VulnerabilitiesKiteworks Reopens Customer Systems After Emergency Fix for Critical, Undisclosed Flaw
Kiteworks restored hosted systems after fixing a critical undisclosed flaw, lifting its global shutdown with no evidence of exploitation.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesKiteworks restored hosted systems after fixing a critical undisclosed flaw, lifting its global shutdown with no evidence of exploitation.
VulnerabilitiesBitget says attacker exploited zero-day in security tool, stole credentials and drained $388M from hot wallets via legit approvals; cold wallets safe.
VulnerabilitiesApple patched CVE-2026-86950, a CoreGraphics out-of-bounds flaw enabling code execution in targeted iPhone attacks. Update iOS 26.7.1 and macOS now.
VulnerabilitiesCISA's 2026 election plan secures voter databases, IT networks, patching and insider risks across 10,000+ US jurisdictions.
VulnerabilitiesCitrix patched CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) in NetScaler ADC/Gateway after active exploitation. Learn affected versions and fixed builds.
VulnerabilitiesWatchTowr reports two unpatched NetScaler ADC RCE flaws with no CVE, patch, or IoCs. Learn risks, affected versions, and guidance for operators.
VulnerabilitiesUNC6240 exploits CVE-2026-35273 in Oracle PeopleSoft via encoded PSEMHUB requests, bypassing WAFs to deploy JSP shells and SIDEEYE backdoor.
VulnerabilitiesKiteworks urged customers to shut down servers for six hours on Sept. 26 after law enforcement warned of a possible imminent attack. No breach confirmed.
VulnerabilitiesElementor 4.3.0-4.3.1 CSRF flaw lets attackers hijack admin sessions with one click to create rogue admins. Update to 4.3.2 immediately.
VulnerabilitiesAttackers exploit CVE-2026-48842, a pre-auth Roundcube SQL injection. Learn affected versions 1.6.x, 1.7.x and how to patch now.
VulnerabilitiesCISA added CVE-2026-5430 (WSO2) and CVE-2026-71362 (Adobe Commerce) to KEV with Sept 27 patch deadline amid active exploitation.
VulnerabilitiesCVE-2026-34223 lets malicious Desigo CC graphics execute scripts, write files to clients, risking workstation compromise and lateral movement.