Security news

Relevant vulnerabilities selected by criticality, active exploitation and how widely the affected technology is used, written automatically from NVD, CISA KEV and vendor advisory data. RSS

AlertCritical

Canonical fixes three critical LXD flaws that allow full host compromise

Three critical vulnerabilities (CVSS 9.6-9.9) in the LXD daemon let an authenticated user with instance-creation rights write, delete or replace files anywhere on the host as root. Fixed releases are available: 4.0.14, 5.0.10, 5.21.8 and 6.10.

Canonical LXDBtrfsLinux3 CVEs
AlertCritical

CISA confirms active exploitation of two critical Citrix NetScaler ADC and Gateway flaws

Citrix has issued security bulletin CTX697096 covering three critical vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them (CVE-2026-88771 and CVE-2026-88772) are already being exploited, and CISA set 30 September 2026 as the remediation deadline for US federal agencies.

Citrix NetScaler ADCCitrix NetScaler Gateway3 CVEs