TODAY
VPN gateways and load balancers under active attack — patch now.
THE THREE
- KEV#1 · CVE-2026-34486
Apache
What: If your org runs Apache Tomcat (versions 11.0.20, 10.1.53, or 9.0.116), session data that should be encrypted is exposed in transit — attackers can intercept sensitive application data or hijack sessions. With 83% exploit probability and active exploitation confirmed, this is a patch-today situation for any Java web app team.
Why it moved: Actively exploited · Everyone runs this · 83% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 immediately.
- KEV#2 · CVE-2026-10520
Ivanti
What: Ivanti Sentry has a perfect CVSS 10.0 OS command injection flaw — an unauthenticated attacker on the internet can get root-level control of your mobile device management gateway, potentially exposing every managed device and credential flowing through it. This has been actively exploited for over two months.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Isolate Ivanti Sentry from public internet and apply vendor patch immediately.
- KEV#3 · CVE-2026-0257
Palo Alto
What: Attackers can bypass authentication on Palo Alto PAN-OS and establish unauthorized VPN connections — effectively walking through your perimeter firewall as a trusted user. With 94% exploit odds and active exploitation, any internet-facing PAN-OS device is a live target.
Why it moved: Actively exploited · Widely deployed · Critical severity · 94% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Palo Alto's PAN-OS patch and audit VPN connection logs for anomalies now.
TRAVERSAL
Graph links this vulnerability to maven/org.apache.tomcat:tomcat-catalina.
NUMBERS
- Entities
- 11M
- Relationships
- 63M
- Threat actors
- 355
- Indicators
- 549k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.