Week in review

AUSCERT Week in Review for 31st July 2026

Greetings, Organisations using JetBrains TeamCity On-Premises are being urged to patch a newly disclosed critical security vulnerability that could allow attackers to bypass authentication and execute malicious commands on affected servers. The flaw, tracked as CVE-2026-63077, impacts all versions of TeamCity On-Premises and has been rated particularly severely because it enables remote code execution with the privileges of the TeamCity server process. TeamCity Cloud customers are not affected, as mitigations have already been implemented by JetBrains. TeamCity is widely used by development teams to automate software building, testing, and deployment processes. According to JetBrains, successful exploitation of the vulnerability could expose sensitive project data, system configurations, stored credentials, and potentially compromise software build pipelines and release artifacts. These risks make the issue especially significant for organisations that rely on TeamCity as a core component of their software delivery environment. While JetBrains stated there is currently no evidence of active exploitation, the warning carries added weight given TeamCity’s history as a target for cybercriminals, including ransomware operators and state-sponsored threat actors in 2023 and 2024. Past vulnerabilities in the platform have been rapidly exploited in real-world attacks, prompting experts to recommend swift remediation whenever critical flaws are disclosed. JetBrains has already addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3 and strongly recommends upgrading as soon as possible. For customers unable to immediately move to the latest releases, the company has also provided a security patch plugin for supported versions dating back to TeamCity 2017.1. Additional security measures, including restricting access through VPNs and limiting exposure of internet-facing TeamCity services, are also recommended to reduce the risk of compromise. Critical VM Escape Vulnerability Patched in VMware ESXi Date: 2026-07-29 Author: Security Week [AUSCERT has informed the affected members via Critical MSINs] [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8797/] Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion. Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape. Cisco warns of FMC static credential flaw exploited in zero-day attacks Date: 2026-07-29 Author: Bleeping Computer [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8812/] Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account. Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Date: 2026-07-25 Author: The Hacker News Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project. US, Australia Release OT Isolation Guidance for Critical Infrastructure Date: 2026-07-29 Author: Security Week The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems. Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis. The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery. Origin Energy boss confirms almost a million Australians compromised by data breach Date: 2026-07-28 Author: Cyber Daily Aussie energy supplier Origin has said it has completed its initial investigations into a cyber security incident first disclosed on 22 July. “We have now completed the initial phase of our review into Origin’s customer data security incident,” Origin CEO Frank Calabria said in a 28 July statement. “At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.” ESB-2026.8651 – macOS Sequoia 15.7.8: CVSS (Max): 9.1* Apple has released security updates for macOS Sequoia 15.7.8 to address multiple security vulnerabilities. Users are advised to install the update to help protect their systems. ESB-2026.8797 – VMware Products: CVSS (Max): 7.8 Broadcom has released security updates for VMware Aria Operations to address a high-severity local privilege escalation vulnerability. ESB-2026.8812 – Cisco Secure FMC Software: CVSS (Max): 5.3 Cisco has released a security update for Secure Firewall Management Center (FMC) to address a critical static credential vulnerability that has been exploited in zero-day attacks. ESB-2026.8839 – GitLab Community & Enterprise Edition: CVSS (Max): 8.5 GitLab has released GitLab 19.2.1 patch updates for Community and Enterprise Editions to address security vulnerabilities and bug fixes. ESB-2026.8857 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has published security updates for Adobe Campaign addressing multiple vulnerabilities. Users are advised to apply the available updates to mitigate potential security risks. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 24th July 2026

Greetings, Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known cyber incident to affect an Australian energy retailer. The company, which serves more than 4.8 million customers, announced it is still investigating the extent of the breach and determining how many may have been impacted. According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers, and limited banking information such as the last four digits of a credit card or the last three digits of a bank account. The company has stressed that full banking and credit card details do not appear to have been exposed. Chief Executive Frank Calabria apologised to customers, acknowledging the trust placed in the company and assuring customers that securing systems and preventing further unauthorised access remains a top priority. Origin says it will contact affected customers directly once it has confirmed who was impacted. The breach came to light after a media outlet was contacted by an alleged hacker who provided a sample of customer records. Following notification of the incident, Origin alerted authorities and informed the Australian Securities Exchange. The incident adds to a growing list of major Australian cyber security breaches in recent years, following attacks on organisations including Optus, Medibank, and Qantas. Cyber security experts are urging Origin customers to remain vigilant for suspicious emails, text messages and phone calls, as criminals often leverage stolen personal information in follow-up scams. While some customers have recently experienced delays receiving energy bills, Origin says those issues are linked to July pricing changes and are not connected to the data breach investigation. Critical ServiceNow code execution flaw now exploited in attacks Date: 2026-07-20 Author: Bleeping Computer Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Date: 2026-07-18 Author: Bleeping Computer [See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8154] Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Date: 2026-07-21 Author: The Hacker News A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw. Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Date: 2026-07-22 Author: Security Week [AUSCERT has published security bulletins for these Oracle updates] Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. CISA orders urgent action on actively exploited Langflow RCE flaw Date: 2026-07-22 Author: Bleeping Computer The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks. ESB-2026.8410 – Mozilla Thunderbird: CVSS (Max): 10.0* A large number of vulnerabilities was patched in Mozilla Thunderbird, with the most severe being tracked as CVE-2026-16367 for a sandbox escape due to invalid pointer in the Disability Access APIs component. ESB-2026.8355 – Tenable Security Center: CVSS (Max): 9.9 Tenable Security Center has underlying third party libraries which were found to contain vulnerabilities. Updated versions are now available from the providers, which Tenable has implemented to address potential impacts of these identified vulnerabilities. ESB-2026.8317 – Atlassian Products: CVSS (Max): 10.0 83 high severity vulnerabilities and 18 critical severity third party vulnerabilities have been fixed in new versions of Atlassian products. Some of the patched vulnerabilities include remote code execution, denial of service and improper authorization. ASB-2026.0144 – Oracle Communications: CVSS (Max): 9.8 Oracle has released a critical patch update containing 168 new security patches or Oracle Communications. Many of these vulnerabilities can be remotely exploitable without authentication over a network. It has also been exploited in the CISA KEV. ESB-2026.8151 – roundcube: CVSS (Max): 10.0 Multiple vulnerabilities in roundcube such as account takeover, cross-site scripting, SSRF bypass, information disclosure and denial of service have been fixed in a new version release. Roundcube strongly recommends patching with the latest version. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 17th July 2026

Greetings, The Office of the Australian Information Commissioner (OAIC) has concluded its preliminary inquiries into the 2025 Qantas data breach, determining that there is currently insufficient evidence to warrant a formal regulatory investigation or enforcement action against the airline. The decision follows an almost year-long review of the incident, which affected approximately 5.12 million Australians and was one of the country's most significant privacy breaches in recent years. The breach occurred when a threat actor successfully carried out a phone-based social engineering, or “vishing”, attack against an employee at an overseas third-party contact centre used by Qantas. The attacker convinced the employee they were speaking with legitimate IT support and ultimately gained access to customer information through a customer relationship management platform. Qantas detected unusual activity within days, contained the incident, revoked access to the compromised account and began its incident response process. According to the OAIC, approximately 5.67 million customer records were affected, including names, email addresses, phone numbers and Qantas Frequent Flyer details. Around 1.7 million records also contained additional information such as addresses, dates of birth, and gender. Importantly, the compromised system did not store credit card details, financial information, passwords, PINs or passport details. After examining Qantas’ privacy governance, security controls, staff training, third-party oversight arrangements and incident response processes, the OAIC concluded there was no indication the airline had failed to take reasonable steps to protect personal information or ensure compliance with privacy obligations. The regulator noted that Qantas had implemented security audits, mandatory cyber-awareness training, contractual privacy requirements for service providers and a prompt breach response program. While the OAIC has closed its preliminary inquiries, it emphasised that the decision is not an endorsement of Qantas’ practices and that future investigations remain possible if new information emerges. The report highlights the growing threat of sophisticated social engineering attacks and reinforces the importance of strong cyber security controls, employee awareness training, and rapid incident response capabilities. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Date: 2026-07-14 Author: Bleeping Computer [AUSCERT has contacted members about this vulnerability where possible] SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. CISA warns admins to patch actively exploited SharePoint flaws Date: 2026-07-15 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Date: 2026-07-14 Author: ASD ACSC Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. SAP warns of critical flaws in NetWeaver and Commerce Cloud Date: 2026-07-14 Author: Bleeping Computer SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software. "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says. "This has high impact on confidentiality, integrity, and availability of the application." RabbitMQ Vulnerability Threatens Enterprise Systems Date: 2026-07-14 Author: Security Week A vulnerability in RabbitMQ could allow attackers to obtain the broker’s confidential OAuth secret, potentially posing a serious threat to enterprises, according to cybersecurity firm Miggo. RabbitMQ is a popular open source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. Tracked as CVE-2026-5721 (CVSS score of 8.7), the security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. ESB-2026.7869 – VMware Avi Load Balancer: CVSS (Max): 9.8 Broadcom has released updates for VMware Avi Load Balancer to fix seven vulnerabilities, including a critical authentication bypass flaw (CVE-2026-47865). ESB-2026.7892 – Zoom: CVSS (Max): 9.8 Zoom has released updates to address a critical account takeover vulnerability (CVE-2026-53412) affecting Windows-based Zoom products. ESB-2026.7904 – Adobe ColdFusion: CVSS (Max): 9.9 Adobe has released security updates for ColdFusion to address multiple critical vulnerabilities, including arbitrary code execution and server-side request forgery (SSRF). ESB-2026.8009 – Splunk Enterprise: CVSS (Max): 9.8 Splunk has released security updates for Splunk Enterprise to address multiple vulnerabilities affecting Windows and Unix/Linux platforms. ASB-2026.0129 – Microsoft ESU: CVSS (Max): 9.9 Microsoft has released its July 2026 Patch Tuesday update, addressing 335 vulnerabilities across Windows, Exchange Server, and other products, including multiple critical remote code execution and privilege escalation flaws. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 10th July 2026

Greetings, The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert following a large-scale cyber campaign targeting vulnerabilities in website content management systems (CMS) across the globe, including Australia. Small and medium-sized businesses have been particularly affected, with attackers actively scanning websites for weaknesses in popular CMS platforms and plugins. According to the ACSC, malicious actors are exploiting known vulnerabilities that enable unauthenticated file uploads, remote code execution and other forms of server compromise. Their primary objective is to deploy webshells, which are malicious scripts that provide remote access and control over web servers. Once installed, webshells can be used to deface websites, steal credentials and sensitive data, distribute additional malware, or provide a foothold for broader network compromise. The campaign is exploiting vulnerabilities in a range of widely used CMS products and plugins, particularly within the WordPress ecosystem, as well as other platforms including Craft CMS, MaxSite CMS, MetInfo CMS and Joomla components. The ACSC noted that this activity highlights the growing cyber threat landscape, with advances in artificial intelligence contributing to faster identification and exploitation of newly disclosed vulnerabilities. Website owners and administrators are being urged to inspect systems for signs of compromise, review logs for suspicious activity, isolate affected servers and restore websites from known-good backups where necessary. The ACSC also recommends prioritising patching, monitoring for unauthorised file creation and restricting file access to reduce the risk of webshell deployment. Organisations should ensure all website software and plugins remain up to date and consider additional controls to detect unusual processes and limit potential movement within corporate networks. Max severity Adobe ColdFusion flaw now exploited in attacks Date: 2026-07-06 Author: Bleeping Computer [Please see AUSCERT Bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.7232/] [AUSCERT has contacted affected members where applicable] Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution Date: 2026-07-03 Author: Security Week Two critical vulnerabilities in the popular AI code editor Cursor could lead to remote code execution on the underlying operating system, Cato Networks reports. The security defects are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS score of 9.8) and are referred to as DuneSlide, given that they lead to remote code execution (RCE) outside of the IDE’s sandbox. According to Cato, the flaws abuse Cursor’s automatic terminal command execution inside the sandbox, which does not prompt the user for approval, and can be triggered when a victim prompts the IDE to ingest an attacker-controlled payload. BeyondTrust warns of critical flaws in remote access software Date: 2026-07-07 Author: Bleeping Computer BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. The first vulnerability, tracked as CVE-2026-40138, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier). This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances, including accounts with elevated privileges. Critical Gitea Flaw Under Active Exploitation, Researchers Warn Date: 2026-07-07 Author: Security Week Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username. Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with a single HTTP header, Sysdig Sr. Director of Threat Research Michael Clark says. The issue exists because, in Gitea Docker images before 1.26.3, the default settings allow connections from any source IP address instead of enforcing an allowlist, security researcher Ali Mustafa, who was credited for finding the bug, explains. Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities Date: 2026-07-07 Author: The Hacker News A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, followed by either the deployment of a web shell for persistent access or a known post-exploitation tool called VShell. ASB-2026.0125 – ALERT CMS and Plugins: CVSS (Max): 10.0* ACSC has published a critical alert warning of a large-scale campaign actively exploiting vulnerabilities in multiple CMS platforms to compromise websites, urging organisations to patch affected systems and check for signs of compromise. ESB-2026.7592 – IBM MQ container software: CVSS (Max): 10.0 IBM has released updates to fix multiple vulnerabilities affecting IBM MQ Operator and Queue manager container images. The update addresses security issues including Improper Privilege Management, Exposure of Sensitive Information to an Unauthorized Actor, and Improper Validation of Integrity Check Value in components such as OpenSSL, WebSphere Application Server Liberty, and Java SE. ESB-2026.7596 – ALERT Palo Alto Prisma Browser: CVSS (Max): 9.6* Palo Alto Networks has incorporated Chromium security fixes into its products. These fixes are included in Google’s Chrome 150 release, which addresses 433 security fixes, including 20 Critical vulnerabilities affecting components such as Browser, V8, ANGLE, Skia, Blink, and FileSystem. ESB-2026.7647 – ALERT Juniper Networks CTPView: CVSS (Max): 10.0 Juniper Networks has released CTPView 9.3R2-3, addressing multiple vulnerabilities. Juniper SIRT is not aware of any malicious exploitation, and no workarounds are available. ESB-2026.7681 – OpenPLC v3: CVSS (Max): 9.9 Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem. Through the standard OpenPLC program compilation process, this may be escalated to arbitrary native code execution, potentially resulting in code execution as the OpenPLC runtime user. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 3rd July 2026

Greetings, Citrix has released patches for six vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances, but industry attention is firmly focused on CVE-2026-8451, a high-severity memory disclosure flaw that researchers say belongs to the same family of vulnerabilities as the infamous “CitrixBleed” attacks that have plagued organisations in recent years. The flaw carries a CVSS score of 8.8 and impacts NetScaler deployments configured as a SAML Identity Provider, a common setup for single sign-on environments. The vulnerability was discovered by security researchers at watchTowr while they were analysing another NetScaler issue disclosed earlier this year. According to the researchers, CVE-2026-8451 stems from insufficient input validation in the way NetScaler processes SAML