watchTowr says two unpatched NetScaler RCE flaws are being exploited and Citrix has published no fix.
PaperCut Software confirmed active attacks on an unspecified vulnerability in its NG and MF print management products.
CISA added six actively exploited flaws to KEV, including a Citrix NetScaler bug now under attack in the wild.
Poland's CERT warns attackers are exploiting a patched Zimbra command-injection flaw in the wild.
CISA adds four actively exploited flaws covering macOS, SharePoint, vCenter, and Microsoft IKE to its urgent patch catalog.
SAP Commerce Cloud's CVSS 10 flaw is under attack just three days after the patch shipped.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
CISA adds actively exploited Cisco FMC static credentials flaw to its known vulnerabilities catalog.