Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Diez CVE en el proceso iked de un cortafuegos: leer el campo de impacto antes que el titular
8 min read

Ten CVEs in one process: the headline is not enough to decide

On 27 August, ten security advisories landed in iked, the process that negotiates a firewall's IPsec tunnels. We read them one by one, and in several of them the headline and the body do not say the same thing: one titled "unauthenticated" needs a VPN user with valid credentials; another the vendor could not reproduce; and one of the lowest-scoring is the only one that mentions reading key material. How to read a bulletin like that in forty minutes.

Puerta de acero de una sala de servidores sujeta abierta con una cuña, con un rack visible al fondo
8 min read

The bulletin said "denial of service". The exploit gives root: NetScaler CVE-2026-8452

Citrix shipped the patch on 30 June and described it as a denial of service; the CVSS vector on that same entry already showed high confidentiality impact and no privileges required. On 14 August, 45 days later, the exploit that gives unauthenticated root went public, and attacks followed within days: CISA set a 29 August deadline. How to check whether you are patched without knocking the box over (513 bytes, error 43549) and why the patch does not evict whoever already got in.

Puesto de trabajo de una oficina vacío al amanecer, con la silla apartada, una taza fría y la persiana entreabierta
8 min read

They switched the EDR off with a reboot, and the encryption failed for lack of memory

On 4 August an Akira affiliate walked in through an MFA-less SSL VPN in roughly seven minutes and, rather than fight the EDR, rebooted the compromised host into <code>Safe Mode with Networking</code>: the agent and Defender real-time protection stopped starting. We counted the blind window against the timestamps in the Huntress report and it comes to 1 h 41 min, not the 10 minutes that circulated. The encryption did fail, but on virtual memory, not on defences.

Aparato de red de 1U extraído sobre sus guías en un rack de sala técnica, con cable de consola conectado y un carro de servicio al lado
6 min read

NetScaler CVE-2026-19490: your version doesn't tell you whether you're exposed

On 19 August Citrix published an authentication bypass scoring 9.3 out of 10 in NetScaler ADC and Gateway. Being affected does not depend on your version alone: it depends on what you have configured, and older builds need fewer conditions. How to actually answer the question, why a pre-authentication flaw leaves your MFA out of the path, and what we do in the window before the first exploit lands.

Armario de comunicaciones de pared en una sala técnica, con un servidor de rack, un pequeño cortafuegos y un panel de parcheo con latiguillos naranjas y grises
7 min read

"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824

Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.

Pasillo de un centro de datos: cuando el concentrador de VPN se reinicia, el acceso remoto de toda la empresa se queda fuera
6 min read

The Cisco flaw that steals nothing: it just reboots the door your people come in through

On 11 August Cisco published an advisory for ASA and Secure Firewall Threat Defense: an HTTP request against the remote access SSL VPN service makes the device reload. The CVSS vector reads C:N/I:N/A:H —nothing is leaked, nothing is altered— and two hours and twenty minutes later it was already in CISA's KEV catalog with a 14 August due date. Three days. What to check on the device, why the patch costs exactly what the attack costs, and when this does not concern you.

WireGuard o IPsec: comparativa honesta entre los dos protocolos de túnel, con el criterio de everyWAN sobre cuál usar en cada caso y el calendario post-cuántico europeo
8 min read

WireGuard or IPsec: what we deploy where

WireGuard is about 4,000 lines of code, it landed in the Linux kernel in 2020 and it fits on one page of config. IPsec drags along thirty years of RFCs and proposals that never quite match. And we still deploy IPsec in a good share of the places we work, for three reasons that show up in no comparison table: who is on the other end of the tunnel, who authenticates the people, and what happens when the cryptography has to change. An honest comparison, no fanboyism, with Europe's post-quantum calendar on the table.

CVE-2025-68686: el parche de FortiOS que se saltaba con una barra de más
8 min read

Patching is not cleaning: FortiOS and the extra slash

On 27 July, CISA added a FortiOS flaw to its exploited-vulnerabilities catalogue with a deadline attached: 10 August. CVE-2025-68686 opens no new door: it reopens the one Fortinet believed it had closed in April 2025, and it does so with one extra slash in the path. The story of the symbolic link in the language-files folder, the patch that was a string comparison, the 7.2, 7.0 and 6.4 branches left with no fix at all, and why patching is an action while being clean is a conclusion you have to prove.

SD-WAN multi-sede: cuándo compensa y cuándo sobra
5 min read

SD-WAN yes, but not everywhere: when it pays off and when it's overkill

Gartner predicted that by 2026, 70% of enterprises would have SD-WAN. We deploy it — and even so, more than once we have recommended against it. What problem it actually solves, when it pays off (changing sites, two transports, suffering applications), when two lines and WireGuard do the job, and the costs that never show up in the demo: the forever license, the orchestrator as a dependency and the complexity that doesn't disappear — it relocates.

Secuestro de DNS en Wi-Fi de hoteles para robar cuentas de Microsoft 365
7 min read

The hotel Wi-Fi works for someone else: DNS hijacked to steal Microsoft 365 accounts

Since June 2026 an active campaign has been compromising captive portals at hotels and conference centers, changing their DNS and redirecting guests to fake Microsoft 365 pages. The refined part: by abusing the device code flow they take your account without stealing your password, with MFA "satisfied". What is happening, why the padlock won't save you, and what we would do: from full-tunnel VPN to blocking the device code flow.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN