Overview
- WatchGuard
- WatchGuard AP
28 Sep 2026
Published
28 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.27%
KEV
Description
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Statistics
- 1 Post
Last activity: Last hour
Fediverse
📰 Citrix Zero-Days and Oracle PeopleSoft Flaw Under Active Exploit
🚨 CRITICAL THREAT: Two Citrix zero-days (CVE-2026-88771, CVE-2026-88772) and an Oracle PeopleSoft flaw (CVE-2026-35273) are under active exploitation for RCE. CISA KEV updated. Patch immediately! #CyberSecurity #ZeroDay #CVE #PatchNow
Overview
- WatchGuard
- WatchGuard AP
28 Sep 2026
Published
28 Sep 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
1.82%
KEV
Description
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
Statistics
- 1 Post
Last activity: 19 hours ago