THE CONNECTMYASSETS JOURNAL

Security

News, analysis and practical guides for the people who operate, secure and lead infrastructure teams.

Backups, security, compliance, network operations…
READ. UNDERSTAND. APPLY.

Security

26 articlesClear filters
Security

Critical Check Point Management Flaw Allows Root Code Execution

A critical vulnerability in Check Point Security Management and Log Servers could let an unauthenticated network attacker execute code as root. Because the management server controls firewall policy and administrator access, organizations should apply the LivePatch fix and verify every potentially exposed system.

Read article
Security

Check Point Management-Server RCE: What to Track

CERT-FR has reported a vulnerability in Check Point products that can allow remote arbitrary code execution. Administrators should identify affected management assets, apply the required vendor updates, and search SmartConsole logs for the login-failure pattern highlighted in the advisory.

Read article
Security

Cisco ISE Zero-Day Under Active Attack

Cisco has disclosed a maximum-severity authentication-bypass vulnerability in ISE that is already being exploited. Network teams should identify affected systems, follow Cisco’s remediation guidance, and document patch or mitigation status across their network-access infrastructure.

Read article
Security

Actively Exploited Cisco ISE Flaw Requires Urgent Patching

Cisco has patched CVE-2026-76460, an actively exploited authentication-bypass vulnerability in Cisco ISE and ISE-PIC. The flaw allows unauthenticated attackers to gain root privileges, making rapid asset identification, patching, and compromise checks essential.

Read article
Security

CISA KEV Additions Put Cisco and Fortinet Patching First

CISA added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities catalog. The additions give network teams a clear reason to identify affected Cisco and Fortinet devices, prioritize patching, and verify remediation against current asset and firmware records.

Read article
Security

F5 NGINX Vulnerability: Track Exposure and Remediation

CERT-FR has published an advisory concerning a vulnerability in F5 NGINX. According to the advisory, a remote attacker could exploit it to cause a denial of service and affect data integrity. Infrastructure teams should identify relevant assets, assess exposure, and coordinate remediation or compensating controls.

Read article
Security

Check Point Patches Two Critical VPN Certificate Flaws

Check Point has patched two critical, 9.8-rated vulnerabilities in how its firewall and management products handle VPN certificates. Both flaws could enable unauthenticated remote code execution under specific, undisclosed conditions, making accurate gateway inventory and patch prioritization essential.

Read article
Security

CERT-FR Warns of Multiple HPE Aruba Networking Vulnerabilities

CERT-FR has reported multiple vulnerabilities affecting HPE Aruba Networking products. The potential impacts include remote arbitrary code execution, privilege escalation, and remote denial of service, making accurate device and firmware inventories essential for remediation.

Read article
Security

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco says attackers are actively exploiting two recently patched Secure Firewall Management Center vulnerabilities in campaigns involving credential theft, Qilin ransomware, and state-sponsored activity. Accurate asset inventory, software tracking, and structured remediation workflows are critical to identifying exposed systems and reducing risk.

Read article
Security

Cisco Product Vulnerabilities Raise RCE, DoS and SQLi Risks

CERT-FR has reported multiple vulnerabilities affecting Cisco products, with potential impacts including remote arbitrary code execution, remote denial of service and SQL injection. Network teams should identify affected infrastructure, verify exposure and document remediation through controlled patching and compliance workflows.

Read article
Security

Fortinet Advisory Highlights Multiple Product Vulnerabilities

CERT-FR has disclosed multiple vulnerabilities affecting Fortinet products, with potential impacts including remote arbitrary code execution, privilege escalation, and remote denial of service. Network teams should use the advisory to identify exposed appliances, prioritize updates, and retain evidence of remediation.

Read article
Security

CISA Adds Five Actively Exploited Flaws, Including RouterOS

CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its KEV catalog. The RouterOS entry makes accurate network inventory and asset-level vulnerability tracking especially important for remediation teams.

Read article
Security

Palo Alto Networks Vulnerabilities: From Advisory to Remediation Evidence

CERT-FR has reported multiple vulnerabilities in Palo Alto Networks products, including flaws that can enable remote arbitrary code execution, remote denial of service, and cross-site scripting. Network teams should translate the advisory into an asset-level response that identifies affected devices, prioritizes remediation, and preserves evidence of completed work.

Read article
Security

Cisco Fixes Seven IOS XR Vulnerabilities, Two Critical

Cisco has released software updates for seven internally discovered vulnerabilities affecting IOS XR, including two critical flaws rated 9.8. Every IOS XR release is affected regardless of configuration, and no workarounds are available. Network teams should identify exposed routers, prioritize updates, and retain evidence of each remediation step.

Read article
Security

MikroTrick RouterOS Exploit Chain: Patch and Lock Down SSH

MikroTik has patched six RouterOS vulnerabilities after attackers began exploiting a two-flaw SSH chain known as MikroTrick. Organizations should update affected routers, remove public management exposure, inspect devices for compromise, and treat missing warning indicators cautiously.

Read article
Security

Cisco Secure Email Gateway Flaw Exploited in the Wild

Cisco warns that a critical AsyncOS vulnerability affecting Secure Email Gateway appliances is being actively exploited. The flaw can let an unauthenticated remote attacker execute commands with root privileges, making rapid exposure checks and controlled patching essential.

Read article
Security

ClearPass Policy Manager Vulnerabilities Require Prompt Review

CERT-FR reports multiple vulnerabilities in HPE Aruba Networking ClearPass Policy Manager. The possible impacts include remote arbitrary code execution, privilege escalation, and remote denial of service, making accurate infrastructure inventory and structured remediation essential.

Read article
Security

Cisco Secure Email Gateway Zero-Day Demands Rapid Action

Cisco has released emergency fixes for an actively exploited Secure Email Gateway vulnerability that can give unauthenticated attackers root-level command execution. Because attackers may alter appliance logs after compromise, organizations must combine firmware remediation with external exposure checks and forensic investigation.

Read article

18 articles shown out of 26

Load more articles
FROM READING TO ACTION

What about your infrastructure?

Explore how ConnectMyAssets addresses these challenges.