Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

Cyber Security

Vulnerabilities, threats and incidents, security advisories from CERT-EU, ENISA, CISA and NCSC, AI security and regulation (NIS2, CRA).

“Pataisa” — 2 articles ✕

Cyber Security· Important

CISA Flags Two Actively Exploited Zammad Vulnerabilities

CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. CVE-2026-102489 is a session fixation flaw and CVE-2026-102490 involves improper privilege management in the Zammad helpdesk/customer service platform. Federal agencies must remediate under Binding Operational Directive 26-04, and CISA urges all organizations to prioritize these fixes.

CISA Advisories

CERT-EU warns of actively exploited critical SharePoint RCE flaws

CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.

CERT-EU