Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Citrix disclosed six high-severity vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, which allows unauthenticated memory disclosure when configured as a SAML identity provider. Other vulnerabilities can lead to denial-of-service (DoS) attacks, arbitrary file access, a...
Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to remote code execution (RCE). Disclosed on July 30, 2026, this flaw affects numer...
The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors must adhere to for compliance with the EU Cyber Resilience Act, effective December 2027. These standards outline minimum security features required for various product categories, including automa...