat Summary On August 11, 2026, Rapid7 released a Proof-of-Concept (PoC) for CVE-2026-55040, a critical authentication bypass affecting Microsoft SharePoint Server Subscription Edition, SharePoint Enterprise
READ MORE
SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299
August 6, 2026
Summary On July 30th, 2026, SolarWinds released fixes for a critical Authentication-Bypass vulnerability in Web Help Desk (WHD) tracked as CVE-2026-28323, and a related high-severity
READ MORE
CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching
August 3, 2026
Threat Summary Threat actors are actively exploiting two high-severity authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able N-Central, a widely deployed remote monitoring and management
READ MORE
CVE-2026-20316, CVE-2026-20079: Active Exploitation of Cisco Secure Firewall Management Center Zero-Day
July 31, 2026
Threat Summary CVE-2026-20316 is a newly discovered zero-day vulnerability affecting Cisco Secure Firewall Management Center (FMC) software, allowing unauthenticated, remote attackers to log in using
READ MORE
UPDATE: Microsoft SharePoint Server Vulnerabilities – Immediate Patching Required
July 21, 2026
Threat Summary Cybersecurity and Infrastructure Security Agency (CISA) has added several critical zero-day vulnerabilities targeting Microsoft SharePoint Server. CVE-2026-58644 is a deserialization flaw in SharePoint
READ MORE
CVE-2026-6875: Critical Remote Code Execution Vulnerability in ServiceNow AI Platform Urgent Mitigation Required
July 20, 2026
Threat Summary CVE-2026-6875 is a critical remote code execution (RCE) vulnerability in the ServiceNow AI Platform. The flaw allows unauthenticated attackers to escape the sandbox
READ MORE
CVE-2026-39808: Critical Fortinet FortiSandbox OS Command Injection Vulnerability
July 17, 2026
Threat Summary On April 14, 2026, Fortinet released fixes for a critical OS command injection vulnerability in FortiSandbox, tracked as CVE-2026-39808. The flaw allows remote
READ MORE
ClickFix Campaign Exploits PowerShell Loader with Identifier Obfuscation for Malicious Activity
July 16, 2026
Threat Summary Arctic Wolf has observed a ClickFix-style intrusion pattern in which a user-executed PowerShell command downloads and runs remote content directly in memory. In
READ MORE
CVE-2026-15409, CVE-2026-15410: Security Bulletin: SonicWall SMA 1000 Series Zero-Day Vulnerabilities
July 15, 2026
Threat Summary Two severe vulnerabilities affecting SonicWall Secure Mobile Access 1000 (SMA1000) series appliances have been confirmed as under active exploitation since their public disclosure
READ MORE
Apache Camel camel-pqc Unsafe Java Deserialization Vulnerability: Upgrade Required for Key Management Security
July 13, 2026
Threat Summary On July 6, 2026, Apache disclosed CVE-2026-43867. Fixed releases (4.21.0 on July 1 and 4.18.3 on July 3) were available prior to public
READ MORE
Security Bulletin: GitHub Impersonation Deploys Information Stealer
July 2, 2026
Overview Arctic Wolf Internal Security Operations (SecOps) recently identified a GitHub page impersonating Arctic Wolf to target our customers and prospects. The SecOps team immediately
READ MORE
CVE-2026-48558: Critical Authentication Bypass Vulnerability in SimpleHelp RMM Exploited for Credential Theft and Malware Delivery
June 30, 2026
Summary CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software, caused by improper validation of OpenID Connect (OIDC) token
READ MORE
Critical Remote Code Execution Vulnerability in libssh2 Client Library Require Urgent Mitigation
June 30, 2026
Threat Summary A suite of severe vulnerabilities has been disclosed in libssh2 (an SSH client library widely embedded in software such as curl, Git GUI
READ MORE
Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries
June 17, 2026
Summary In mid-June 2026, security researchers identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, dubbed FortiBleed. Threat actors have been systematically extracting
READ MORE
CVE-2026-25089: Fortinet FortiSandbox Critical OS Command Injection Vulnerability Immediate Action Required
June 15, 2026
Threat Summary CVE-2026-25089 is a critical OS command injection (CWE-78) vulnerability discovered in Fortinet FortiSandbox versions 4.4.0–4.4.8, 5.0.0–5.0.5, and corresponding Cloud and Platform as a
READ MORE
Microsoft Patch Tuesday Security Recap: June 2026 Edition
June 11, 2026
Threat Summary On June 9, 2026, Microsoft released its regular Patch Tuesday security update, fixing 206 vulnerabilities (with 39 rated Critical) affecting a broad spectrum
READ MORE
Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign
June 11, 2026
Summary A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, tracked as CVE-2026-35273, is under active exploitation by the ShinyHunters extortion group in
READ MORE
Ivanti Sentry Critical Vulnerabilities CVE-2026-10520 and CVE-2026-10523 Require Urgent Patching
June 11, 2026
On June 9–10, 2026, Ivanti disclosed and patched two maximum-severity vulnerabilities in the Sentry appliance (formerly MobileIron Sentry): CVE-2026-10520 (OS command injection, CVSS 10.0) and
READ MORE
Categories
Adversary Research
Cyber Attacks and Breaches
Cyber Insurance
Endpoint Security
Incident Response
Managed Detection and Response
Regulatory Compliance
Security Awareness
Security Bulletins
Technical Briefs
Threat Research
Vulnerability Management
Subscribe to our Monthly Newsletter
GLOBAL HEADQUARTERS
Arctic Wolf Networks
8939 Columbine Rd
Eden Prairie, MN 55347
1.888.272.8429
𝕏
REQUEST A DEMO
Solutions
Managed Detection and Response
Cloud Detection and Response
Exposure Management​
Cloud Security Posture Management
Security Awareness & Training
Incident Response
Aurora Endpoint Security
Company
Contact Us
Careers
Leadership
Newsroom
Partners
Why Partner with Arctic Wolf?
Resources
Blog
Case Studies
Webinars
Events
Analyst Reports
Newsletter
© 2026 Arctic Wolf Networks Inc. All Rights Reserved.
Privacy Notice
Terms of Use
Cookie Policy
Accessibility Statement
Information Security
Sustainability Statement
Cookies Settings