Relevant vulnerabilities selected by criticality, active exploitation and how widely the affected technology is used, written automatically from NVD, CISA KEV and vendor advisory data. RSS
CVE-2026-86950 allows arbitrary code execution when a maliciously crafted file is processed. Apple acknowledges it may have been used in an extremely sophisticated attack against specific individuals, and CISA has added it to its known exploited vulnerabilities catalogue.
Apple iOSApple iPadOSApple macOSApple iPhoneApple iPadCVE-2026-86950
CVE-2026-12342, rated 9.6 out of 10 on the CVSS scale, affects all versions of SailPoint IdentityIQ and lets an attacker run code on the server without credentials. Any organisation using IdentityIQ for identity governance is potentially exposed.
Three critical vulnerabilities (CVSS 9.6-9.9) in the LXD daemon let an authenticated user with instance-creation rights write, delete or replace files anywhere on the host as root. Fixed releases are available: 4.0.14, 5.0.10, 5.21.8 and 6.10.
Google has published two security bulletins detailing critical vulnerabilities CVE-2026-19759 and CVE-2026-81867 in Cloud Application Integration. Both allowed authenticated users to run code or privileged internal calls, and both were already fixed on the platform in June 2026.
Google Cloud Application IntegrationGoogle Cloud Platform2 CVEs
Citrix has issued security bulletin CTX697096 covering three critical vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them (CVE-2026-88771 and CVE-2026-88772) are already being exploited, and CISA set 30 September 2026 as the remediation deadline for US federal agencies.