<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CISO Intelligence — Kwetsbaarheden</title><description>Kwetsbaarheden met handelingsperspectief, elke twee uur ververst. Automatisch, niet redactioneel beoordeeld.</description><link>https://nieuws.aegiscore.nl/</link><language>nl</language><item><title>[Deze week] NCSC-2026-0399 [1.00] [M/H] Kwetsbaarheid verholpen in Citrix NetScaler ADC en NetScaler Gateway</title><link>https://advisories.ncsc.nl/advisory?id=NCSC-2026-0399</link><guid isPermaLink="true">https://advisories.ncsc.nl/advisory?id=NCSC-2026-0399</guid><description>Bron: NCSC-NL (Prioriteit 1).

Citrix heeft een kwetsbaarheid verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid betreft een geheugenoverflow in versies van NetScaler ADC en NetScaler Gateway die ouder zijn dan 14.1-73.41 en 13.1-64.28. Deze kwetsbaarheid kan leiden tot een Denial of Service (DoS) waarbij de normale beschikbaarheid van de dienst wordt verstoord.

Handelingsperspectief: Deze week (deze week). Stel vast of het product in gebruik is. Plan de update deze week in, systemen die aan internet hangen eerst.

Gebaseerd op: NCSC-inschatting: kans middel, schade hoog.</description><pubDate>Sun, 04 Oct 2026 11:19:06 GMT</pubDate><category>Deze week</category></item><item><title>[Reguliere patchcyclus] Fortra Patches Critical Vulnerabilities in BoKS</title><link>https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/</link><guid isPermaLink="true">https://www.securityweek.com/fortra-patches-critical-vulnerabilities-in-boks/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Sat, 03 Oct 2026 11:34:00 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Cisco IOS XE Software Security Hardening Release: August 2026</title><link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Security%20Hardening%20Release:%20August%202026%26vs_k=1</link><guid isPermaLink="true">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Security%20Hardening%20Release:%20August%202026%26vs_k=1</guid><description>Bron: Cisco PSIRT (Prioriteit 1).

&lt;p&gt;As part of Cisco&apos;s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.&amp;nbsp; &amp;nbsp;&lt;/p&gt; &lt;p&gt;These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class &amp;mdash; Common Weakness Enumeration (CWE)

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day. Leverancier beoordeelt de ernst als kritiek.</description><pubDate>Fri, 02 Oct 2026 19:21:28 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-20267</category><category>CVE-2026-20268</category><category>CVE-2026-20269</category><category>CVE-2026-20270</category><category>CVE-2026-20271</category><category>CVE-2026-20272</category><category>CVE-2026-20273</category></item><item><title>[Direct handelen] Kiteworks &amp; Citrix Incidents Show Challenges of Zero-Day Response</title><link>https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/kiteworks-citrix-incidents-challenges-zero-day-response</guid><description>Bron: Dark Reading (Prioriteit 2).

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Fri, 02 Oct 2026 16:56:30 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] GitLab warns of critical RCE vulnerability in AI Gateway service</title><link>https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/</guid><description>Bron: BleepingComputer (Prioriteit 2).

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 16:20:05 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Vulnerability Backlogs Are an Ownership Problem</title><link>https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem</link><guid isPermaLink="true">https://www.darkreading.com/cybersecurity-operations/vulnerability-backlogs-ownership-problem</guid><description>Bron: Dark Reading (Prioriteit 2).

Organizations don&apos;t need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 14:00:00 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability</title><link>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940</link><guid isPermaLink="true">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940</guid><description>Bron: Microsoft Security Response Center (MSRC) (Prioriteit 1).

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 14:00:00 GMT</pubDate><category>Reguliere patchcyclus</category><category>CVE-2026-96940</category></item><item><title>[Reguliere patchcyclus] Dell asks admins to patch max severity CSM flaws as soon as possible</title><link>https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 12:37:40 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Kwetsbaarheid melden</title><link>https://www.rijksoverheid.nl/service/kwetsbaarheid-melden</link><guid isPermaLink="true">https://www.rijksoverheid.nl/service/kwetsbaarheid-melden</guid><description>Bron: Rijksoverheid (Prioriteit 1).

Ziet u een zwakke plek of kwetsbaarheid op deze website? Meld dit dan bij het Nationaal Cyber Security Centrum (NCSC).

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 12:18:41 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Actief misbruikt: Zammad GmbH Zammad (CVE-2026-102490)</title><link>https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102490</link><guid isPermaLink="true">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102490</guid><description>Bron: CISA (Prioriteit 1).

