Check Point has patched a critical authentication vulnerability (CVE-2026-16232) in SmartConsole that is already being exploited and allows full admin access.
The LegacyHive vulnerability enables privilege escalation on Windows 10 2004+ and Windows Server 2022; an unofficial micropatch from ACROS Security is available, with an official CVE and update pending.
Attackers often need only hours to reverse-engineer a published patch into a working exploit – faster patching processes alone do not provide adequate protection.
Attackers are actively exploiting two zero-day vulnerabilities in SonicWall SMA1000, with at least one classified as critical and identified as an SSRF flaw.
A chain of two zero-day vulnerabilities in SonicWall SMA enables attackers from the Inc ransomware group to achieve full system control over mobile access devices.
A publicly disclosed zero-day exploit (Legacyhive) allows Windows users to obtain administrative privileges and is currently not being addressed by a Microsoft patch.
CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 enable unauthenticated and authenticated attacks with severity 10.0; immediate patches required, no workarounds available.