
Windows IKE RCE Exploited - CVE-2026-65xxx in the Wild
CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.
Posts

CVE-2026-65xxx Windows IKE Extension RCE now exploited; Cl0p names 40+ Windchill victims; DOJ charges 17 Iranian Mabna Institute hackers.

CVE-2026-19478 GitLab GraphQL RCE hits CI/CD pipelines. Windows Task Host exploited by ransomware. City Forum scrapes 3.6M Azure records.

CVE-2026-59310 vCenter RCE exploited by China-nexus APT for Babuk ransomware. Plus Clop claims GE and Philips, SAP Commerce Cloud hit in 3 days.

White House authorizes private hack-back ops against cybercrime gangs. GeoServer zero-day exploited with no patch. Shell loses 89GB to Clop exfiltration.

CVE-2026-20349 crashes Cisco firewalls via unauthenticated HTTP. SharePoint CVE-2026-55040 exploited hours after PoC. Fortinet auth bypass patched.

CVE-2026-20349 crashes Cisco firewalls remotely. Microsoft patches 398 flaws with one exploited zero-day. VMware vCenter CVSS 9.8 RCE now in the wild.

CISA adds Progress LoadMaster and SonicWall SMA1000 CVSS 10 to KEV; FBI warns of Gunra ransomware hitting FortiOS and Schneider Electric flaws.

Progress LoadMaster CVSS 10 RCE added to CISA KEV with active exploitation. Iranian actors pivot through private APN to hit Polish energy.

NatJack attacks manipulate NAT state to hijack TCP sessions and spoof DNS. Plus Linux SCTP root exploit since 2008 and three Cisco SD-WAN CVSS 9.9 patches.

Cisco patches 24 critical flaws across SD-WAN, IOS XE, and FMC with one public PoC. CVE-2026-63077 TeamCity RCE hits CISA KEV. Oracle DB fileless pivot.