CVE Spotlight
Critical vulnerabilities and zero-days affecting Australian businesses
Last updated: August 2026
SonicWall SonicOS Improper Access Control
An improper access control vulnerability in the SonicWall SonicOS management access and SSLVPN allows unauthorized resource access and may cause the firewall to crash. Actively exploited in the wild.
Impact
Unauthorized access to management interface and SSLVPN, potential firewall crash leading to network exposure. Confirmed active exploitation against multiple organizations.
Mitigation
Update to latest SonicOS firmware immediately. Restrict management access to trusted sources. Enable MFA on all SSLVPN accounts. Source: NVD.
Windows TCP/IP Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the Windows TCP/IP stack when processing specially crafted IPv6 packets. An unauthenticated attacker could exploit this by sending malicious packets to a target system.
Impact
Unauthenticated remote code execution via network. No user interaction required. All Windows systems with IPv6 enabled are potentially vulnerable.
Mitigation
Apply August 2024 Patch Tuesday updates immediately. As interim mitigation, disable IPv6 if not required. Source: NVD.
Palo Alto Networks PAN-OS Command Injection Vulnerability
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software enables an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
Impact
Unauthenticated remote code execution with root privileges. Actively exploited as a zero-day. Complete compromise of affected firewalls.
Mitigation
Apply PAN-OS hotfixes immediately. Enable Threat Prevention signatures. If unable to patch, disable GlobalProtect gateway or apply workarounds per vendor advisory. Source: NVD.
OpenSSH Remote Code Execution (regreSSHion)
A signal handler race condition in OpenSSH server (sshd) on glibc-based Linux systems allows unauthenticated remote code execution as root. This is a regression of CVE-2006-5051.
Impact
Unauthenticated remote code execution as root on affected Linux systems. Millions of internet-facing SSH servers potentially vulnerable.
Mitigation
Update OpenSSH to version 9.8p1 or later. Set LoginGraceTime to 0 as interim mitigation (note: this enables DoS). Limit SSH access via firewall rules. Source: NVD.
Fortinet FortiOS Out-of-Bounds Write
An out-of-bounds write vulnerability in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted HTTP requests. Confirmed active exploitation.
Impact
Unauthenticated remote code execution on FortiGate firewalls. Actively exploited in the wild by threat actors targeting enterprise networks.
Mitigation
Upgrade FortiOS to patched versions immediately. Disable SSL-VPN as workaround if patching is not immediately possible. Source: NVD.
Microsoft Outlook Remote Code Execution Vulnerability (Moniker Link)
A remote code execution vulnerability in Microsoft Outlook allows attackers to bypass Office Protected View via a crafted moniker link, enabling code execution when a user clicks a malicious link in an email.
Impact
Remote code execution bypassing Protected View. Attacker gains code execution in context of the user. NTLM credential theft also possible.
Mitigation
Apply February 2024 Patch Tuesday updates. Ensure Protected View and Application Guard are enabled. Educate users about suspicious links. Source: NVD.
PHP CGI Argument Injection Vulnerability
An argument injection vulnerability in PHP CGI on Windows systems allows unauthenticated attackers to execute arbitrary code. The flaw exists in how PHP handles character encoding conversions, bypassing CVE-2012-1823 protections.
Impact
Unauthenticated remote code execution on Windows systems running PHP in CGI mode. Actively exploited within 48 hours of disclosure.
Mitigation
Update PHP to patched versions (8.3.8, 8.2.20, 8.1.29). Migrate from CGI to FastCGI/PHP-FPM. Apply web server rewrite rules as interim mitigation. Source: NVD.
JetBrains TeamCity Authentication Bypass
An authentication bypass vulnerability in JetBrains TeamCity allows an unauthenticated attacker to gain administrative control of the TeamCity server via a crafted request to specific API endpoints.
Impact
Complete administrative access to TeamCity server. Enables supply chain attacks through CI/CD pipeline compromise, source code theft, and credential harvesting.
Mitigation
Update TeamCity to version 2023.11.4 or later immediately. Restrict network access to TeamCity server. Audit for unauthorized admin accounts. Source: NVD.
VMware ESXi Authentication Bypass
An authentication bypass vulnerability in VMware ESXi allows a malicious actor with sufficient Active Directory permissions to gain full access to an ESXi host by re-creating a previously deleted AD group.
Impact
Full administrative access to ESXi hosts joined to Active Directory. Used by ransomware operators to encrypt virtual machine disk files.
Mitigation
Apply VMware patches. Audit AD group memberships. Consider removing ESXi hosts from Active Directory domains. Monitor for unauthorized access. Source: NVD.
Citrix NetScaler Information Disclosure (Citrix Bleed)
A sensitive information disclosure vulnerability in Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to extract session tokens from device memory, enabling session hijacking.
Impact
Session token theft enabling authenticated session hijacking. Bypasses MFA. Actively exploited by LockBit ransomware affiliates and other threat actors.
Mitigation
Apply Citrix patches immediately. Kill all active and persistent sessions after patching. Rotate credentials. Monitor for unauthorized access. Source: NVD.
Apache ActiveMQ Remote Code Execution
Apache ActiveMQ is vulnerable to remote code execution due to unsafe deserialization in the OpenWire protocol. An attacker with network access to the broker can execute arbitrary shell commands.
Impact
Unauthenticated remote code execution. Actively exploited by ransomware groups and cryptominers. Complete system compromise possible.
Mitigation
Upgrade to ActiveMQ 5.15.16, 5.16.7, 5.17.6, or 5.18.3. Restrict network access to broker ports (61616). Apply environment hardening. Source: NVD.
HTTP/2 Rapid Reset Attack
The HTTP/2 protocol allows denial of service because request cancellation can reset many streams quickly. Exploited in the wild to launch record-breaking DDoS attacks exceeding 398 million requests per second.
Impact
Massive denial of service attacks against any HTTP/2 enabled web server. Record-breaking DDoS volumes observed across major cloud providers.
Mitigation
Update web servers, load balancers, and proxies to patched versions. Implement rate limiting on HTTP/2 stream resets. Configure DDoS protection. Source: NVD.
Progress MOVEit Transfer SQL Injection
A SQL injection vulnerability in Progress MOVEit Transfer web application allows unauthenticated attackers to access the database and execute arbitrary code. Exploited by CL0P ransomware gang in mass attacks.
Impact
Unauthenticated database access and remote code execution. CL0P ransomware gang exploited this to steal data from thousands of organizations worldwide.
Mitigation
Apply vendor patches immediately. Block HTTP/HTTPS traffic to MOVEit Transfer on ports 80/443 as interim measure. Review for indicators of compromise. Source: NVD.
Cisco IOS XE Web UI Privilege Escalation
A privilege escalation vulnerability in the web UI of Cisco IOS XE Software allows an unauthenticated remote attacker to create an account with privilege level 15 access, granting full control of the device.
Impact
Unauthenticated full device compromise. Over 40,000 devices found compromised in the wild. Enables persistent backdoor access to network infrastructure.
Mitigation
Disable the HTTP/HTTPS server feature on internet-facing systems. Apply Cisco patches. Check for unauthorized local accounts and implants. Source: NVD.
Fortinet FortiOS Heap Buffer Overflow
A heap-based buffer overflow vulnerability in FortiOS SSL-VPN pre-authentication allows a remote unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
Impact
Unauthenticated remote code execution on FortiGate devices. Pre-authentication exploitation means no credentials required. Actively exploited.
Mitigation
Upgrade FortiOS to patched versions. Disable SSL-VPN if not needed. Restrict VPN access to known IP ranges as interim measure. Source: NVD.
Microsoft Outlook Elevation of Privilege Vulnerability
An elevation of privilege vulnerability in Microsoft Outlook allows an attacker to steal NTLM credential hashes by sending a specially crafted email. No user interaction beyond receiving the email is required.
Impact
NTLM credential theft without user interaction. Exploited by Russian APT28 (Fancy Bear) against government and critical infrastructure targets. Enables lateral movement.
Mitigation
Apply March 2023 Patch Tuesday updates. Block outbound SMB (TCP 445) at the firewall. Add users to Protected Users security group. Disable NTLM where possible. Source: NVD.
CVE Resources and Tools
🔥 Active Threats
ACSC Critical Alert
Active exploitation of SonicWall SSL VPNs in Australia
CVE-2024-40766: Authentication bypass vulnerability being actively exploited by threat actors. Immediate patching required.
View Full Advisory →NIST National Vulnerability Database
Official US government repository of standards-based vulnerability management data
CVE Program
Community-driven effort to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities
ACSC Security Advisories
Australian Cyber Security Centre advisories and vulnerability alerts
CVSS Calculator
Common Vulnerability Scoring System for assessing vulnerability severity
Need Help Managing Vulnerabilities?
Staying on top of CVEs and security vulnerabilities requires expertise and dedicated resources. Partner with Australia's leading cybersecurity specialists for comprehensive vulnerability management.
Get Free Security Scan