2026-09-07 — Kritieke RCE in voorbeeldproduct 2026-09-07 — Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway 2026-09-07 — Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts 2026-09-07 — Kwetsbaarheid verholpen in N-central van N-able 2026-09-07 — Hackers exploit new MikroTik RouterOS flaws to hijack routers 2026-09-07 — ConnectWise warns of new ScreenConnect flaw without patch 2026-09-07 — N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw 2026-09-07 — JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies 2026-09-07 — N-able patches max severity N-central flaw amid ongoing attacks 2026-09-06 — A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-06 — commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. 2026-09-06 — A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. 2026-09-06 — league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service. 2026-09-06 — A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. 2026-09-06 — A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-07 — Kritieke RCE in voorbeeldproduct 2026-09-07 — Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway 2026-09-07 — Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts 2026-09-07 — Kwetsbaarheid verholpen in N-central van N-able 2026-09-07 — Hackers exploit new MikroTik RouterOS flaws to hijack routers 2026-09-07 — ConnectWise warns of new ScreenConnect flaw without patch 2026-09-07 — N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw 2026-09-07 — JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies 2026-09-07 — N-able patches max severity N-central flaw amid ongoing attacks 2026-09-06 — A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-06 — commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. 2026-09-06 — A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. 2026-09-06 — league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service. 2026-09-06 — A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. 2026-09-06 — A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

Perceptive modernizes SOCs for tomorrow's world.

Perceptive Security provides specialized cybersecurity consultancy and services for Security Operations Centers. Perceptive strengthens SOC capabilities by implementing modern SIEM solutions, complemented with XDR, SOAR and AI technology. This enables early threat detection and more efficient incident response using the latest technologies.

FREE Cyber Security Early Warning Service
SIEM
Perceptive Security designs and implements advanced SIEM solutions, connects all your log sources, and integrates seamlessly with external systems to give a SOC fast, efficient and future-proof security monitoring.
EDR/XDR
Traditional log sources offer insufficient visibility into advanced threats, making XDR technology essential. Perceptive helps organizations implement and fine-tune XDR solutions for faster detection and more effective response.
SOAR
SOAR takes repetitive incident-response tasks off analysts' hands, so they can focus on what really matters. Perceptive helps with implementation and automation, making your SOC faster, smarter and more effective.
Threat Intel
By integrating threat intelligence platforms with SIEM and SOAR tools, SOC teams gain actionable insight into emerging attack techniques, threat-actor behavior and vulnerabilities.
Detection Engineering
Our team can optimize threat detection so cyberattacks are discovered as quickly as possible. We can help with gap analyses of an environment and write additional detection logic to minimize risk.
AI / ML
By connecting AI to SIEM and SOAR platforms we automate routine analysis, enrich alerts with deeper context, and let analysts spot threat patterns far faster.

email: info@perceptivesecurity.com
or call -