Zammad GmbH Zammad Improper Privilege Management Vulnerability. Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-102490 (Zammad GmbH Zammad), toegevoegd 2 okt 2026, CISA-deadline voor Amerikaanse overheidsinstanties 5 okt 2026.</description><pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-102490</category></item><item><title>[Direct handelen] Actief misbruikt: Zammad GmbH Zammad (CVE-2026-102489)</title><link>https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102489</link><guid isPermaLink="true">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-102489</guid><description>Bron: CISA (Prioriteit 1).

Zammad GmbH Zammad Session Fixation Vulnerability. Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-102489 (Zammad GmbH Zammad), toegevoegd 2 okt 2026, CISA-deadline voor Amerikaanse overheidsinstanties 5 okt 2026.</description><pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-102489</category></item><item><title>[Reguliere patchcyclus] CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM)</title><link>https://security.paloaltonetworks.com/CVE-2026-0250</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0250</guid><description>Bron: Palo Alto Networks security advisories (Prioriteit 1).

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 08:15:00 GMT</pubDate><category>Reguliere patchcyclus</category><category>CVE-2026-0250</category></item><item><title>[Reguliere patchcyclus] Stable Channel Update for Desktop</title><link>http://chromereleases.googleblog.com/feeds/6766445691312943866/comments/default</link><guid isPermaLink="true">http://chromereleases.googleblog.com/feeds/6766445691312943866/comments/default</guid><description>Bron: Google Chrome Releases (Prioriteit 1).

&lt;p&gt;&lt;span face=&quot;Roboto, sans-serif&quot; style=&quot;color: #666666;&quot;&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;The Stable channel has been updated to 154.0.8037.97/.98 for Windows and&lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt; &lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;Mac and &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #666666; font-family: arial;&quot;&gt;154.0.8037.97 to &lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;color: #666666;&quot;&gt;Linux which will roll out over the coming days/weeks. A full list of changes in 

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Fri, 02 Oct 2026 01:04:35 GMT</pubDate><category>Reguliere patchcyclus</category><category>CVE-2026-103628</category><category>CVE-2026-103626</category><category>CVE-2026-103621</category><category>CVE-2026-103630</category><category>CVE-2026-103625</category><category>CVE-2026-103624</category><category>CVE-2026-103629</category><category>CVE-2026-103622</category><category>CVE-2026-103623</category><category>CVE-2026-103631</category><category>CVE-2026-103627</category></item><item><title>[Deze week] GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1</title><link>https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/</link><guid isPermaLink="true">https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/</guid><description>Bron: GitLab security releases (Prioriteit 1).

We have released versions 19.2.4, 19.3.2, and 19.4.1 of the GitLab AI Gateway. These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately. We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance. A fix has already been deployed for GitLab-hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances using a GitLab-hos

Handelingsperspectief: Deze week (deze week). Stel vast of het product in gebruik is. Plan de update deze week in, systemen die aan internet hangen eerst.

Gebaseerd op: Leverancier beoordeelt de ernst als kritiek.</description><pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate><category>Deze week</category><category>CVE-2026-90970</category></item><item><title>[Reguliere patchcyclus] Kiteworks patches max severity code injection vulnerability</title><link>https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Thu, 01 Oct 2026 13:51:08 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit</title><link>https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/divd-agentic-ai-attack-breach/</guid><description>Bron: Help Net Security (Prioriteit 2).

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. “Used together, [the two flaws] allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds, due to the agentic part of this hack. From there they were able to access other services and read and … More → The post AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit appeared first o

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Thu, 01 Oct 2026 13:13:14 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] Legit Security extends automated fixes to vulnerable open-source dependencies</title><link>https://www.helpnetsecurity.com/2026/10/01/legit-security-agentic-remediation-expansion/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/legit-security-agentic-remediation-expansion/</guid><description>Bron: Help Net Security (Prioriteit 2).

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage. The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases are made up largely of open-source dependencies, and every new package introduces potential exposure to known vulnerabilities. Traditional find-it, fix-it … More → The post Legit Security ext

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Thu, 01 Oct 2026 13:04:31 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure</title><link>https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/</link><guid isPermaLink="true">https://www.securityweek.com/zimbra-vulnerability-exploited-in-the-wild-prior-to-public-disclosure/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure appeared first on SecurityWeek .

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-73570 (Synacor Zimbra Collaboration Suite (ZCS)), toegevoegd 21 aug 2026, CISA-deadline voor Amerikaanse overheidsinstanties 24 aug 2026.</description><pubDate>Thu, 01 Oct 2026 12:55:57 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-73570</category></item><item><title>[Direct handelen] Actief misbruikt: Fortinet FortiMail (CVE-2026-104286)</title><link>https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286</link><guid isPermaLink="true">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-104286</guid><description>Bron: CISA (Prioriteit 1).

Fortinet FortiMail Path Traversal Vulnerability. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-104286 (Fortinet FortiMail), toegevoegd 1 okt 2026, CISA-deadline voor Amerikaanse overheidsinstanties 4 okt 2026.</description><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-104286</category></item><item><title>[Direct handelen] Zammad Zero-Days Exploited in AI-Powered DIVD Hack</title><link>https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/</link><guid isPermaLink="true">https://www.securityweek.com/zammad-zero-days-exploited-in-ai-powered-divd-hack/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek .

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Thu, 01 Oct 2026 10:42:49 GMT</pubDate><category>Direct handelen</category></item><item><title>[Deze week] NCSC-2026-0397 [1.00] [M/H] Kwetsbaarheid verholpen in Apple CoreGraphics</title><link>https://advisories.ncsc.nl/advisory?id=NCSC-2026-0397</link><guid isPermaLink="true">https://advisories.ncsc.nl/advisory?id=NCSC-2026-0397</guid><description>Bron: NCSC-NL (Prioriteit 1).

Apple heeft een kwetsbaarheid verholpen in CoreGraphics op iOS, iPadOS en macOS. De kwetsbaarheid betreft een out-of-bounds write in de CoreGraphics component. Een aanvaller kan deze kwetsbaarheid misbruiken door speciaal vervaardigde bestanden te verwerken, wat kan leiden tot het uitvoeren van willekeurige code. Deze kwetsbaarheid is gebruikt in gerichte aanvallen op iOS-versies vóór iOS 27. De kwetsbaarheid komt voor in meerdere Apple besturingssystemen.

Handelingsperspectief: Deze week (deze week). Stel vast of het product in gebruik is. Plan de update deze week in, systemen die aan internet hangen eerst.

Gebaseerd op: NCSC-inschatting: kans middel, schade hoog.</description><pubDate>Thu, 01 Oct 2026 10:35:52 GMT</pubDate><category>Deze week</category></item><item><title>[Reguliere patchcyclus] Warning: Multiple Vulnerabilities Identified in WatchGuard Fireware OS, Including Remote Code Execution , Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-identified-watchguard-fireware-os-including-remote-code</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-identified-watchguard-fireware-os-including-remote-code</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Thu, 01 Oct 2026 08:55:52 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability</title><link>https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/</link><guid isPermaLink="true">https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek .

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Thu, 01 Oct 2026 08:26:03 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] Improper limitation of a pathname to a restricted directory</title><link>https://fortiguard.fortinet.com/psirt/FG-IR-26-175</link><guid isPermaLink="true">https://fortiguard.fortinet.com/psirt/FG-IR-26-175</guid><description>Bron: Fortinet PSIRT (Prioriteit 1).

CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory (&apos;Path Traversal&apos;) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-01 00:00:00

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day. CVSS 9,8 volgens de bron.</description><pubDate>Thu, 01 Oct 2026 07:00:00 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] The vulnerabilities AI finds are the ones attackers want</title><link>https://www.helpnetsecurity.com/2026/10/01/google-ai-discovered-vulnerabilities-remote-code-execution/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/google-ai-discovered-vulnerabilities-remote-code-execution/</guid><description>Bron: Help Net Security (Prioriteit 2).

Attackers exploited a flaw found by an AI research agent within four days of its public disclosure, and they are exploiting more vulnerabilities overall, according to new research by Google Threat Intelligence Group (GTIG). The researchers examined vulnerability disclosure and exploitation data from January 2025 to August 2026. Disclosures doubled, exploitation stays rare Monthly CVE disclosures doubled in 2026, from 5,045 in January to 10,740 in August. Only 0.23% of the vulnerabilities disclosed this year, … More → The post The vulnerabilities AI finds are the ones attackers want appeared fi

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Thu, 01 Oct 2026 05:00:35 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Google says Gemini 4 Argon can find and patch critical software flaws</title><link>https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/</guid><description>Bron: Help Net Security (Prioriteit 2).

Google announced Gemini 4 Argon, its new frontier AI model, and is rolling it out to a set of trusted cyber defenders through its Fairwind Program. Google says the model can locate critical software vulnerabilities, validate them, and patch them without human help, and it will release a version without cyber guardrails to those defenders and to its own internal teams. Developers, enterprises, and consumers get Argon later, starting with paid API customers and Google … More → The post Google says Gemini 4 Argon can find and patch critical software flaws appeared first on Help Net Security .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Thu, 01 Oct 2026 04:00:41 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] DIVD says Zammad zero-days enabled AI-driven network breach</title><link>https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Wed, 30 Sep 2026 19:49:15 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation</title><link>https://therecord.media/google-vulnerabilities-cyberattacks-ai</link><guid isPermaLink="true">https://therecord.media/google-vulnerabilities-cyberattacks-ai</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 19:00:00 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS</title><link>https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 15:49:29 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Deze week] NCSC-2026-0395 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager</title><link>https://advisories.ncsc.nl/advisory?id=NCSC-2026-0395</link><guid isPermaLink="true">https://advisories.ncsc.nl/advisory?id=NCSC-2026-0395</guid><description>Bron: NCSC-NL (Prioriteit 1).

Cisco heeft een kwetsbaarheid verholpen in Cisco Catalyst SD-WAN Manager. De kwetsbaarheid bevindt zich in een API van Cisco Catalyst SD-WAN Manager. Door onjuiste verwerking van URI-encoding kunnen ongeauthenticeerde kwaadwillenden authenticatiemechanismen omzeilen. Hierdoor kan de kwaadwillende administratieve toegang tot het systeem verkrijgen en de controle over het systeem overnemen.

Handelingsperspectief: Deze week (deze week). Stel vast of het product in gebruik is. Plan de update deze week in, systemen die aan internet hangen eerst.

Gebaseerd op: NCSC-inschatting: kans middel, schade hoog.</description><pubDate>Wed, 30 Sep 2026 14:43:36 GMT</pubDate><category>Deze week</category></item><item><title>[Reguliere patchcyclus] Google: AI vindt meer en gevaarlijkere kwetsbaarheden in software</title><link>https://www.security.nl/posting/955356/Google%3A+AI+vindt+meer+en+gevaarlijkere+kwetsbaarheden+in+software?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955356/Google%3A+AI+vindt+meer+en+gevaarlijkere+kwetsbaarheden+in+software?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Door het gebruik van AI worden veel meer kwetsbaarheden in software gevonden die ook nog eens veel gevaarlijker zijn, zo stelt ...

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 14:41:14 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Google: AI Is Changing the Pace and Profile of Vulnerability Discovery</title><link>https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/</link><guid isPermaLink="true">https://www.securityweek.com/google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 14:05:58 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570</title><link>https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/</link><guid isPermaLink="true">https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/</guid><description>Bron: Microsoft Security Blog (Prioriteit 1).

Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog .

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-73570 (Synacor Zimbra Collaboration Suite (ZCS)), toegevoegd 21 aug 2026, CISA-deadline voor Amerikaanse overheidsinstanties 24 aug 2026.</description><pubDate>Wed, 30 Sep 2026 14:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-73570</category></item><item><title>[Direct handelen] Vulnerability Discovery and Exploitation Trends in the AI Era</title><link>https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/</link><guid isPermaLink="true">https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/</guid><description>Bron: Google Threat Intelligence / Mandiant (Prioriteit 1).

&lt;div class=&quot;block-paragraph_advanced&quot;&gt;&lt;p&gt;&lt;span style=&quot;vertical-align: baseline;&quot;&gt;Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee&lt;/span&gt;&lt;/p&gt; &lt;hr/&gt; &lt;h3&gt;&lt;span style=&quot;vertical-align: baseline;&quot;&gt;Introduction&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;&lt;span style=&quot;vertical-align: baseline;&quot;&gt;Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typic

