NINJA SIGNAL
DEFCON··MAXIMUM

TODAY

153 ransomware victims in 7 days — patch VPNs and servers now.

THE THREE

  1. #1 · CVE-2026-34486

    Apache

    KEV

    What: Apache Tomcat's encryption protection can be bypassed on versions 11.0.20, 10.1.53, and 9.0.116, meaning sensitive data passing through your app server could be exposed or intercepted — and 83% exploit probability means attackers are actively working this. Almost every Java web shop runs Tomcat.

    Why it moved: Actively exploited · Everyone runs this · 83% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 today.

  2. #2 · CVE-2026-10520

    Ivanti

    KEV

    What: Ivanti Sentry has a perfect CVSS 10 OS command injection flaw — an unauthenticated attacker on the internet can get full root access to your mobile device management gateway, handing over your entire MDM environment. Exploit probability is essentially 100%.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch or isolate Ivanti Sentry from internet exposure immediately.

  3. #3 · CVE-2026-0257

    Palo Alto

    KEV

    What: Attackers can bypass authentication on Palo Alto PAN-OS and create unauthorized VPN connections, effectively walking through your perimeter firewall without credentials — 94% exploit odds means this is happening in the wild right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 94% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Palo Alto's PAN-OS patch and audit VPN session logs for anomalies.

TRAVERSAL

Graph links this vulnerability to maven/org.apache.tomcat:tomcat-catalina.

software · maven/org.apache.tomcat:tomcat-catalinasoftware · maven/org.apache.tomcat.embed:tomcat-embed-coresoftware · maven/org.apache.tomcat:tomcat

NUMBERS

Entities
11M
Relationships
63M
Threat actors
355
Indicators
551k
Feeds live
0
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.