authentication requests, creating an out-of-bounds memory read condition that could allow sensitive data to be exposed before authentication. In its analysis, watchTowr argued that the issue highlights a broader pattern of memory management weaknesses within NetScaler appliances. The researchers noted that similar memory disclosure vulnerabilities have repeatedly emerged in the product line, leading them to dub the latest flaw “CitrixBleed To Infinity And Beyond.” While there is currently no public evidence that CVE-2026-8451 is being actively exploited, security teams are taking the issue seriously. A closely related NetScaler vulnerability disclosed in March 2026 was exploited in the wild shortly after publication and was subsequently added to CISA’s Known Exploited Vulnerabilities catalogue. Organisations running affected NetScaler versions are strongly encouraged to apply Citrix’s latest updates as soon as possible and review vendor guidance for any additional mitigation steps. Critical SimpleHelp flaw exploited to deploy new stealer malware Date: 2026-06-29 Author: bleepingcomputer Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. The SimpleHelp platform is primarily used by managed service providers (MSPs), IT departments, helpdesks, and system administrators for remote monitoring and management (RMM). Hackers now exploit critical Oracle E-Business flaw in attacks Date: 2026-06-29 Author: Bleeping Computer [See also AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.5874/] [AUSCERT has contacted affected members where applicable] Attackers have begun exploiting a critical vulnerability (tracked as CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. This security flaw was found in the File Transmission component of EBS's Oracle Payments product and enables unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks. Anonymous researcher drops 0-day 'exploitarium' repo Date: 2026-06-29 Author: The Register [AUSCERT has published security bulletins for CVE-2026-55200] Not everyone is willing to follow responsible disclosure of vulns. An anonymous researcher has dumped what they say is working exploit code for zero-day vulnerabilities across 15 software products and open source projects without notifying any vendors or maintainers prior to publishing – and attackers are already exploiting at least two of these. The first is CVE-2026-55200, a critical, pre-authentication remote code execution (RCE) vulnerability in libssh2, a popular client-side C library that implements the SSH2 protocol. DirtyClone: A Linux Privilege Escalation That Leaves No Trace on DiskDirtyClone: Fourth Linux Kernel Flaw in Six Weeks Escalates to Root Date: 2026-06-27 Author: Security Affairs DirtyClone: a Linux kernel privilege escalation that silently rewrites executables in memory, leaving no disk trace. Patch now. JFrog Security Research published a working exploit walkthrough on June 25 for CVE-2026-43503 (CVSS score of 8.8), a Linux kernel privilege escalation they call DirtyClone. It’s the fourth vulnerability in the DirtyFrag family, all sharing the same root failure: file-backed memory gets treated as packet data, and an in-place network operation writes where it should have copied. CVSSIf your kernel doesn’t have the May 21 mainline patch, update now. CISA: Windows BlueHammer flaw now exploited by ransomware gangs Date: 2026-06-30 Author: Bleeping Computer CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks. Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process. ESB-2026.7189 – Apple iOS and iPadOS: CVSS (Max): 8.8* Apple has released updates for iOS and iPadOS to address multiple vulnerabilities affecting Kernel, WebKit, WebRTC, and other components, including issues that may allow unexpected system termination, cross-origin data exposure, and sensitive information disclosure. ESB-2026.7232 – Adobe ColdFusion: CVSS (Max): 10.0 Adobe has released security updates for ColdFusion versions 2025 and 2023 to address multiple critical and important vulnerabilities. These vulnerabilities could allow arbitrary code execution, privilege escalation, unauthorized file system access, and security feature bypass. ESB-2026.7296 – NetScaler ADC and NetScaler Gateway: CVSS (Max): 8.8 Multiple vulnerabilities have been identified in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Cloud Software Group strongly recommends updating as soon as possible. ESB-2026.7324 – Splunk: CVSS (Max): 9.8 Splunk has remediated multiple Common Vulnerabilities and Exposures (CVEs) affecting third-party packages included in Python for Scientific Computing version 4.3.2 and later. ESB-2026.7358 – IBM MQ for HPE NonStop: CVSS (Max): 9.8 IBM MQ for HPE NonStop is affected by multiple OpenSSL vulnerabilities, including CVE-2026-31789. The most severe issue may lead to a heap buffer overflow when processing specially crafted X.509 certificates, potentially resulting in a crash or code execution. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more