Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Sala de control con un muro de pantallas de monitorización y varias personas mirándolo de pie
10 min read

AI now finds zero-days on its own. Your problem is the 43 days that come after

On 4 September OpenAI launched GPT-6 Astra and declared it the first model it deploys reaching the "Critical" cybersecurity capability level of its preparedness framework. Almost all the coverage went after that half. The two numbers that decide what happens to you predate Astra and neither is about finding flaws: mean time to exploit is minus seven days according to M-Trends 2026, and the median to fully remediate a KEV-listed vulnerability is 43 days according to Verizon's DBIR. The bottleneck was never finding.

Técnico agachado con un portátil trabajando en la parte trasera de un rack de servidores
5 min read

REPLICATION was never a read-only privilege: PostgreSQL closed a twelve-year dlopen()

On 13 August PostgreSQL shipped 18.6, 17.11, 16.15, 15.19 and 14.24. Among the CVEs they close there is one that is not about buffer overflows: any account holding the REPLICATION attribute could name as its logical decoding plugin any file visible to the system, and the server would load it and run its code as the operating system user. The patch adds a whitelist with two entries by default: if your change data capture uses decoderbufs or wal2json, it stops your replication until somebody edits postgresql.conf.

Armario de red mural abierto en el pasillo de una oficina, con anillas pasahilos y cables recogidos, y un extintor apoyado en la pared al fondo
7 min read

July's patch is September's vulnerable build

SonicWall closed the SMA 1000 zero-day pair in build 12.4.3-03453 on 14 July. The 1 September advisory lists 12.4.3-03453 and earlier as affected: anyone who met the three-day KEV deadline landed on exactly the build that is back in the catalog 49 days later, with the same shape of flaw. When an appliance repeats the shape of the flaw, the question stops being whether it is patched and becomes how far that box reaches.

Servidor de dos alturas con la tapa quitada sobre una estantería metálica, en el trastero de una oficina, con cartones apoyados en la pared
5 min read

Artifactory's "medium" CVE hit the catalog before the critical one

CISA confirmed exploitation of a 5.3 JFrog Artifactory flaw on 27 August; of the 9.8 that lets anyone forge admin tokens, on 2 September. Six days apart, and in the opposite order to the scores. Look at the full vector of the "medium" one and you see why: two of the three impact dimensions are zero and the one left at maximum is integrity. In an artifact repository, integrity is exactly what you are buying.

Cuarto de instalaciones de una oficina con un ordenador de sobremesa y un conmutador de red pequeño en una estantería metálica, junto a una caja de cables y material de limpieza
9 min read

Kestra, 10 out of 10: the flaw that does not need to face the internet

On 2 September 2026 CISA added seven exploited flaws to the KEV catalog. Three were perimeter appliances; another three are services your own team stood up (JFrog Artifactory, Kestra and LiteLLM), and the seventh, Starlette, nobody installed at all. The Kestra one scores 10.0 and opens because an authentication filter uses endsWith instead of an exact comparison. And the advisory says internet exposure is not required: reaching the port from inside is enough. What that changes in your patching queue.

Cuarto de interconexión con paneles de parcheo, latiguillos de fibra naranja y amarilla recogidos en peines horizontales y una bobina de fibra colgada en la pared
5 min read

The route hijack RPKI called valid: the ROA allowed all the way down to /24

Between 28 and 30 August 2026, a BGP hijack diverted traffic for 162.55.80.0/24 across some 22 active hours and served a malicious update from behind a valid TLS certificate. We went and checked the ROA on RIPEstat: until 1 September it carried maxLength 24, so while the hijack lasted the route was RPKI valid. What origin validation checks and what it does not, why that same maxLength was also the cure, and the six verifications you can run today.

Proxmox VE 7 y CVE-2023-54391: dos servidores viejos todavía encendidos en la estantería de un cuarto trastero
7 min read

Proxmox VE 7: the patch had been out for three years and nobody knew it was a patch

On 1 September 2026 Proxmox published advisory PSA-2026-00043-1: on Proxmox VE 7, sending any tfa-challenge value is enough to log in as root@pam with no password. The code that fixed it shipped on 20 July 2023 inside a refactor nobody classified as security, which is why it was never backported. What the flaw does, why a second factor saved you, what to check on your node today, and what all of this says about your inventory.

Archivo de oficina con cajas y carpetas apiladas en estanterías metálicas bajo luz natural
5 min read

They are not old bugs: they are old classes of bug. We ran the numbers on CISA's catalogue

We downloaded CISA's Known Exploited Vulnerabilities catalogue and counted its 1,685 entries. Of the 201 added in 2026, 123 carry an identifier from this same year and the median gap is zero: what is old is not the individual bug but the class. We measured that too, using the file's own cwes field: CWE-20, improper input validation, tops the catalogue with 118 entries, followed by command injection and out-of-bounds write. And something turned up that we were not looking for: on 10 June directive BOD 26-04 revoked BOD 22-01, and since then 81% of what goes in arrives with a three-day deadline instead of the previous 23%.

Cuarto de impresión de una oficina con una multifunción, cajas de papel y un servidor en una estantería metálica
9 min read

PaperCut: the print server runs as SYSTEM, and nearly half the measured estate has no patch

On 27 August PaperCut confirmed active exploitation of PaperCut NG and MF. The identifiers landed the next day: CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 (CVSS 9.4), chained into unauthenticated remote code execution. Huntress watched one intrusion last under two minutes, and in their proof of concept the code executes as SYSTEM. The figure that orders everything else: 47% of the 2,500 installations Huntress tracks are on version 23 or older, for which no patch exists. What happened hour by hour, why Thursday's patch did not hold on Friday, and today's notice that turns one of the indicators into a false positive.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
5 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Armario de red mural con la puerta abierta en el cuarto trastero de una oficina, con cajas de cartón, una fregona y estanterías
7 min read

Gitea's flaw "requires write access". The signup form hands it to you

The CVE-2026-60004 write-up says you need write access to a repository. The official vector in the same advisory says <code>PR:N</code>, privileges required: none. Both are true, because Gitea installs with <code>DISABLE_REGISTRATION=false</code>. What that means for how you prioritise patching everything you self-host, what happened in the eleven seconds of the only public case, and the list of what to check today.

Fotocopiadora multifunción de oficina con la puerta de tóner abierta y la bandeja de papel a medio sacar
7 min read

August's patch broke printing in WPF apps: the three ways out, with the maths done

The 11 August .NET Framework cumulative update breaks printing and PDF export in WPF applications using Calibri, Cambria, Constantia and Corbel: <code>System.IO.FileFormatException</code> on a font Windows itself installs. Microsoft acknowledged it on the 24th, thirteen days later, and the interim workaround switches off the overflow protection that same patch had just added. We looked at what exactly it turns off, why the decision should be per application rather than per fleet, and which of the three ways out costs least in each case.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
9 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Jaula de rejilla metálica cerrada con candado en una sala de datacenter compartida, con dos racks de servidores detrás
9 min read

The patch that isn't yours: what to do with Entra ID's CVE-2026-69836

On 20 August Microsoft published a critical remote code execution flaw in Entra ID, and the next day corrected the exploitation field to "No". There is nothing to install: the record says "customerActionRequired: false". What is yours is the ability to answer "were we affected?", and on an Entra ID Free licence that lasts seven days. How to read the record from Microsoft's own API, and the checklist we apply to the tenant.

Armario de red mural abierto en una oficina, con panel de parcheo, dos conmutadores de rack y un mazo de latiguillos peinado sobre el raíl lateral
9 min read

A CVE is no longer one bug: Cisco has changed the unit of measurement

On 19 August Cisco published two advisories carrying five CVEs scored 10.0 between them. They are not five bugs: each identifier groups an entire class of bugs and carries the score of the worst one in the bag. Across the four hardening advisories we reviewed the mitigation line says the same thing, "none." This is not a complaint about Cisco: it is that the unit you count vulnerabilities in has changed size, and your inventory has not noticed.

  • 1
  • 2

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN