Edge & VPN security
Vulnerabilities in the internet-facing gear attackers hit first: firewalls, VPNs, and load balancers from Fortinet, Citrix, Ivanti, Palo Alto, and more.
Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.
A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.
Akira ransomware reboots Windows into Safe Mode to shut off security tools
An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.
Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.
Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.
Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.
CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.
Ivanti Endpoint Manager patch: leaked database passwords, editable session recordings, crashable agents
Ivanti's August 2026 Endpoint Manager advisory fixes three high-severity flaws (CVE-2026-18129, -18127, -18125), all resolved in 2024 SU7.
An AI agent hit 460 servers on its own, but known CVEs did the breaking
A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
Attackers can slip past Fortinet's fix and keep reading a hacked firewall's files, CISA warns
CISA added CVE-2025-68686 to its exploited catalog: a bypass of Fortinet's FortiOS symlink fix lets attackers who already breached a FortiGate keep reading its
A Palo Alto VPN auth bypass is now a Qilin ransomware front door
CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.
Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.
Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.
Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box
SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.
Progress tells ShareFile users to shut servers down, and no patch means assume breach
Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.
We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.
FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.
Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped
Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.
Citrix shipped six NetScaler fixes. One of them isn't done until you change a setting.
Citrix fixed six NetScaler flaws, including a pre-login memory leak and an HTTP/2 Bomb denial of service. One fix needs a config change, not just an upgrade.
Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.
CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.
Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.
Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.
Your Fortinet password reset won't lock the FortiBleed attacker out
CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.
INC ransomware never used a zero-day. It used your patch backlog.
INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
FortiBleed isn't a Fortinet bug. It's every password you never rotated.
FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach
Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.