This week in security: Windows zero-days, Flax Typhoon, Oracle Health breach

This week in security: Windows zero-days, Flax Typhoon, Oracle Health breach

This weekly security digest for 2026-W41 covers two exploited Windows privilege-escalation flaws, an FBI seizure of Flax Typhoon domains and a reported Oracle Health Cerner breach affecting nearly 20 million people. CISA added eight vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, five of them due for remediation on 11 October 2026.

Top stories

Also this week: a Qilin ransomware suspect was extradited from Japan to Germany, the MonsterCloud owner was charged with secretly paying ransoms and fake AI ad portals were found using browser-in-the-browser phishing to steal MFA codes.

Newly exploited vulnerabilities

CISA added these eight entries to the KEV catalog this week.

CVE Vendor / product Issue Due date
CVE-2015-5477 ISC BIND Data processing errors 2026-10-11
CVE-2016-3081 Apache Struts Command injection 2026-10-11
CVE-2023-22894 Strapi Cleartext storage of sensitive information 2026-10-11
CVE-2021-3199 ONLYOFFICE Docs Server path traversal 2026-10-11
CVE-2015-3306 ProFTPD Improper access control 2026-10-11
CVE-2026-88779 Citrix NetScaler Memory buffer bounds restriction 2026-10-07
CVE-2026-102490 Zammad Improper privilege management 2026-10-05
CVE-2026-102489 Zammad Session fixation 2026-10-05

Why this matters

Analysis: Several of this week’s KEV entries are old CVEs (2015 to 2023) in widely deployed software such as BIND, Struts and ProFTPD. Attackers keep using flaws that were patched years ago, so unpatched or forgotten internet-facing systems are the realistic risk for a typical environment.

What to prioritise next week

  • Check the 11 October KEV deadline items first. Look for BIND, Struts, ProFTPD, Strapi and ONLYOFFICE Docs in your asset inventory; patch or restrict affected Strapi and ONLYOFFICE Docs versions.
  • Patch the Windows zero-days (CVE-2026-81963 and CVE-2026-85880) from the September Patch Tuesday release, since both are in KEV.
  • Treat Citrix NetScaler (CVE-2026-88779) and Zammad (CVE-2026-102489, CVE-2026-102490) as overdue: their KEV due dates have already passed, so verify they are fixed and review sessions and admin access.
  • Review internet-exposed admin tools such as Rejetto HFS (upgrade to the fixed release) and Atlassian Data Center products, and restrict access while you update.
  • Hunt for Flax Typhoon activity using the details in our seizure coverage, and check Exchange Server and FortiMail versions against the vendor fixes.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts