TODAY
188 ransomware victims in 7 days — patch your perimeter now.
THE THREE
- KEV#1 · CVE-2026-34486
Apache
What: If you run Apache Tomcat, attackers can strip away its encryption layer and chain this with a previously known flaw (CVE-2025-24813) to potentially take over your application server — this was added to CISA's exploited list 7 days ago with an 81% exploit probability. Any org hosting Java web apps on Tomcat is directly in the crosshairs.
Why it moved: Actively exploited · Everyone runs this · 81% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the latest Apache Tomcat patch and verify EncryptInterceptor is enforced.
- KEV#2 · CVE-2026-10520
Ivanti
What: Ivanti Sentry has a perfect 10.0 CVSS score and a 99.9% exploit probability — an unauthenticated attacker on the internet can gain full root-level control of your mobile device management gateway with no credentials required. This is as bad as it gets for any org using Ivanti Sentry for mobile access.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Patch Ivanti Sentry immediately or isolate it from internet exposure today.
- KEV#3 · CVE-2026-0257
Palo Alto
What: Attackers can bypass authentication on Palo Alto PAN-OS firewalls and create unauthorized VPN connections, effectively walking past your perimeter — 94% exploit probability means this is being actively weaponized. Organizations relying on Palo Alto for network security are at direct risk of perimeter compromise.
Why it moved: Actively exploited · Widely deployed · Critical severity · 94% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Palo Alto PAN-OS patches and audit VPN connection logs for anomalies.
TRAVERSAL
Graph links this vulnerability to maven/org.apache.tomcat:tomcat-tribes.
NUMBERS
- Entities
- 10M
- Relationships
- 62M
- Threat actors
- 352
- Indicators
- 545k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.