Skip to content
Cyber alerts

Cyber alerts

Digital.Nhs.Uk January 31, 2026

Ivanti has addressed two exploited vulnerabilities that could lead to unauthenticated remote code execution

Successful exploitation could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CVE-2026-21509 is under active exploitation and could be used to bypass OLE mitigations in Microsoft 365 and Microsoft Office

Cisco reports RCE vulnerability CVE-2026-20045 has had exploitation attempts in the wild

Successful exploitation could allow an unauthenticated attacker with HTTP network access to create, delete, or modify critical data accessible through the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug‑in

Palo Alto Networks releases security update for PAN-OS to address a high severity vulnerability that could result in a denial-of-service condition

Advisory addresses a vulnerability which if exploited could allow a remote unauthenticated attacker to perform arbitrary code or command execution

Scheduled updates for Microsoft products address 112 vulnerabilities, including an exploited information disclosure vulnerability and 2 others that have been publicly disclosed

A vulnerability in MongoDB could allow a remote attacker to extract secrets, credentials or other sensitive data

Successful exploitation of CVE-2025-14733 could allow a remote unauthenticated attacker to execute code remotely.