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt. Wordt gebruikt door ransomwaregroepen: controleer of offline back-ups en detectie op orde zijn.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-1731 (BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)), toegevoegd 13 feb 2026, CISA-deadline voor Amerikaanse overheidsinstanties 16 feb 2026. CISA KEV: misbruik bevestigd voor CVE-2026-42271 (BerriAI LiteLLM), toegevoegd 8 jun 2026, CISA-deadline voor Amerikaanse overheidsinstanties 22 jun 2026. CISA KEV: misbruik bevestigd voor CVE-2025-3248 (Langflow Langflow), toegevoegd 5 mei 2025, CISA-deadline voor Amerikaanse overheidsinstanties 26 mei 2025. CISA: bekend gebruikt in ransomwarecampagnes.</description><pubDate>Wed, 30 Sep 2026 14:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-1731</category><category>CVE-2026-42271</category><category>CVE-2026-5027</category><category>CVE-2025-3248</category></item><item><title>[Reguliere patchcyclus] OpenSSL dicht kwetsbaarheid waardoor heap memory kan lekken</title><link>https://www.security.nl/posting/955339/OpenSSL+dicht+kwetsbaarheid+waardoor+heap+memory+kan+lekken?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/955339/OpenSSL+dicht+kwetsbaarheid+waardoor+heap+memory+kan+lekken?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

De makers van OpenSSL hebben updates uitgebracht voor meerdere kwetsbaarheden in de software, waaronder een beveiligingslek ...

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 13:37:28 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] WatchGuard Patches Critical Fireware OS Code Injection Vulnerability</title><link>https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/</link><guid isPermaLink="true">https://www.securityweek.com/watchguard-patches-critical-fireware-os-code-injection-vulnerability/</guid><description>Bron: SecurityWeek (Prioriteit 2).

WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 13:16:56 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] TeamViewer urges users to patch severe flaws “as soon as possible”</title><link>https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 12:25:10 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Chrome, Firefox Updates Patch Over 100 Vulnerabilities</title><link>https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/</link><guid isPermaLink="true">https://www.securityweek.com/chrome-firefox-updates-patch-over-100-vulnerabilities/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 12:16:52 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Actief misbruikt: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)</title><link>https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-76504</link><guid isPermaLink="true">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-76504</guid><description>Bron: CISA (Prioriteit 1).

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-76504 (Cisco Catalyst SD-WAN Manager), toegevoegd 30 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 3 okt 2026.</description><pubDate>Wed, 30 Sep 2026 12:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-76504</category></item><item><title>[Direct handelen] Bitget hacked via zero-day in third-party security products</title><link>https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/bitget-hacked-via-zero-day-in-third-party-security-products/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Wed, 30 Sep 2026 11:11:46 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised</title><link>https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/openinfra-jfrog-artifactory-instance-compromised/</guid><description>Bron: Help Net Security (Prioriteit 2).

Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. OpenInfra Europe’s security incident notice “Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says. Compromise through CVE-2026-82329 The OpenInfra Foundation … More → The post OpenIn

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-82329 (JFrog Artifactory), toegevoegd 2 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 5 sep 2026.</description><pubDate>Wed, 30 Sep 2026 10:39:26 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-82329</category></item><item><title>[Reguliere patchcyclus] High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL</title><link>https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/</link><guid isPermaLink="true">https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl/</guid><description>Bron: SecurityWeek (Prioriteit 2).

Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 06:55:50 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)</title><link>https://security.paloaltonetworks.com/CVE-2026-0307</link><guid isPermaLink="true">https://security.paloaltonetworks.com/CVE-2026-0307</guid><description>Bron: Palo Alto Networks security advisories (Prioriteit 1).

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 06:15:00 GMT</pubDate><category>Reguliere patchcyclus</category><category>CVE-2026-0307</category></item><item><title>[Reguliere patchcyclus] Most open critical and high flaws are over 90 days old</title><link>https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/</guid><description>Bron: Help Net Security (Prioriteit 2).

Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems are months old. Of the critical and high-severity vulnerabilities open at the time of the snapshot, 97% in the Nordics had been exposed for more than 90 days, along with 92% in the UK and 86% in the US. Source: Detectify The organizations already know about … More → The post Most open critical and high flaws are over 90 days old appeared first on Help Net Security .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Wed, 30 Sep 2026 04:00:38 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution</title><link>https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution</link><guid isPermaLink="true">https://www.darkreading.com/application-security/unsloth-studio-flaw-model-inspection-code-execution</guid><description>Bron: Dark Reading (Prioriteit 2).

A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 21:08:42 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Stable Channel Update for Desktop</title><link>http://chromereleases.googleblog.com/feeds/850975213617995096/comments/default</link><guid isPermaLink="true">http://chromereleases.googleblog.com/feeds/850975213617995096/comments/default</guid><description>Bron: Google Chrome Releases (Prioriteit 1).

&lt;p&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span face=&quot;Roboto, sans-serif&quot; style=&quot;color: #666666;&quot;&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;The Stable channel has been updated to 154.0.8037.92/.93 for Windows and&lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt; &lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;Mac and &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;color: #666666; font-family: arial;&quot;&gt;154.0.8037.92 to &lt;/span&gt;&lt;span color=&quot;rgba(0, 0, 0, 0.87)&quot; style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;color: #666666;&quot;&gt;Linux which will roll out over the coming days/

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 18:38:51 GMT</pubDate><category>Reguliere patchcyclus</category><category>CVE-2026-102331</category><category>CVE-2026-102317</category><category>CVE-2026-102312</category><category>CVE-2026-102313</category><category>CVE-2026-102299</category><category>CVE-2026-102306</category><category>CVE-2026-102307</category><category>CVE-2026-102323</category><category>CVE-2026-102303</category><category>CVE-2026-102311</category><category>CVE-2026-102300</category><category>CVE-2026-102326</category><category>CVE-2026-102316</category><category>CVE-2026-102304</category><category>CVE-2026-102328</category><category>CVE-2026-102309</category><category>CVE-2026-102325</category><category>CVE-2026-102308</category><category>CVE-2026-102301</category><category>CVE-2026-102319</category><category>CVE-2026-102324</category><category>CVE-2026-102318</category><category>CVE-2026-102329</category><category>CVE-2026-102315</category><category>CVE-2026-102302</category><category>CVE-2026-102321</category><category>CVE-2026-102320</category><category>CVE-2026-102310</category><category>CVE-2026-102327</category><category>CVE-2026-102330</category><category>CVE-2026-102314</category><category>CVE-2026-102305</category></item><item><title>[Reguliere patchcyclus] Warning: Two critical vulnerabilities which can lead to Remote Code Execution in WatchGuard, Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-which-can-lead-remote-code-execution-watchguard</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-two-critical-vulnerabilities-which-can-lead-remote-code-execution-watchguard</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 18:20:00 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers</title><link>https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix</link><guid isPermaLink="true">https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix</guid><description>Bron: Dark Reading (Prioriteit 2).

The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers&apos; networks.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Tue, 29 Sep 2026 14:19:43 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances</title><link>https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances/</link><guid isPermaLink="true">https://cloud.google.com/blog/topics/threat-intelligence/defending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances/</guid><description>Bron: Google Threat Intelligence / Mandiant (Prioriteit 1).

&lt;div class=&quot;block-paragraph_advanced&quot;&gt;&lt;h3&gt;Introduction&lt;/h3&gt; &lt;p&gt;&lt;span style=&quot;vertical-align: baseline;&quot;&gt;In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has been ongoing s

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-88772 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026. CISA KEV: misbruik bevestigd voor CVE-2026-88771 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026.</description><pubDate>Tue, 29 Sep 2026 14:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-88772</category><category>CVE-2026-88771</category><category>CVE-2026-88778</category></item><item><title>[Direct handelen] Actief misbruikt: Apple Multiple Products (CVE-2026-86950)</title><link>https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-86950</link><guid isPermaLink="true">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-86950</guid><description>Bron: CISA (Prioriteit 1).

Apple Multiple Products Out-of-Bounds Write Vulnerability. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-86950 (Apple Multiple Products), toegevoegd 29 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 2 okt 2026.</description><pubDate>Tue, 29 Sep 2026 12:00:00 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-86950</category></item><item><title>[Reguliere patchcyclus] Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider</title><link>https://www.helpnetsecurity.com/2026/09/29/qbusoft-medyc-data-breach-poland/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/29/qbusoft-medyc-data-breach-poland/</guid><description>Bron: Help Net Security (Prioriteit 2).

Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. The data comes from Medyc, a platform the company sells to medical offices and clinics to manage patient registration, records and prescriptions. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. The … More → The post Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider appear

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 09:17:43 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Kiteworks patches critical flaw, brings customer systems online</title><link>https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/kiteworks-lifts-shutdown-warning-after-patching-critical-flaw/</guid><description>Bron: BleepingComputer (Prioriteit 2).

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 09:04:06 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Apple patches CoreGraphics zero-day flaw exploited in attacks</title><link>https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Apple released security updates to fix a zero-day vulnerability exploited in &quot;extremely sophisticated&quot; targeted attacks on iOS devices. [...]

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Tue, 29 Sep 2026 07:33:12 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] GitHub’s AI agent found 24 Android app vulnerabilities</title><link>https://www.helpnetsecurity.com/2026/09/29/github-ai-android-app-vulnerabilities/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/29/github-ai-android-app-vulnerabilities/</guid><description>Bron: Help Net Security (Prioriteit 2).

GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps. Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal … More → The post GitHub’s AI agent found 24 Android app vulnerabilities appeared first on Help Net Security .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Tue, 29 Sep 2026 06:39:42 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] US, UK warn of exploited Citrix NetScaler zero-day bugs</title><link>https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug</link><guid isPermaLink="true">https://therecord.media/us-uk-warn-of-citrix-netscaler-zero-day-bug</guid><description>Bron: The Record (Recorded Future News) (Prioriteit 2).

Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Mon, 28 Sep 2026 16:19:00 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] Warning: Critical vulnerabilities in Mikrotik RouterOS, Patch immediately!</title><link>https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-mikrotik-routeros-patch-immediately</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-mikrotik-routeros-patch-immediately</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 14:44:33 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Warning: Cross-site Scripting vulnerabilities in Zimbra, Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-cross-site-scripting-vulnerabilities-zimbra-patch-immediately</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-cross-site-scripting-vulnerabilities-zimbra-patch-immediately</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 14:04:11 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day</title><link>https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/</link><guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/</guid><description>Bron: Help Net Security (Prioriteit 2).

The FBI’s online portals for job applicants (at apply.fbijobs.gov) and special agent applicants (at fbijobs.gov/special-agents) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group. Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees. ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals. They … More → The p

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Mon, 28 Sep 2026 13:56:45 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway</title><link>https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway</link><guid isPermaLink="true">https://www.ncsc.gov.uk/news/exploitation-of-vulnerabilities-affecting-citrix-netscaler-adc-and-citrix-netscaler-gateway</guid><description>Bron: NCSC-UK (Prioriteit 1).

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Mon, 28 Sep 2026 12:00:00 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign</title><link>https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/</link><guid isPermaLink="true">https://www.securityweek.com/google-warns-of-shinyhunters-fresh-oracle-peoplesoft-campaign/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273. The post Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign appeared first on SecurityWeek .

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt. Wordt gebruikt door ransomwaregroepen: controleer of offline back-ups en detectie op orde zijn.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-35273 (Oracle  PeopleSoft Enterprise PeopleTools), toegevoegd 12 jun 2026, CISA-deadline voor Amerikaanse overheidsinstanties 15 jun 2026. CISA: bekend gebruikt in ransomwarecampagnes.</description><pubDate>Mon, 28 Sep 2026 10:56:46 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-35273</category></item><item><title>[Reguliere patchcyclus] Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability</title><link>https://www.securityweek.com/kiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability/</link><guid isPermaLink="true">https://www.securityweek.com/kiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability/</guid><description>Bron: SecurityWeek (Prioriteit 2).

The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek .

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 09:44:27 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Patiëntomgevingen ziekenhuizen weer online na Citrix-kwetsbaarheden</title><link>https://www.security.nl/posting/954864/Pati%C3%ABntomgevingen+ziekenhuizen+weer+online+na+Citrix-kwetsbaarheden?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/954864/Pati%C3%ABntomgevingen+ziekenhuizen+weer+online+na+Citrix-kwetsbaarheden?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

De patiëntomgevingen van verschillende Nederlandse ziekenhuizen zijn weer online nadat die eerder wegens kwetsbaarheden in ...

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 09:22:00 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] Warning: Citrix NetScaler ADC &amp; NetScaler Gateway RCE Vulnerabilities Actively Exploited as Zero-Days, Patch Immediately!</title><link>https://ccb.belgium.be/advisories/warning-citrix-netscaler-adc-netscaler-gateway-rce-vulnerabilities-actively-exploited</link><guid isPermaLink="true">https://ccb.belgium.be/advisories/warning-citrix-netscaler-adc-netscaler-gateway-rce-vulnerabilities-actively-exploited</guid><description>Bron: CCB (Centre for Cybersecurity Belgium) (Prioriteit 1).

CCB Advisories

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Mon, 28 Sep 2026 08:53:55 GMT</pubDate><category>Direct handelen</category></item><item><title>[Reguliere patchcyclus] Citrix waarschuwt voor misbruikte kwetsbaarheden: &apos;Zo snel mogelijk updaten&apos;</title><link>https://www.security.nl/posting/954841/Citrix+waarschuwt+voor+misbruikte+kwetsbaarheden%3A+%27Zo+snel+mogelijk+updaten%27?channel=rss</link><guid isPermaLink="true">https://www.security.nl/posting/954841/Citrix+waarschuwt+voor+misbruikte+kwetsbaarheden%3A+%27Zo+snel+mogelijk+updaten%27?channel=rss</guid><description>Bron: Security.nl (Prioriteit 2).

