Get the weekly advisory digest
Every Monday: the week's bulletins in plain language. You confirm by email, and every digest has an unsubscribe link.
Almost done: check your inbox and click the confirmation link.
Please enter a valid email address and complete the verification check.
We could not subscribe you just now. Please try again later or write to info@cybernestsec.com.
Sent through Mailchimp. See our Privacy Policy .
High
October 5, 2026
CVE-2026-88779
A memory flaw lets an unauthenticated attacker knock NetScaler's SAML sign-in offline. Citrix has seen targeted attacks and CISA added it to KEV on October 4.
Read bulletin and recommended action →
Critical
October 3, 2026
CVE-2026-76504
A crafted request bypasses login on Cisco Catalyst SD-WAN Manager and grants admin API access. Cisco confirms exploitation; fixed releases are out.
Read bulletin and recommended action →
Critical
October 3, 2026
CVE-2026-104286
An unauthenticated attacker can write files on FortiMail. Fortinet confirms exploitation, fixed releases are still upcoming, and CISA added it to KEV.
Read bulletin and recommended action →
High
September 1, 2026
Aesto Health reported a breach affecting 9.5 million patients to HHS — check whether your organization uses it.
Read bulletin and recommended action →
High
September 1, 2026
CVE-2026-62911
CVE-2026-62911 lets an attacker take over Exchange mailboxes. Microsoft has patched it, but about 22,000 servers remain exposed.
Read bulletin and recommended action →
Critical
September 1, 2026
CVE-2026-82329
CVE-2026-82329 (CVSS 9.8) gives an unauthenticated attacker admin access to JFrog Artifactory. Exploited four days after the patch.
Read bulletin and recommended action →
Critical
September 1, 2026
CVE-2026-0768 CVE-2026-66066
CVE-2026-0768 (CVSS 9.8) allows remote code execution in Langflow, an AI app builder, and is being used to steal cloud and API keys.
Read bulletin and recommended action →
Critical
August 31, 2026
CVE-2026-82078 CVE-2026-81578
CISA added two PaperCut print-management flaws to its Known Exploited Vulnerabilities catalog on August 31, 2026.
Read bulletin and recommended action →
Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.