ZeroHour

Search: “Canadian Centre for Cyber Security”

160 stories

AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

Canada's Cyber Centre warns of three exploited MikroTik RouterOS vulnerabilities affecting SSH-exposed devices; CISA added two to its KEV catalog.

The Canadian Centre for Cyber Security issued alert AL26-020 for three MikroTik RouterOS vulnerabilities, especially on devices exposing SSH to the internet: CVE-2026-67277 (missing authentication, CWE-306, enabling sensitive information disclosure), CVE-2026-86060 (argument injection, CWE-88, enabling privilege escalation), and CVE-2026-67276 (improper cryptographic signature verification, CWE-347, allowing SSH command channel access without the private key). On September 10, 2026, CISA added CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities catalog. Fixed versions include RouterOS 6.49.21, 7.23.4 (Long-Term), 7.24.2 (Stable), and 7.25 beta 3.

Canadian Centre for Cyber Securityupdated · 5d agofirst · 6d agoVulnerability in the wild 2 sourcesCVE-2026-67276CVE-2026-67277CVE-2026-860603· 2 reads

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Canadian Cyber Centre alerts on Citrix NetScaler ADC/Gateway flaws CVE-2026-19490 (authentication bypass) and CVE-2026-19489 (buffer overflow), urging emergency patching.

The Canadian Centre for Cyber Security issued alert AL26-019 covering two Citrix NetScaler vulnerabilities disclosed in a vendor advisory on August 19, 2026. CVE-2026-19490 (CWE-288) allows a remote unauthenticated attacker to bypass authentication on appliances configured as a Gateway for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. CVE-2026-19489 (CWE-120) is a classic buffer overflow that may cause memory overflow, unpredictable behavior, or denial-of-service conditions. Affected appliances are vulnerable when configured as a SAML IdP; fixed versions include 14.1-73.32, 13.1-63.21, and 13.1-37.277 for FIPS.

Fortinet security advisory (AV26-023) - Update 1

CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.

The Canadian Centre for Cyber Security updated advisory AV26-023, which relays January 2026 Fortinet advisories covering FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. On September 9, 2026, CISA added CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its Known Exploited Vulnerabilities catalog. Related Fortinet flaws include unauthenticated local configuration access (CVE-2025-47855) and unauthenticated remote command injection (CVE-2025-64155). Administrators should review the advisories and apply available updates.

Citrix security advisory (AV26-833) - Update 1

CISA added actively exploited NetScaler flaw CVE-2026-19490 to its KEV catalog; the Canadian Cyber Centre urges Citrix ADC and Gateway admins to patch.

The Canadian Centre for Cyber Security updated advisory AV26-833 covering Citrix NetScaler ADC and Gateway vulnerabilities in versions 13.1 (prior to 13.1-63.21) and 14.1 (prior to 14.1-73.32), plus FIPS builds. On September 9, 2026, CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog, indicating confirmed exploitation. The bulletin also references CVE-2026-19489 from the Citrix NetScaler ADC and Gateway Security Bulletin. Administrators should apply the fixed builds, including 13.1-37.277 and 14.1-73.32 for FIPS variants.