Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

Cyber Security

Vulnerabilities, threats and incidents, security advisories from CERT-EU, ENISA, CISA and NCSC, AI security and regulation (NIS2, CRA).

#RCE — 2 articles ✕

Critical RCE Vulnerabilities Found in Check Point VPN Gateways

On 9 September 2026, Check Point released emergency hotfixes for two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103), both with CVSS 9.8, affecting Security Gateway, Security Management Server, and Spark Firewall deployments using Remote Access VPN or Site-to-Site VPN. Both flaws allow unauthenticated remote attackers to execute arbitrary code on affected appliances. CERT-EU urges immediate patching, prioritising internet-facing and perimeter devices.

CERT-EU

Critical Citrix NetScaler Vulnerabilities Actively Exploited

Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.

CERT-EU