๐จ ACTIVE EXPLOITATION
-
Actively exploited Cisco ASA and FTD flaw can crash firewalls Attackers are exploiting a Cisco firewall flaw to remotely crash devices.
- Cisco Secure Firewall ASA and FTD customers are affected; Secure Firewall Management Center is not.
CVE-2026-20349affects ASA 9.16, 9.18, 9.20, 9.22, 9.23 and 9.24, plus FTD 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.- The flaw impacts IKEv2 Remote Access VPN, SSL VPN and FTD Zero Trust Network Access configurations.
- Unauthenticated attackers send crafted HTTP requests to the Remote Access SSL VPN service.
- Successful exploitation reloads the firewall and causes a denial-of-service condition; CISA added the flaw to its KEV catalog. ๐ Coverage: cybersecuritydive.com ยท ๐ via Cybersecurity Dive
-
Attackers Weaponize Rapid7 SharePoint Authentication-Bypass PoC
CVE-2026-55040Attackers are exploiting a Microsoft SharePoint authentication-bypass vulnerability using Rapid7's public PoC.- Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019 are affected.
CVE-2026-55040enables unauthenticated attackers to bypass JWT authentication.- Attackers can impersonate SharePoint users or administrators to disclose files and modify data.
- Defused observed attacks against its honeypots using Rapid7's PoC shortly after release. ๐ Source: rapid7.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via SecurityWeek
๐ฅ BREACHES & INCIDENTS
-
Colombia's Justice Ministry Hit by Ransomware Before Presidential Transition Ransomware disrupted services at Colombia's Justice Ministry.
- Colombia's Ministry of Justice was targeted days before the presidential transition.
- The attack disrupted services supporting illicit-drug monitoring and legal processes.
- The ministry reported a ransomware attack against its technology infrastructure.
- Acting Justice Minister Cielo Rusinque denied that information had been stolen. ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
Helpjuice support pages reportedly compromised in ClickFix attack Helpjuice-hosted support pages were reportedly altered to deliver a ClickFix lure.
- Helpjuice-hosted customer support pages were reportedly affected.
- Visitors saw a fake Cloudflare CAPTCHA page.
- The lure instructed users to press Windows+R, paste a PowerShell command, and press Enter.
- Helpjuice reportedly switched its status site to read-only mode after identifying a security incident. ๐ Coverage: reddit.com ยท ๐ via r/cybersecurity
๐ CVEs & KEV
- CVE-2026-26035 โ CVSS 9.8 โ FortiWeb Critical Improper Authentication Bypass (CVE-2026-26035)
- CVE-2026-50561 โ CVSS 9.4 โ Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator ...
- CVE-2026-67285 โ CVSS 9.2 โ Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file ...
- CVE-2026-47231 โ CVSS 8.1 โ Admidio has IDOR in
documents-files.phpmode=move_savethat lets any fold... - CVE-2026-49349 โ CVSS 6.8 โ regclient may leak authentication credentials to external blob storesregclien...
- CVE-2026-47233 โ CVSS 6.5 โ Admidio: Any logged-in user can delete inventory fields via `mode=field_delet...
- CVE-2026-47230 โ CVSS 6.5 โ Admidio: IDOR in documents-files.php allows cross-folder file rename and desc...
- CVE-2026-47227 โ CVSS 6.5 โ Admidio module-administrator can delete or reorder categories owned by other ...
- CVE-2026-47226 โ CVSS 6.5 โ Admidio: Authorization bypass in file_delete enables cross-folder file remova...
- CVE-2026-67287 โ CVSS 6.3 โ Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Pa...
- CVE-2026-67286 โ CVSS 6.3 โ Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creat...
- CVE-2026-73374 โ CVSS 6.1 โ Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnera...
๐ต๏ธ RESEARCH & DEEP DIVES
- Nightmare Eclipse releases ShieldBreak Windows Defender zero-day PoC
Nightmare Eclipse released a PoC for a Windows Defender zero-day that allegedly grants SYSTEM privileges.
- Windows 10, Windows 11, and Windows Server systems with Microsoft Defender are affected.
- ShieldBreak allegedly bypasses Microsoft's fix for the RoguePlanet