
Kiteworks orders global 6-hour server shutdown over zero-day threat
Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.
17 stories tagged with this topic.

Kiteworks instructed all customers to shut down servers for six hours on Saturday after receiving threat intelligence about a potential zero-day attack, with no patch available.

Arista Networks released emergency patches for a zero-day vulnerability in VeloCloud Orchestrator On-Prem deployments, which was being actively exploited in the wild.

Cisco has acknowledged that attackers are actively exploiting a critical authentication bypass vulnerability in Secure Firewall Management Center, tracked as CVE-2026-20079.

Adobe released an emergency security update on Tuesday to address CVE-2026-75650, a max-severity zero-day vulnerability in Magento and Adobe Commerce actively exploited to install backdoors on e-commerce servers. The flaw, dubbed StyleSmuggler, was under active attack prior to patching.

Hosting providers and merchants face active exploitation of a Magento zero-day (StyleSmuggler) that bypasses all current patches. The first confirmed victim ran the latest security updates, and Adobe has yet to release a fix or CVE. Mitigation requires disabling GraphQL or deploying third-party blocking tools.

PaperCut has issued an urgent warning after attackers exploited an unpatched vulnerability in its NG and MF print management platforms, with no fix yet available.

Microsoft has released a fix for a critical vulnerability in Entra ID after confirming in-the-wild exploitation. The flaw allows attackers to bypass authentication controls in the identity and access management service.

Cisco has disclosed active exploitation of a high-severity vulnerability in Secure Firewall Management Center, allowing unauthorized device access.

Hackers are exploiting a zero-day vulnerability in the FastJson Java library to execute remote code on US-based systems without authentication or elevated privileges.

Arista released an emergency patch for a maximum-severity vulnerability in VeloCloud Orchestrator that attackers were already exploiting in the wild.

Check Point has issued a hotfix for a zero-day vulnerability in its SmartConsole GUI that attackers were already exploiting in the wild.

SonicWall has released emergency fixes for two zero-day vulnerabilities in its SMA1000 secure access gateways after observing active exploitation. No customer impact details have been disclosed.

Microsoft has acknowledged CVE-2026-50656, a privilege-escalation flaw in Microsoft Defender dubbed RoguePlanet, and is developing a patch after a researcher released a proof-of-concept exploit. The vulnerability affects Windows 10 and 11 systems regardless of real-time protection status.

Three critical Fortinet sandbox vulnerabilities, patched in April and June, are now under active exploitation, with attackers bypassing authentication and executing arbitrary code. Threat intelligence firm Defused reports exploitation began over the weekend, despite no public exploit for one flaw.

Cisco has released security updates for a zero-day vulnerability in Catalyst SD-WAN Manager (formerly vManage) that was actively exploited to gain root access. The flaw, tracked as CVE-2026-20262, affects all deployment types and stems from insufficient input validation during file uploads.

Microsoft's June 2026 Patch Tuesday is the largest in the cycle's history, covering close to 200 vulnerabilities in Windows and related software, with Rapid7 noting an additional 360 browser flaws that fall outside the official count.

Mandiant and Google Threat Intelligence Group have attributed an active compromise campaign to ShinyHunters (UNC6240), exploiting CVE-2026-35273 in Oracle PeopleSoft before Oracle issued its advisory on June 10, 2026. Over 100 organizations were exposed, 68% of them academic institutions.