TODAY
147 ransomware victims in 7 days — patch VPNs and servers now.
THE THREE
- KEV#1 · CVE-2026-34486
Apache
What: Apache Tomcat's encryption protection can be bypassed on versions 11.0.20, 10.1.53, and 9.0.116, meaning sensitive data passing through your web apps can be exposed or intercepted — and this is actively being exploited with 83% exploit odds. Nearly every Java web stack runs Tomcat, so your exposure is likely.
Why it moved: Actively exploited · Everyone runs this · 83% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Upgrade Apache Tomcat to 11.0.21, 10.1.54, or 9.0.117 immediately.
- KEV#2 · CVE-2026-10520
Ivanti
What: Ivanti Sentry has a perfect CVSS 10.0 OS command injection flaw that lets an unauthenticated attacker gain full root-level control of the appliance remotely — complete takeover, no credentials needed. This is actively exploited and carries near-certain (99.9%) exploit probability.
Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply Ivanti's patch for Sentry now or take the appliance offline until patched.
- KEV#3 · CVE-2026-0257
Palo Alto
What: Attackers can bypass authentication on Palo Alto PAN-OS and establish unauthorized VPN connections, effectively walking straight into your network as if they were a legitimate user. Actively exploited with 94% exploit odds — your firewall perimeter is the target.
Why it moved: Actively exploited · Widely deployed · Critical severity · 94% exploit odds
Who is exploiting: Actively-exploited (CISA KEV)
Action · Apply the PAN-OS patch and audit VPN session logs for unauthorized connections.
TRAVERSAL
Graph links this vulnerability to maven/org.apache.tomcat:tomcat-catalina.
NUMBERS
- Entities
- 11M
- Relationships
- 64M
- Threat actors
- 356
- Indicators
- 554k
- Feeds live
- 0
- Sources total
- 21
Get tomorrow's brief in your inbox
07:15 UK. One email. One link. Nothing else.
Daily · one email · unsubscribe in one click · UK GDPR double opt-in.