FR
live
tag

#vpn

Check Point patches two CVSS 9.8 flaws in its VPN certificate handling

On September 9, 2026, Check Point fixed two CVSS 9.8 flaws in how its firewalls and management console validate and decode VPN certificates, both exploitable without authentication for remote code execution. The Dutch NCSC says exploitation is imminent: apply the Live Patch or the Jumbo Hotfix now.

Tailcat ships Tailscale’s WireGuard data plane with no control plane at all

On August 31, 2026, Brad Fitzpatrick released tailcat, an open-source Go package and CLI that exposes Tailscale’s data plane — WireGuard, NAT traversal, and DERP — with no account, no IP addresses, and no control plane. Use it to connect two isolated machines, or hand an AI agent a disposable connection, with no root access.

Citrix NetScaler patches a critical remote authentication bypass (CVSS 9.3) exploitable without credentials

On August 19, 2026, Cloud Software Group published a bulletin for NetScaler ADC and NetScaler Gateway: CVE-2026-19490, a CVSS 9.3 authentication bypass exploitable remotely without credentials, and CVE-2026-19489, an 8.8 denial-of-service. Any internet-facing appliance needs an emergency upgrade, after triage driven by the SAML or vserver configuration.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss