Rapid Response

Active Threat Alerts

Built for MSSPs who need to brief clients before the story hits mainstream.

Updated continuously. Alerts represent items prioritized for MSSP response.

KEV Confirmed
67
Active Exploits
82
Advisories Ready
149
Critical🔴 KEV ALERTConfirmed

Check Point SmartConsole Auth Bypass (CVE-2026-16232) — Full Admin Takeover, CISA KEV

⚡ Recommended ActionIn the next 24 hours, audit every instance of Check Point SmartConsole in your environment and in any client environment where you hold management responsibility, then apply the vendor patch immediately without waiting for a scheduled maintenance window. If patching cannot be completed within the day, restrict SmartConsole access to internal management networks only and disable any internet-facing exposure as an emergency interim control. Send a direct client notification today to any account running Check Point infrastructure so they are aware of the risk and can see that you are already acting on it.
Jul 22, 2026CVE-2026-16232Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Fortinet FortiSandbox Unauthenticated RCE (CVE-2026-25089) — CISA KEV, Patch by July 19

⚡ Recommended ActionIn the next 24 hours, audit every instance of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS across your own stack and every client environment you manage, and document which are internet-exposed. Push the Fortinet vendor patch immediately for any exposed instance, and if a patch cannot be applied before end of business today, take that instance offline or block external access at the perimeter until it can be patched. Send a direct client notification today, not this week, so your clients hear about this from you before they read it elsewhere.
Jul 16, 2026CVE-2026-25089Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Oracle E-Business Suite Payments Takeover (CVE-2026-46817) — CISA KEV, Patch by July 18

⚡ Recommended ActionIn the next 24 hours, run a discovery sweep across every client environment you manage and identify any Oracle E-Business Suite deployment, then flag every instance where the application has any internet-facing HTTP exposure and treat those as actively compromised until patched. Contact those clients directly today with a written advisory, document that contact, and push them to apply Oracle's patch or restrict network access immediately. If a client cannot patch within 24 hours, work with them to take the Oracle Payments component offline or block external HTTP access at the perimeter as a temporary control while the patch is staged.
Jul 15, 2026CVE-2026-46817Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

SonicWall SMA1000 SSRF (CVE-2026-15409) — Actively Exploited, CISA KEV

⚡ Recommended ActionIn the next 24 hours, pull your asset inventory and your client asset inventories and identify every SonicWall SMA1000 appliance that is internet-facing. Apply the vendor patch immediately and do not wait for a scheduled maintenance window, because the attacker is not waiting either. Send a direct client notification today, even a short one, so the advisory obligation is documented and your clients know you are watching.
Jul 14, 2026CVE-2026-15409Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

SharePoint Server Missing Authentication (CVE-2026-56164) — CISA KEV, Patch by July 17

⚡ Recommended ActionIn the next 24 hours, pull a full inventory of every SharePoint Server deployment across your client base and your own environment, prioritize any instance with internet exposure, and begin emergency patch deployment today rather than waiting for the July 17 deadline. For any client where patching cannot happen immediately, push network-level controls to block external access to SharePoint until the patch is applied and document that advisory communication in writing.
Jul 14, 2026CVE-2026-56164Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Adobe ColdFusion Path Traversal RCE (CVE-2026-48282) | MSSP Advisory

⚡ Recommended ActionIn the next 24 hours, run an asset inventory sweep across your RMM for any ColdFusion installations in both your internal environment and every managed client environment. Push the patch or apply vendor mitigations immediately for any internet-exposed instance, and send a written client advisory today so your notification is timestamped before any incident occurs.
Jul 7, 2026CVE-2026-48282Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Citrix NetScaler Memory Overread Exploit Active (CVE-2026-8451) | MSSP Advisory

⚡ Recommended ActionAudit every NetScaler ADC and NetScaler Gateway appliance in your stack and across all managed client environments within the next 24 hours, prioritize any configured as a SAML Identity Provider, and push the upgrade to versions 14.1-72.61, 13.1-63.18, or the applicable FIPS and NDcPP builds immediately, then run the watchTowr Python detection script against any appliance you cannot patch tonight to confirm exposure status before morning.
Jul 3, 2026CVE-2026-8451, CVE-2023-4966, CVE-2026-3055Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) | MSSP Advisory

⚡ Recommended ActionIn the next 24 hours, pull a complete inventory of every SharePoint Server instance across your client base and your own internal environment, then confirm patch status against Microsoft's guidance and flag any unpatched instance as an active incident risk requiring immediate escalation. Send a direct written notification to every affected client today so your advisory obligation is documented, timestamped, and on record before any exploitation event occurs.
Jul 1, 2026CVE-2026-45659Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Cisco Unified Communications Manager SSRF Arbitrary File Write (CVE-2026-20230) | MSSP Advisory

⚡ Recommended ActionIn the next 24 hours, pull your asset inventory and your client asset inventories and identify every instance of Cisco Unified CM and Unified CM SME that is internet-exposed or reachable from an internet-facing segment. Apply Cisco's vendor patches immediately on any identified instance and send a direct client notification today, not at end of week, so your clients have the information they need to make patching decisions on systems you do not directly manage.
Jun 25, 2026CVE-2026-20230Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

PTC Windchill FlexPLM Unauthenticated RCE (CVE-2026-12569) | MSSP Advisory

⚡ Recommended ActionIn the next 24 hours, pull your client asset inventory and identify any Windchill or FlexPLM deployments, then flag every instance that has any internet-facing exposure for emergency patching ahead of the June 28 deadline. Send a direct written advisory to all manufacturing, engineering, and defense sector clients today regardless of whether you have confirmed exposure, because the documentation of that outreach protects you contractually and demonstrates the advisory value they are paying for.
Jun 25, 2026CVE-2026-12569Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory

⚡ Recommended ActionPull your asset inventory right now, identify every Ivanti Sentry instance across your own environment and every client environment you manage, apply the vendor patch released this week immediately, and send a written advisory to all clients today documenting the threat, your remediation steps, and any exposure findings so your obligation is on record.
Jun 12, 2026CVE-2026-10520Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) | MSSP Advisory

⚡ Recommended ActionPull a list of every Check Point Security Gateway in your client inventory and your own environment right now, confirm whether sk185033 has been applied, and send a direct written advisory to every client running an affected Gaia version today before end of business.
Jun 12, 2026CVE-2026-50751Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Ivanti Sentry OS Command Injection RCE (CVE-2026-10520) | MSSP Advisory

⚡ Recommended ActionIn the next 24 hours, audit every Sentry deployment across your own infrastructure and your full client base to confirm whether endpoints are externally reachable and whether mTLS or Neurons for MDM access restrictions are in place. Any appliance that is internet-exposed and unmanaged gets patched or taken offline today, not by June 14. Send a direct client notification this afternoon to every account running Ivanti Sentry so they cannot later claim they were not warned.
Jun 11, 2026CVE-2026-10520Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Chrome V8 Out-of-Bounds Memory Access RCE (CVE-2026-11645) | MSSP Advisory

⚡ Recommended ActionPush Chrome version 149.0.7827.102 or 149.0.7827.103 to every managed endpoint and every internal technician workstation within the next 24 hours using your RMM, and send a direct client notification today naming CVE-2026-11645 and confirming the patch is in flight.
Jun 9, 2026CVE-2026-11645Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Check Point Security Gateway Authentication Bypass RCE (CVE-2026-50751) | MSSP Advisory

⚡ Recommended ActionAudit every Check Point Security Gateway in your own stack and across all client accounts within the next 24 hours and confirm patch status against the vendor advisory. For any unpatched gateway, treat it as actively compromised, restrict IKEv1 negotiation at the firewall policy level as an immediate compensating control, and push the vendor patch the moment it clears your change process. Client-facing communication goes out today.
Jun 8, 2026CVE-2026-50751Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Cisco Catalyst SD-WAN Manager Privilege Escalation RCE (CVE-2026-20245) | MSSP Advisory

⚡ Recommended ActionAudit every client environment and your own stack for Cisco Catalyst SD-WAN Manager deployments in the next 24 hours, check the /var/log/scripts.log file for the IOC pattern Cisco published, open a Cisco TAC case immediately for any system you cannot verify as clean, and push a direct client advisory tonight naming the CVE and the configuration-change risk.
Jun 5, 2026CVE-2026-20245Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Mirasvit Full Page Cache Warmer RCE Active Exploitation (CVE-2026-45247) | MSSP Advisory

⚡ Recommended ActionAudit every client environment today for the Mirasvit Full Page Cache Warmer extension, push an emergency patch to version 1.11.12, then send each affected client a written advisory documenting when the patch was applied and what log review was performed to rule out prior compromise.
Jun 4, 2026CVE-2026-45247Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Google Android Framework Integer Overflow LPE Exploited (CVE-2025-48595) | MSSP Advisory

⚡ Recommended ActionAudit every Android device in your team's hands and any client-enrolled Android endpoints in your MDM within the next 24 hours, confirm the June 2026-06-05 patch level is applied or push an immediate enrollment compliance alert to flag unpatched devices, and send a direct client advisory today naming CVE-2025-48595, the zero-interaction risk, and the steps to check patch level on Android.
Jun 2, 2026CVE-2025-48595Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Palo Alto Networks PAN-OS Authentication Bypass VPN (CVE-2026-0257) | MSSP Advisory

⚡ Recommended ActionAudit your entire Palo Alto estate within 24 hours and apply vendor patches immediately where available. Contact all clients with PAN-OS devices and provide emergency patching guidance or temporary mitigation steps before end of business today.
May 29, 2026CVE-2026-0257Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Daemon Tools Lite Embedded Malicious Code Vulnerability (CVE-2026-8398) | MSSP Advisory

⚡ Recommended ActionAudit your stack and all client environments for Daemon Tools Lite installations within 24 hours. Remove the software immediately where possible or apply vendor patches if available. Document removal decisions for compliance with BOD 22-01 requirements.
May 27, 2026CVE-2026-8398Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Nx Console Embedded Malicious Code Supply Chain (CVE-2026-48027) | MSSP Advisory

⚡ Recommended ActionAudit all client environments within 24 hours to identify Nx Console installations and immediately isolate any affected developer workstations. Force credential resets for any developer accounts that had access to production systems, rotate API keys and service account credentials, and implement emergency monitoring for unusual authentication patterns across client networks.
May 27, 2026CVE-2026-48027Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

LiteSpeed cPanel Plugin Privilege Escalation to Root (CVE-2026-48172) | MSSP Advisory

⚡ Recommended ActionInventory all client hosting environments using LiteSpeed cPanel plugins within 24 hours and apply vendor patches immediately. Contact hosting providers for client sites you do not directly control and document the notification for compliance records.
May 26, 2026CVE-2026-48172Open Client Advisory →
Critical🔴 KEV ALERTHigh Confidence

Trend Micro Apex One Path Traversal RCE (CVE-2026-34926) | MSSP Advisory

⚡ Recommended ActionDeploy the Trend Micro patch immediately across all Apex One installations and notify every client running Apex One of the active exploitation within 24 hours.
May 26, 2026CVE-2026-34926Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

LiteSpeed cPanel Plugin Privilege Escalation RCE Root (CVE-2026-48172) | MSSP Advisory

⚡ Recommended ActionIdentify all client environments running LiteSpeed cPanel Plugin and coordinate immediate patching or temporary plugin disabling within 24 hours.
May 23, 2026CVE-2026-48172Open Client Advisory →
Critical🔴 KEV ALERT

Trend Micro Apex One Directory Traversal RCE (CVE-2026-34926) | MSSP Advisory

⚡ Recommended ActionAudit all client Apex One deployments within 24 hours and verify vendor patches are applied immediately. Contact clients with on-premise Apex One installations to confirm their patch status and document your advisory in writing.
May 21, 2026CVE-2026-34926Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Microsoft Defender Malware Protection Engine Privilege Escalation (CVE-2026-41091) | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft security updates for Defender immediately across your own infrastructure and client environments within 24 hours, then communicate the criticality to all clients running Windows Defender.
May 21, 2026CVE-2026-41091, CVE-2026-45498Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Microsoft Exchange OWA XSS Zero-Day Active (CVE-2026-42897) | MSSP Advisory

⚡ Recommended ActionDisable Outlook Web Access on all Exchange servers immediately until Microsoft releases a patch, then notify clients within 24 hours with specific instructions to do the same.
May 18, 2026CVE-2026-42897Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Cisco SD-WAN Controller Authentication Bypass Active Exploit (CVE-2026-20182) | MSSP Advisory

⚡ Recommended ActionAudit all client Cisco SD-WAN deployments within 24 hours and coordinate emergency patching for CVE-2026-20182 on both Controller and Manager components.
May 15, 2026CVE-2026-20182Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Cisco Catalyst SD-WAN Controller Auth Bypass Admin Access (CVE-2026-20182) | MSSP Advisory

⚡ Recommended ActionContact every client running Cisco Catalyst SD-WAN Controller or SD-WAN Manager immediately and schedule emergency patching within 24 hours.
May 14, 2026CVE-2026-20182Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182) | MSSP Advisory

⚡ Recommended ActionAudit every client environment for Cisco SD-WAN devices within 24 hours and immediately implement CISA Emergency Directive 26-03 mitigations. Contact clients with exposed devices before they discover the risk themselves, positioning your firm as proactive rather than reactive.
May 14, 2026CVE-2026-20182Open Client Advisory →
Critical🔴 KEV ALERT

Palo Alto Networks PAN-OS Captive Portal RCE (CVE-2026-0300) | MSSP Advisory

⚡ Recommended ActionAudit all Palo Alto devices in your environment and client environments within 24 hours. Implement the workarounds immediately by restricting captive portal access to trusted zones only or disabling it entirely if unused.
May 6, 2026CVE-2026-0300Open Client Advisory →
Critical🔴 KEV ALERT

Ivanti Endpoint Manager Mobile Unauthenticated RCE (CVE-2026-1340) | MSSP Advisory

⚡ Recommended ActionAudit your internal mobile management tools and all client EPMM deployments within 24 hours. Apply vendor patches immediately where available or prepare emergency migration plans for unpatched systems before the April deadline.
May 6, 2026CVE-2026-1340Open Client Advisory →
Critical🔴 KEV ALERT

Fortinet FortiClient EMS SQL Injection RCE (CVE-2026-21643) | MSSP Advisory

⚡ Recommended ActionAudit all FortiClient EMS deployments across your stack and client environments within 24 hours. Apply Fortinet patches immediately where available or prepare client communications about service disruption if systems must be taken offline.
May 6, 2026CVE-2026-21643Open Client Advisory →
Critical🔴 KEV ALERT

Cisco Catalyst SD-WAN Manager Password Storage Privilege Escalation (CVE-2026-20128) | MSSP Advisory

⚡ Recommended ActionInventory all Cisco SD-WAN Manager instances across your stack and client environments within 24 hours. Apply CISA Emergency Directive 26-03 mitigations immediately or disconnect devices that cannot be patched before the April deadline.
May 6, 2026CVE-2026-20128Open Client Advisory →
Critical🔴 KEV ALERT

Cisco Catalyst SD-WAN Manager Privilege Escalation File Upload (CVE-2026-20122) | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Cisco Catalyst SD-WAN Manager deployments within 24 hours and cross-reference against CISA Emergency Directive 26-03 requirements. Execute the Hunt & Hardening Guidance protocols immediately on identified systems and prepare client communications explaining exposure status and remediation timelines.
May 6, 2026CVE-2026-20122Open Client Advisory →
Critical🔴 KEV ALERT

Marimo Pre-Authorization Remote Code Execution (CVE-2026-39987) | MSSP Advisory

⚡ Recommended ActionScan all managed environments for Marimo installations within 24 hours and immediately isolate any discovered instances. Contact affected clients with specific remediation timelines and document your advisory communication for contract compliance.
May 6, 2026CVE-2026-39987Open Client Advisory →
Critical🔴 KEV ALERT

Microsoft Windows Network Spoofing Protection Mechanism Failure (CVE-2026-32202) | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft security updates for CVE-2026-32202 across all Windows systems in your environment and client networks within 24 hours.
May 3, 2026CVE-2026-32202Open Client Advisory →
Critical🔴 KEV ALERT

ConnectWise ScreenConnect Path Traversal RCE (CVE-2024-1708) | MSSP Advisory

⚡ Recommended ActionUpdate ScreenConnect to version 23.9.8 or later within 24 hours and verify the patch deployment across all instances you operate.
May 3, 2026CVE-2024-1708Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

TrueConf Zero-Day Exploitation Southeast Asian Governments (CVE-2026-3502) | MSSP Advisory

⚡ Recommended ActionDisable TrueConf software across all client environments and your own infrastructure within 24 hours until patches are available.
Apr 21, 2026CVE-2026-3502Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Citrix NetScaler Unauthenticated Remote Code Execution (CVE-2026-3055) | MSSP Advisory

⚡ Recommended ActionImmediately patch all NetScaler ADC and Gateway appliances to the latest firmware version and notify all clients running NetScaler infrastructure within 24 hours.
Apr 21, 2026CVE-2026-3055Open Client Advisory →
Critical🔴 KEV ALERTConfirmed

Citrix NetScaler Critical RCE Exploited (CVE-2026-3055) | MSSP Advisory

⚡ Recommended ActionImmediately inventory all client NetScaler deployments and push emergency patching within 24 hours for any instances running vulnerable firmware versions.
Apr 21, 2026CVE-2026-3055Open Client Advisory →
High🔴 KEV ALERTConfirmed

Citrix NetScaler ADC and Gateway Memory Buffer Vulnerability (CVE-2026-8452)

⚡ Recommended ActionIn the next 24 hours, pull a full inventory of every NetScaler ADC and NetScaler Gateway instance across your own stack and every client account, then cross-reference against Citrix's published patch guidance and apply available mitigations immediately. Do not wait for the August 29 deadline — contact any client running an affected version today with a direct communication that names the vulnerability, states the risk, and confirms your remediation timeline.
Aug 26, 2026CVE-2026-8452Open Client Advisory →
High🔴 KEV ALERTConfirmed

Microsoft Entra ID Deserialization Vulnerability (CVE-2026-69836)

⚡ Recommended ActionIn the next 24 hours, audit every Entra ID tenant you manage, starting with your own, and confirm that Microsoft's published mitigations are applied and verified, not just scheduled. Pull your delegated admin access logs for anomalous authentication events going back at least 14 days and treat any unexplained service principal activity as a potential indicator of prior compromise. Send a direct client notification today, not a newsletter, a direct message to each client's primary contact explaining the vulnerability, the action you are taking on their behalf, and what they need to do on their end.
Aug 21, 2026CVE-2026-69836Open Client Advisory →
High🔴 KEV ALERTConfirmed

N-able N-central Authentication Bypass (CVE-2026-18556)

⚡ Recommended ActionIn the next 24 hours, pull your N-central version, confirm whether you are running an affected build, and apply the vendor patch immediately without waiting for a scheduled maintenance window. If a patch is not yet available or cannot be applied today, take your N-central instance off public internet exposure right now and restrict access to known IP ranges only. Send a brief, factual client notification today stating that you are actively managing a vulnerability in your management platform and that you have taken steps to protect their environments.
Aug 4, 2026CVE-2026-18556Open Client Advisory →
High🔴 KEV ALERTConfirmed

Gamaredon WinRAR Vulnerability Data Theft Campaign (CVE-2025-8088) | MSSP Advisory

⚡ Recommended ActionAudit every managed endpoint and your own internal machines for WinRAR installations within the next 24 hours, patch or remove them immediately, and send clients a direct advisory today naming CVE-2025-8088, stating that RAR archive attachments should not be opened without confirmation from the sender, and explaining that you are actively verifying patch status across their environment.
Jun 2, 2026CVE-2025-8088Open Client Advisory →
High🔴 KEV ALERTConfirmed

Fortinet FortiClient EMS Authentication Bypass RCE (CVE-2026-35616) | MSSP Advisory

⚡ Recommended ActionImmediately update all FortiClient EMS instances to the latest patched version and verify no unauthorized access occurred in server logs within the past 30 days.
May 28, 2026CVE-2026-35616Open Client Advisory →
High🔴 KEV ALERTConfirmed

TanStack Malicious npm Package Supply Chain Compromise (CVE-2026-45321) | MSSP Advisory

⚡ Recommended ActionAudit all internal tools and client environments for TanStack usage within 24 hours. Issue immediate client advisories about the compromised npm packages and provide specific remediation steps. Coordinate with clients to identify and isolate any systems running the malicious versions.
May 27, 2026CVE-2026-45321Open Client Advisory →
High🔴 KEV ALERT

Drupal Core SQL Injection RCE Privilege Escalation (CVE-2026-9082) | MSSP Advisory

⚡ Recommended ActionInventory all Drupal instances across client environments and your own infrastructure within 24 hours. Coordinate emergency patching windows with affected clients and apply vendor mitigations immediately, treating this as an active exploitation scenario regardless of the 2026 deadline.
May 22, 2026CVE-2026-9082Open Client Advisory →
High🔴 KEV ALERT

Langflow CORS Validation Authentication Token Theft (CVE-2025-34291) | MSSP Advisory

⚡ Recommended ActionAudit all Langflow deployments across your stack and client environments within 24 hours. Apply vendor patches immediately or isolate Langflow instances from network access until patches are available. Send client notifications today about this vulnerability if they use Langflow for any AI or automation workflows.
May 21, 2026CVE-2025-34291Open Client Advisory →
High🔴 KEV ALERTConfirmed

Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498) | MSSP Advisory

⚡ Recommended ActionAudit all client Defender deployments within 24 hours and apply Microsoft's mitigation guidance immediately. Contact clients with Defender installations to communicate the risk and document your advisory in writing for liability protection.
May 20, 2026CVE-2026-45498Open Client Advisory →
High🔴 KEV ALERTConfirmed

Microsoft Defender Privilege Escalation LPE (CVE-2026-41091) | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Defender versions within 24 hours and apply Microsoft patches immediately where available. For any systems where patches are not yet released, document the risk in client communications and consider temporary endpoint protection alternatives for high-value assets.
May 20, 2026CVE-2026-41091Open Client Advisory →
High🔴 KEV ALERTConfirmed

Adobe Acrobat Reader Heap Buffer Overflow RCE (CVE-2009-3459) | MSSP Advisory

⚡ Recommended ActionAudit all client environments within 24 hours for Adobe Acrobat and Reader installations, prioritizing versions from 2009-2012 that remain unpatched. Deploy emergency patches or remove the software entirely from critical systems while implementing PDF sandboxing controls across your stack.
May 20, 2026CVE-2009-3459Open Client Advisory →
High🔴 KEV ALERTConfirmed

Microsoft Exchange Server Outlook Web Access XSS (CVE-2026-42897) | MSSP Advisory

⚡ Recommended ActionAudit all client Exchange deployments within 24 hours and prioritize patching based on external exposure and privilege levels. Contact Microsoft immediately for mitigation guidance and prepare contingency plans for clients who cannot patch quickly enough to meet security requirements.
May 15, 2026CVE-2026-42897Open Client Advisory →
High🔴 KEV ALERTConfirmed

BerriAI LiteLLM SQL Injection Database Exposure (CVE-2026-42208) | MSSP Advisory

⚡ Recommended ActionAudit your security stack and client environments for LiteLLM deployments within 24 hours. Issue immediate client advisories about SQL injection risks in AI proxy services and demand vendor patches or service discontinuation where mitigations are unavailable.
May 8, 2026CVE-2026-42208Open Client Advisory →
High🔴 KEV ALERT

Ivanti EPMM Improper Input Validation RCE (CVE-2026-6973) | MSSP Advisory

⚡ Recommended ActionInventory your stack and all client environments for Ivanti EPMM deployments within 24 hours. Contact every affected client immediately with mitigation guidance or discontinuation recommendations if patches remain unavailable. Document your advisory communications to protect against retention issues.
May 7, 2026CVE-2026-6973Open Client Advisory →
High🔴 KEV ALERT

Microsoft SharePoint Server Input Validation Spoofing (CVE-2026-32201) | MSSP Advisory

⚡ Recommended ActionRun asset discovery across all client networks within 24 hours to identify SharePoint Server instances and their patch status. Deploy Microsoft's security updates immediately on any identified systems and document the remediation in your compliance tracking for BOD 22-01 requirements.
May 6, 2026CVE-2026-32201Open Client Advisory →
High🔴 KEV ALERTConfirmed

Apache ActiveMQ Code Injection RCE (CVE-2026-34197) | MSSP Advisory

⚡ Recommended ActionScan all client environments within 24 hours for Apache ActiveMQ installations and instances. Contact affected clients immediately to coordinate emergency patching or service isolation. Update your standard security assessments to include ActiveMQ version checks going forward.
May 6, 2026CVE-2026-34197Open Client Advisory →
High🔴 KEV ALERT

JetBrains TeamCity Path Traversal Auth Bypass (CVE-2024-27199) | MSSP Advisory

⚡ Recommended ActionAudit all client environments for TeamCity instances within 24 hours and verify current patch status against vendor guidance. Contact clients running affected versions immediately with patch requirements and timeline, as this carries both ransomware risk and federal compliance implications for any clients in regulated industries.
May 6, 2026CVE-2024-27199Open Client Advisory →
High🔴 KEV ALERT

Quest KACE Systems Management Appliance Authentication Bypass (CVE-2025-32975) | MSSP Advisory

⚡ Recommended ActionAudit your stack and all client environments for Quest KACE SMA deployments within 24 hours, immediately apply vendor patches where available, and send client notifications about this vulnerability with specific remediation timelines. If patches are not available, prepare contingency plans for alternative management solutions.
May 6, 2026CVE-2025-32975Open Client Advisory →
High🔴 KEV ALERT

Synacor Zimbra Collaboration Suite XSS (CVE-2025-48700) | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Zimbra deployments today and push emergency patching communications before end of business. Temporarily restrict RMM access to Zimbra systems until patches are verified deployed across your client base.
May 6, 2026CVE-2025-48700Open Client Advisory →
High🔴 KEV ALERT

Kentico Xperience Path Traversal Arbitrary File Upload (CVE-2025-2749) | MSSP Advisory

⚡ Recommended ActionAudit your stack and all client environments for Kentico Xperience installations within 24 hours and apply vendor patches immediately. Contact clients running Kentico websites to schedule emergency patching or temporary service shutdowns if patches are unavailable.
May 6, 2026CVE-2025-2749Open Client Advisory →
High🔴 KEV ALERT

Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure (CVE-2026-20133) | MSSP Advisory