Citrix waarschuwt voor twee kritieke kwetsbaarheden in Citrix NetScaler ADC en Gateway waar aanvallers actief misbruik van ...

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 07:24:36 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] CISA orders feds to patch exploited Citrix flaws by Wednesday</title><link>https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/</guid><description>Bron: BleepingComputer (Prioriteit 2).

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Mon, 28 Sep 2026 06:24:19 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Reguliere patchcyclus] Kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway: update nu</title><link>https://www.ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu</link><guid isPermaLink="true">https://www.ncsc.nl/alerts/kwetsbaarheden-in-citrix-netscaler-adc-en-netscaler-gateway-update-nu</guid><description>Bron: NCSC-NL (Prioriteit 1).

Er is een aantal kwetsbaarheden gevonden in Citrix NetScaler ADC en NetScaler Gateway. De ernst van deze kwetsbaarheden varieert, met CVSS-scores tot 9,5. De kwetsbaarheden betreffen verschillende beveiligingsproblemen die onder meer kunnen leiden tot het omzeilen van beveiligingsmaatregelen, het onbruikbaar maken van de NetScaler en het uitvoeren van malafide code op het systeem. Twee van deze kwetsbaarheden worden al misbruikt. Citrix heeft updates uitgebracht. Het NCSC adviseert om deze zo snel mogelijk te installeren.

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Sun, 27 Sep 2026 19:11:42 GMT</pubDate><category>Reguliere patchcyclus</category></item><item><title>[Direct handelen] 2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway</title><link>https://cert.europa.eu/publications/security-advisories/2026-014/</link><guid isPermaLink="true">https://cert.europa.eu/publications/security-advisories/2026-014/</guid><description>Bron: CERT-EU (Prioriteit 1).

On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE) vulnerabilities. Citrix has confirmed active exploitation of these 2 critical vulnerabilities in the wild.&lt;br&gt; CERT-EU recommends updating affected software and running a compromise assessment on those exposed on the internet.&lt;br&gt;

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: De bron meldt actief misbruik of een zero-day.</description><pubDate>Sun, 27 Sep 2026 17:40:52 GMT</pubDate><category>Direct handelen</category></item><item><title>[Direct handelen] NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway</title><link>https://advisories.ncsc.nl/advisory?id=NCSC-2026-0394</link><guid isPermaLink="true">https://advisories.ncsc.nl/advisory?id=NCSC-2026-0394</guid><description>Bron: NCSC-NL (Prioriteit 1).

Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóór versie 13.1-64.23 - Citrix NetScaler ADC FIPS vóór versie 14.1-73.37 FIPS - Citrix NetScaler ADC FIPS en NDcPP vóór versie 13.1-37.279 Secure Private Access Hybrid-implementaties die gebruikmaken van NetScaler-instances zijn ook kwetsbaar voor deze kwetsbaarheden. Deze advisory 

Handelingsperspectief: Direct handelen (binnen 48 uur). Stel vast of het product bij jullie of bij een leverancier in gebruik is. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

Gebaseerd op: CISA KEV: misbruik bevestigd voor CVE-2026-88771 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026. CISA KEV: misbruik bevestigd voor CVE-2026-88772 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026. NCSC-inschatting: kans hoog, schade hoog.</description><pubDate>Sun, 27 Sep 2026 16:55:29 GMT</pubDate><category>Direct handelen</category><category>CVE-2026-88771</category><category>CVE-2026-88772</category><category>CVE-2026-88773</category><category>CVE-2026-88774</category><category>CVE-2026-88775</category><category>CVE-2026-88776</category><category>CVE-2026-88777</category><category>CVE-2026-88778</category></item><item><title>[Reguliere patchcyclus] Cloudflare fixes Containers cross-tenant flaw exposing customer data</title><link>https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/</link><guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/</guid><description>Bron: BleepingComputer (Prioriteit 2).

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers&apos; containers on the same physical host. [...]

Handelingsperspectief: Reguliere patchcyclus (binnen de reguliere patchcyclus). Neem de update mee in de reguliere patchcyclus.

Gebaseerd op: Geen aanwijzingen voor misbruik of een hoge ernst in de brondata.</description><pubDate>Sun, 27 Sep 2026 14:13:31 GMT</pubDate><category>Reguliere patchcyclus</category></item></channel></rss>