CISOs must immediately prioritize the three critical zero-days (CVE-2026-56155, CVE-2026-56164, CVE-2026-50661), but also inventory RC4-dependent systems and prepare for AES encryption migration to avoid authentication failures after the update.
Progress has confirmed a critical zero-day vulnerability in ShareFile Storage Zone Controller and is releasing patches requiring immediate attention from CISOs.
An unpatched PeopleSoft vulnerability is being exploited as a zero-day by extortionists; CISOs must scan their systems for indicators and prioritize Oracle patches.
A planned intelligence services law would require the BSI to report previously unknown security vulnerabilities to the BND — a practice that cybersecurity experts view critically.
The unauthenticated, remotely exploitable vulnerability CVE-2026-48282 in ColdFusion allows arbitrary file writing and code execution when RDS is enabled and unauthenticated.
Six AI code assistants fail to validate symlinks before write operations, allowing attackers to manipulate system configurations through fraudulent project files — some vendors have already patched, others are still working on fixes.