⚡ Recommended ActionInventory all client environments with Cisco Catalyst SD-WAN Manager immediately and assess exposure using CISA's Emergency Directive 26-03 guidance. Contact affected clients within 24 hours to discuss the vulnerability and coordinate patching or mitigation steps. Document your advisory efforts and client responses for compliance with service agreements.
May 6, 2026CVE-2026-20133Open Client Advisory →
High🔴 KEV ALERT

Microsoft Defender Privilege Escalation Access Control (CVE-2026-33825) | MSSP Advisory

⚡ Recommended ActionAudit all Defender deployments across your stack and client environments within 24 hours. Deploy Microsoft patches immediately where available, implement access control hardening per vendor guidance, or prepare alternative endpoint protection rollouts for environments where patches fail.
May 6, 2026CVE-2026-33825Open Client Advisory →
High🔴 KEV ALERT

SimpleHelp Missing Authorization Privilege Escalation (CVE-2024-57726) | MSSP Advisory

⚡ Recommended ActionAudit your SimpleHelp user permissions immediately and apply vendor patches within 24 hours. Review all existing API keys for unauthorized creation or excessive permissions, then inform clients that your remote access platform had a security update to maintain transparency about your security posture.
May 6, 2026CVE-2024-57726Open Client Advisory →
High🔴 KEV ALERT

SimpleHelp Path Traversal Remote Code Execution (CVE-2024-57728) | MSSP Advisory

⚡ Recommended ActionAudit your infrastructure and all client environments for SimpleHelp installations within 24 hours. Apply vendor patches immediately where possible, or isolate and replace SimpleHelp instances that cannot be patched before the weekend.
May 6, 2026CVE-2024-57728Open Client Advisory →
High🔴 KEV ALERT

Samsung MagicINFO 9 Server Path Traversal File Write (CVE-2024-7399) | MSSP Advisory

⚡ Recommended ActionScan all client networks for Samsung MagicINFO 9 Server instances within 24 hours and immediately isolate any discovered systems. Contact affected clients today with patch timelines or removal recommendations before they ask why their MSSP missed a CISA alert.
May 6, 2026CVE-2024-7399Open Client Advisory →
High🔴 KEV ALERT

D-Link DIR-823X Command Injection RCE (CVE-2025-29635) | MSSP Advisory

⚡ Recommended ActionRun network discovery scans across all client environments within 24 hours to identify D-Link DIR-823X devices and create a replacement timeline for each instance. Contact clients immediately with findings and position this as a critical infrastructure upgrade that cannot wait for the next refresh cycle.
May 6, 2026CVE-2025-29635Open Client Advisory →
CriticalHigh Confidence

Splunk Enterprise PostgreSQL Sidecar Pre-Auth RCE (CVE-2026-20253) | MSSP Advisory

⚡ Recommended ActionAudit every client environment and your own stack for Splunk Enterprise on AWS right now, confirm whether the PostgreSQL Sidecar Service is running by checking for the process on port 5435, apply Splunk's patch for versions 10 and above immediately, and send a direct written advisory to any client running Splunk before end of business today.
Jun 12, 2026CVE-2026-20253Open Client Advisory →
CriticalHigh Confidence

Ubiquiti UniFi OS Server Unauthenticated RCE (CVE-2026-34908) | MSSP Advisory

⚡ Recommended ActionWithin the next 24 hours, audit every client environment and your own internal stack for UniFi OS Server versions at or below 5.0.6, run the Bishop Fox detection script against all exposed instances, and push the upgrade to UniFi OS Server 5.0.8 before end of business today.
Jun 8, 2026CVE-2026-34908, CVE-2026-34909, CVE-2026-34910Open Client Advisory →
CriticalHigh Confidence

Windows Netlogon Stack Buffer Overflow RCE (CVE-2026-41089) | MSSP Advisory

⚡ Recommended ActionDeploy the May 2026 Windows patches to all domain controllers in your environment and every client environment within 24 hours.
Jun 1, 2026CVE-2026-41089Open Client Advisory →
CriticalHigh Confidence

WP Maps Pro Privilege Escalation Admin Account Creation (CVE-2026-8732) | MSSP Advisory

⚡ Recommended ActionContact every client running WordPress immediately to audit for WP Maps Pro installations and force update to version 6.1.1 or remove the plugin entirely within 24 hours.
Jun 1, 2026CVE-2026-8732Open Client Advisory →
CriticalHigh Confidence

Starlette Host Header Authentication Bypass (CVE-2026-48710) | MSSP Advisory

⚡ Recommended ActionAudit all internal and client systems running FastAPI or Starlette applications within 24 hours and apply the security patch released through GitHub, then test vulnerable systems using badhost.org before bringing them back online.
May 27, 2026CVE-2026-48710Open Client Advisory →
CriticalCredible Report

LiteSpeed cPanel Plugin Remote Code Execution | MSSP Advisory

⚡ Recommended ActionAudit all client environments for cPanel installations with LiteSpeed plugins and force immediate patching or service isolation within 24 hours.
May 27, 2026Open Client Advisory →
CriticalCredible Report

Lazarus Group RemotePE Malware Financial Targeting | MSSP Advisory

⚡ Recommended ActionContact all financial services clients within 24 hours with a specific threat advisory naming Lazarus Group and RemotePE malware, requiring immediate review of email security controls and endpoint detection coverage.
May 26, 2026Open Client Advisory →
CriticalHigh Confidence

Japanese LMS Zero-Day Cobalt Strike Deployment (CVE-2026-5426) | MSSP Advisory

⚡ Recommended ActionRun vulnerability scans across all client ASP.NET applications within 24 hours to identify hard-coded machine keys and push emergency patches for any LMS or web application using default cryptographic configurations.
May 26, 2026CVE-2026-5426Open Client Advisory →
Critical

Universal Robots PolyScope OS Remote Command Execution | MSSP Advisory

⚡ Recommended ActionContact all manufacturing clients immediately to identify Universal Robots installations and coordinate emergency patching to PolyScope OS version 5.25.1 within 24 hours.
May 26, 2026Open Client Advisory →
Critical

Microsoft SharePoint Deserialization RCE | MSSP Advisory

⚡ Recommended ActionContact all clients running SharePoint Server today to schedule emergency patching of CVE-2026-45659 within 24 hours.
May 26, 2026Open Client Advisory →
Critical

Drupal Core SQL Injection Active Exploitation | MSSP Advisory

⚡ Recommended ActionPatch all Drupal Core installations to the latest version within 24 hours and immediately scan your entire client base for Drupal instances using vulnerability scanners.
May 23, 2026Open Client Advisory →
Critical

Ubiquiti UniFi OS Critical Vulnerabilities Path Traversal RCE | MSSP Advisory

⚡ Recommended ActionDeploy patches for CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 across all client UniFi OS instances within 24 hours and verify patch status through your RMM platform.
May 22, 2026Open Client Advisory →
CriticalCredible Report

Cisco Secure Workload API Remote Code Execution | MSSP Advisory

⚡ Recommended ActionContact every client running Cisco Secure Workload today and schedule emergency patching within 24 hours.
May 22, 2026Open Client Advisory →
CriticalCredible Report

Drupal SQL Injection RCE Active Exploitation | MSSP Advisory

⚡ Recommended ActionPatch all client Drupal installations to version 10.2.11 or 10.3.6 immediately and scan for indicators of compromise including unexpected admin accounts and file modifications in the web root.
May 22, 2026Open Client Advisory →
Critical

Trend Micro Apex One Unauthenticated RCE | MSSP Advisory

⚡ Recommended ActionVerify all Trend Micro Apex One installations in your environment and client environments are updated to Service Pack 1 Critical Patch b13959 or later within 24 hours.
May 22, 2026Open Client Advisory →
Critical

Microsoft Defender Malware Engine Privilege Escalation LPE | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft's emergency patches for CVE-2026-41091 and CVE-2026-45498 across all internal systems and client environments within 24 hours through your patch management platform.
May 21, 2026Open Client Advisory →
Critical

Cisco Secure Workload API Authentication Bypass | MSSP Advisory

⚡ Recommended ActionAudit your client base for Cisco Secure Workload deployments within 24 hours and issue emergency patch notifications with confirmation requirements for all affected environments.
May 21, 2026Open Client Advisory →
Critical

ChromaDB Race Condition Remote Code Execution | MSSP Advisory

⚡ Recommended ActionInventory all client environments for ChromaDB installations immediately and push emergency updates to version 1.5.9 or later within 24 hours.
May 21, 2026Open Client Advisory →
Critical

SonicWall Gen6 SSL-VPN MFA Bypass | MSSP Advisory

⚡ Recommended ActionImmediately identify all SonicWall Gen6 SSL-VPN appliances across your client base and your own infrastructure, then apply emergency patches or disable the devices until patching is complete.
May 21, 2026Open Client Advisory →
CriticalCredible Report

First VPN Service Seized Law Enforcement Takedown | MSSP Advisory

⚡ Recommended ActionBlock all known First VPN IP ranges immediately and audit your firewall logs for any historical connections to these addresses within the past 90 days.
May 21, 2026Open Client Advisory →
Critical

Windows Defender Privilege Escalation Active Exploitation | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft's security updates through your RMM platform immediately and verify Defender is updated to the latest version on all managed endpoints within 24 hours.
May 21, 2026Open Client Advisory →
CriticalCredible Report

Windows Defender Zero-Day Detection Bypass | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft's December 2024 Defender engine updates immediately through Windows Update, WSUS, or your patch management platform within 24 hours.
May 21, 2026Open Client Advisory →
CriticalCredible Report

WantToCry Ransomware SMB Brute Force Remote Encryption | MSSP Advisory

⚡ Recommended ActionRun immediate network scans across all client environments to identify and document exposed SMB ports on external interfaces, then schedule emergency client calls to disable SMB on internet-facing systems within 24 hours.
May 20, 2026Open Client Advisory →
CriticalCredible Report

ChromaDB Unauthenticated Remote Code Execution | MSSP Advisory

⚡ Recommended ActionScan your infrastructure and all client environments for ChromaDB installations immediately and update to the patched version or isolate affected systems within 24 hours.
May 20, 2026Open Client Advisory →
CriticalCredible Report

GitHub Internal Repositories Breached via Malicious Extension | MSSP Advisory

⚡ Recommended ActionAudit all Visual Studio Code extensions across your organization within 24 hours and establish mandatory approval processes for any new extension installations.
May 20, 2026Open Client Advisory →
CriticalCredible Report

Drupal Core Critical Vulnerability High Exploitation Risk | MSSP Advisory

⚡ Recommended ActionInventory all client Drupal installations immediately and schedule emergency patching windows within 24 hours, starting with internet-facing instances running Drupal 10.2 or 10.3.
May 20, 2026Open Client Advisory →
CriticalCredible Report

Microsoft Disrupts Malware Code-Signing Service Ransomware Groups | MSSP Advisory

⚡ Recommended ActionCheck all recent installations of AnyDesk, Microsoft Teams, Putty, and Webex across your client base within the last 90 days and verify download sources match official vendor repositories.
May 20, 2026Open Client Advisory →
CriticalCredible Report

Windows Zero-Day Vulnerabilities YellowKey GreenPlasma MiniPlasma | MSSP Advisory

⚡ Recommended ActionDeploy emergency endpoint monitoring rules in your RMM platform to detect unusual process execution patterns associated with these exploit techniques within the next 24 hours.
May 19, 2026Open Client Advisory →
CriticalCredible Report

F5 NGINX Critical Vulnerability Active Exploitation | MSSP Advisory

⚡ Recommended ActionInventory all NGINX deployments across your infrastructure and client environments within 24 hours, then coordinate emergency patching with F5 security advisories.
May 18, 2026Open Client Advisory →
Critical

NGINX Rift Critical RCE Exploitation Active | MSSP Advisory

⚡ Recommended ActionPatch all NGINX instances in your environment immediately and send emergency advisories to all clients within 24 hours identifying their NGINX deployments and requiring immediate patching.
May 18, 2026Open Client Advisory →
Critical

MiniPlasma Windows Privilege Escalation Zero-Day | MSSP Advisory

⚡ Recommended ActionBlock the cldflt.sys driver through Windows Defender Application Control policies on all managed endpoints within 24 hours.
May 18, 2026Open Client Advisory →
Critical

Windows Kernel MiniPlasma Privilege Escalation LPE | MSSP Advisory

⚡ Recommended ActionDeploy advanced endpoint protection with behavioral monitoring on all Windows systems within 24 hours and immediately notify clients about this unpatched privilege escalation risk affecting their Windows infrastructure.
May 17, 2026Open Client Advisory →
Critical

NGINX Heap Buffer Overflow RCE Exploited | MSSP Advisory

⚡ Recommended ActionPatch all NGINX installations to version 1.30.1 or later immediately and verify client NGINX versions through your RMM tools within 24 hours.
May 17, 2026Open Client Advisory →
Critical

Funnel Builder Plugin WooCommerce Checkout Skimming | MSSP Advisory

⚡ Recommended ActionAudit all managed WordPress sites for Funnel Builder plugin installations and disable the plugin immediately on any WooCommerce sites until a patched version releases.
May 16, 2026Open Client Advisory →
Critical

Microsoft Exchange Server OWA XSS Active Exploitation | MSSP Advisory

⚡ Recommended ActionContact all clients with on-premises Exchange servers today to disable external OWA access until Microsoft patches this zero-day.
May 15, 2026Open Client Advisory →
Critical

Cisco Catalyst SD-WAN Controller Authentication Bypass | MSSP Advisory

⚡ Recommended ActionPatch all Cisco Catalyst SD-WAN Controllers to the latest firmware version immediately and verify authentication logs for suspicious access patterns over the past 30 days.
May 15, 2026Open Client Advisory →
CriticalCredible Report

Cisco Catalyst SD-WAN Controller Authentication Bypass RCE | MSSP Advisory

⚡ Recommended ActionImmediately inventory all client environments for Cisco Catalyst SD-WAN Controller and Manager deployments and schedule emergency patching within 24 hours.
May 15, 2026Open Client Advisory →
Critical

Exim Mail Server User-After-Free RCE | MSSP Advisory

⚡ Recommended ActionImmediately audit all client environments for Exim installations and push emergency patches or disable Exim services until updates can be applied within 24 hours.
May 14, 2026Open Client Advisory →
Critical

KongTuke Initial Access Brokers Microsoft Teams Social Engineering | MSSP Advisory

⚡ Recommended ActionBlock external Teams communications in client tenants immediately and configure Microsoft Teams to reject calls and messages from outside the organization.
May 14, 2026Open Client Advisory →
Critical

Windows BitLocker Bypass and CTFMON Privilege Escalation | MSSP Advisory

⚡ Recommended ActionBlock CTFMON.exe execution through your RMM endpoint protection policies and notify all clients within 24 hours that BitLocker alone cannot protect against physical device compromise until Microsoft patches these vulnerabilities.
May 14, 2026Open Client Advisory →
Critical

West Pharmaceutical Services Ransomware Attack | MSSP Advisory

⚡ Recommended ActionContact all manufacturing clients within 24 hours to verify their network segmentation between IT and OT environments and confirm ransomware backup restoration procedures are tested and functional.
May 13, 2026Open Client Advisory →
Critical

Windows Critical RCE Flaws Discovered by AI System | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft's May 12 patches immediately across your RMM infrastructure, PSA systems, and all client Windows endpoints within 24 hours.
May 13, 2026Open Client Advisory →
Critical

Nitrogen Ransomware Foxconn Manufacturing Facilities Attack | MSSP Advisory

⚡ Recommended ActionContact all manufacturing clients within 24 hours to verify their OT network segmentation and disable unnecessary remote access connections between IT and operational systems.
May 13, 2026Open Client Advisory →
Critical

Microsoft DNS Server Unauthenticated RCE | MSSP Advisory

⚡ Recommended ActionDeploy Microsoft patches immediately to all Windows servers in your infrastructure and push emergency patching communications to clients with specific focus on domain controllers and DNS servers within 24 hours.
May 13, 2026Open Client Advisory →
Critical

Microsoft Windows Networking Authentication RCE Flaws | MSSP Advisory

⚡ Recommended ActionDeploy emergency Windows updates for CVE-2026-40361 and CVE-2026-40364 across all client environments within 24 hours and immediately audit your own RMM infrastructure for vulnerable Windows components.
May 13, 2026Open Client Advisory →
Critical

Linux Dirty Frag Zero-Day LPE | MSSP Advisory

⚡ Recommended ActionPatch all Linux systems immediately once vendor updates become available and audit which clients are running unpatched Linux distributions for emergency communications.
May 8, 2026Open Client Advisory →
Critical

TCLBANKER Banking Trojan Targets Financial Platforms | MSSP Advisory

⚡ Recommended ActionBlock all executable attachments in email security policies and immediately audit which clients have business banking credentials stored in your password management systems within 24 hours.
May 8, 2026Open Client Advisory →
Critical

xrdp Pre-Authentication Remote Code Execution | MSSP Advisory

⚡ Recommended ActionPatch all xrdp installations across your stack and client environments within 24 hours, starting with internet-facing systems.
May 8, 2026Open Client Advisory →
Critical

TCLBanker Trojan Self-Spreads WhatsApp Outlook Banking Theft | MSSP Advisory

⚡ Recommended ActionBlock all MSI installer execution except from verified software deployment channels and immediately audit all Logitech software installations across your stack and client environments within 24 hours.
May 7, 2026Open Client Advisory →
Critical

Palo Alto Networks PAN-OS Authentication Bypass Zero-Day | MSSP Advisory

⚡ Recommended ActionImmediately audit all client Palo Alto PAN-OS devices for the latest patches and deploy the emergency hotfixes Palo Alto released, then review firewall logs from the past month for suspicious administrative activity or configuration changes.
May 7, 2026Open Client Advisory →
CriticalCredible Report

Palo Alto Networks PAN-OS Critical RCE Exploited | MSSP Advisory

⚡ Recommended ActionPatch all Palo Alto PAN-OS systems immediately and disable User-ID Authentication Portal exposure to untrusted networks until patches are applied.
May 7, 2026Open Client Advisory →
Critical

MuddyWater Microsoft Teams Credential Theft Campaign | MSSP Advisory

⚡ Recommended ActionBlock external Teams communications for all client tenants within 24 hours and audit your own Teams tenant for unauthorized external contacts or file shares.
May 6, 2026Open Client Advisory →
Critical

Weaver E-cology Critical Vulnerability Active Exploitation | MSSP Advisory

⚡ Recommended ActionInventory all client environments for Weaver E-cology installations and immediately isolate those systems from network access until patches can be applied.
May 6, 2026Open Client Advisory →
Critical

Trellix Source Code Breach Supply Chain | MSSP Advisory

⚡ Recommended ActionEmail all clients running Trellix products within 24 hours explaining the breach impact and implementing additional monitoring layers outside the Trellix stack until the vendor releases detection updates.
May 5, 2026Open Client Advisory →
Critical

Weaver E-cology Critical RCE Actively Exploited | MSSP Advisory

⚡ Recommended ActionContact all clients immediately to identify Weaver E-cology installations and coordinate emergency patching or network isolation within 24 hours.
May 5, 2026Open Client Advisory →
Critical

Progress MOVEit Automation Arbitrary Code Execution | MSSP Advisory

⚡ Recommended ActionInventory all client MOVEit Automation installations immediately and contact Progress Software for the emergency patch release timeline.
May 5, 2026Open Client Advisory →
Critical

Apache HTTP Server HTTP/2 Double Free DoS RCE | MSSP Advisory

⚡ Recommended ActionPatch all Apache HTTP Server instances to the latest version immediately and disable HTTP/2 protocol support as a temporary mitigation if patching cannot be completed within 24 hours.
May 5, 2026Open Client Advisory →
Critical

UAT-8302 Targets Government Entities Across Regions | MSSP Advisory

⚡ Recommended ActionContact all government clients within 24 hours to brief them on UAT-8302 targeting patterns and validate their endpoint detection coverage against custom malware deployment techniques.
May 5, 2026Open Client Advisory →
Critical

Ollama Windows Auto-Updater Persistent RCE | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Ollama installations within 24 hours and disable automatic updates until patches are released.
May 5, 2026Open Client Advisory →
Critical

