
Dutch NCSC warns of imminent Check Point VPN exploits
The Dutch National Cyber Security Centre has issued an alert about two critical vulnerabilities in Check Point VPN products, warning that exploitation is expected shortly.
Incidents, vulnerabilities, abuse and certificates.

The Dutch National Cyber Security Centre has issued an alert about two critical vulnerabilities in Check Point VPN products, warning that exploitation is expected shortly.

GitLab has urged users to apply an immediate patch for a critical path traversal vulnerability affecting its self-managed instances, warning of potential unauthorized access risks.

WHMCS released fixes for a critical remote code execution vulnerability (CVE-2026-67399) and a separate data-exposure flaw in its billing and automation platform. Administrators must upgrade to 9.0.8 or 8.13.7 to mitigate risks.

Cisco has acknowledged that attackers are actively exploiting a critical authentication bypass vulnerability in Secure Firewall Management Center, tracked as CVE-2026-20079.

G7 cybersecurity agencies have issued a call to action for governments and businesses to begin immediate planning for post-quantum cryptography migration, citing risks to authentication, DNSSEC, TLS, and routing security. The transition is expected to take years and requires coordinated action across digital infrastructure.

Adobe released an emergency security update on Tuesday to address CVE-2026-75650, a max-severity zero-day vulnerability in Magento and Adobe Commerce actively exploited to install backdoors on e-commerce servers. The flaw, dubbed StyleSmuggler, was under active attack prior to patching.

A phishing-as-a-service framework named BigBear 2.0 compromised 258 organizations by bypassing multi-factor authentication to extract over 5,000 Microsoft 365 credentials, security researchers reported.

Hosting providers and merchants face active exploitation of a Magento zero-day (StyleSmuggler) that bypasses all current patches. The first confirmed victim ran the latest security updates, and Adobe has yet to release a fix or CVE. Mitigation requires disabling GraphQL or deploying third-party blocking tools.

Attackers are exploiting two recently disclosed RouterOS flaws to compromise MikroTik routers with internet-exposed SSH services, security researchers report.

ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

A Google Cloud engineer accidentally disconnected all fiber-optic cables in a us-central1-b zone during routine maintenance, causing a 4-hour outage for virtual machines and elevated packet loss. Google confirmed the incident stemmed from procedural failure.

Cloudflare's early-access Vulnerability Discovery and Remediation service uses OpenAI models to detect and prioritize code vulnerabilities based on production exposure, proposing tailored patches and WAF rules for customer review.

Attackers breached Coder's Cloudflare infrastructure to distribute malicious Terraform modules containing credential-stealing code to developers.

Hewlett Packard Enterprise has released a security update for ArubaOS-CX to address a critical remote code execution vulnerability, mitigating potential network compromise risks.

Hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and gain remote code execution on affected systems.

DTLS 1.3, finalized in 2022, reduces handshake latency by 50% and introduces support for NIST-standardized post-quantum cryptography, addressing a critical gap in DTLS 1.2. wolfSSL has offered a production-ready implementation since the RFC's publication.

Security teams detected active exploitation of CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, shortly after the vendor released a fix. Attackers are generating administrative credentials and probing internal topologies on internet-facing systems.

Hackers hijacked BGP routes for Virtualizor's update servers, replacing legitimate VPS management software updates with malware in a targeted supply-chain attack.

Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability, leaving all user mailboxes open to hijacking.

Microsoft is investigating a service disruption affecting Exchange Online email delivery and authentication, with no estimated resolution time disclosed.