MetInfo CMS Code Injection RCE Exploitation | MSSP Advisory

⚡ Recommended ActionScan all client environments immediately for MetInfo CMS installations and either patch to the latest version or take affected sites offline within 24 hours.
May 5, 2026Open Client Advisory →
Critical

CloudZ RAT Abuses Microsoft Phone Link SMS Interception | MSSP Advisory

⚡ Recommended ActionAudit all Windows systems in your environment and client networks for Phone Link installations and disable the service through Group Policy immediately.
May 5, 2026Open Client Advisory →
Critical

CloudZ RAT Pheno Plugin SMS OTP Theft | MSSP Advisory

⚡ Recommended ActionAudit all client environments for active Microsoft Phone Link installations and disable the service through Group Policy or direct configuration where business justification does not exist.
May 5, 2026Open Client Advisory →
Critical

Weaver E-cology Unauthenticated RCE Debug API | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Weaver E-cology installations immediately and demand emergency patching to version 20260312 or newer within 24 hours.
May 5, 2026Open Client Advisory →
Critical

Weaver E-cology Critical RCE Actively Exploited | MSSP Advisory

⚡ Recommended ActionAudit all client environments for Weaver E-cology installations within 24 hours and isolate any discovered systems until patches can be applied.
May 4, 2026Open Client Advisory →
Critical

cPanel Authentication Bypass Exploitation Active | MSSP Advisory

⚡ Recommended ActionContact all clients using cPanel hosting within 24 hours to verify patch status and force password resets on all cPanel accounts immediately.
May 4, 2026Open Client Advisory →
Critical

Progress MOVEit Automation Authentication Bypass | MSSP Advisory

⚡ Recommended ActionImmediately audit your environment and all client networks for MOVEit Automation installations and push the Progress Software security update to every instance within 24 hours.
May 4, 2026Open Client Advisory →
Critical

Progress MOVEit Automation Auth Bypass RCE | MSSP Advisory

⚡ Recommended ActionScan all client environments for MOVEit Automation installations within 24 hours and push emergency patches to the latest fixed version immediately.
May 4, 2026Open Client Advisory →
Critical

Progress MOVEit Automation Authentication Bypass RCE | MSSP Advisory

⚡ Recommended ActionContact every client running MOVEit Automation immediately to verify they have applied the patches released by Progress and document their response in your ticketing system.
May 4, 2026Open Client Advisory →
CriticalCredible Report

cPanel Vulnerability Exploited Against Government MSP Networks | MSSP Advisory

⚡ Recommended ActionImmediately patch all cPanel installations in your environment and issue emergency advisories to every client running cPanel web hosting with specific patch deployment timelines within 24 hours.
May 4, 2026Open Client Advisory →
Critical

France Titres Government Data Breach | MSSP Advisory

⚡ Recommended ActionForce immediate password resets for all client accounts that use government document numbers or personal identifiers as authentication factors within 24 hours.
May 4, 2026Open Client Advisory →
Critical

cPanel Critical Flaw Sorry Ransomware Mass Exploitation | MSSP Advisory

⚡ Recommended ActionImmediately audit all client hosting environments for cPanel installations and push emergency patching within 24 hours while blocking unnecessary access to cPanel admin interfaces.
May 2, 2026Open Client Advisory →
Critical

SonicWall Firewall Vulnerabilities Exploited by Ransomware | MSSP Advisory

⚡ Recommended ActionAudit your client base immediately for SonicWall devices and schedule emergency firmware updates within 24 hours.
May 1, 2026Open Client Advisory →
Critical

The Com Threat Groups Target Critical Infrastructure Data Theft | MSSP Advisory

⚡ Recommended ActionAudit your identity platform configurations within 24 hours and enable conditional access policies that block logins from unrecognized devices or locations for all admin accounts accessing client environments.
May 1, 2026Open Client Advisory →
Critical

BlackCat Ransomware Insider Attack Campaign | MSSP Advisory

⚡ Recommended ActionImplement dual-control procedures for all client administrative access within 24 hours, requiring two-person authorization for any system changes or credential usage.
May 1, 2026Open Client Advisory →
Critical

Linux Kernel Nine-Year-Old Zero-Day Flaw | MSSP Advisory

⚡ Recommended ActionAudit your entire Linux server inventory today and establish emergency patching schedules for both your internal stack and all client Linux systems within 24 hours.
May 1, 2026Open Client Advisory →
Critical

Vercel OAuth Integration Breach Third-Party Compromise | MSSP Advisory

⚡ Recommended ActionAudit all OAuth integrations across your RMM, PSA, and client environments within 24 hours, document which applications have what level of access, and revoke any unused or overprivileged OAuth tokens immediately.
May 1, 2026Open Client Advisory →
Critical

cPanel WHM Authentication Bypass Zero-Day | MSSP Advisory

⚡ Recommended ActionPatch all cPanel and WHM installations to the latest version immediately and audit every client environment that uses cPanel-based hosting for signs of unauthorized administrative access or configuration changes.
May 1, 2026Open Client Advisory →
Critical

GitHub Git Push Remote Code Execution | MSSP Advisory

⚡ Recommended ActionCheck all GitHub Enterprise Server instances under your management and apply the security patches GitHub released for all supported versions immediately.
May 1, 2026Open Client Advisory →
Critical

Google Gemini CLI RCE in CI/CD Pipelines | MSSP Advisory

⚡ Recommended ActionImmediately audit all client CI/CD pipelines for '@google/gemini-cli' npm package usage and 'google-github-actions/run-gemini-cli' GitHub Actions workflow, then force updates to patched versions within 24 hours.
May 1, 2026Open Client Advisory →
Critical

cPanel WHM Authentication Bypass Admin Access | MSSP Advisory

⚡ Recommended ActionContact all clients running cPanel or WHM within 24 hours to verify patch status for CVE-2026-41940 and schedule emergency updates if unpatched.
May 1, 2026Open Client Advisory →
Critical

cPanel Authentication Bypass Zero-Day Exploited | MSSP Advisory

⚡ Recommended ActionContact every client using shared hosting or cPanel-based hosting immediately to verify their hosting provider has applied the CVE-2026-41940 patch and implemented additional authentication controls.
May 1, 2026Open Client Advisory →
CriticalCredible Report

Microsoft Defender Three Zero-Days Privilege Escalation | MSSP Advisory

⚡ Recommended ActionContact all Windows clients within 24 hours to verify their current Defender update status and implement additional endpoint monitoring for privilege escalation attempts until Microsoft patches the remaining two vulnerabilities.
Apr 21, 2026Open Client Advisory →
Every alert becomes a client-ready advisory under your brand.

See how BetterMSSP turns these into finished, branded client communications.

Preview Advisory Workflow →