Complete article archive
260 published articles · Showing 13–24 · Newest first
Microsoft September 2026 Security Update Cycle
Analysis of the September 9, 2026, Microsoft security updates addressing 974 vulnerabilities, including two zero-day flaws.
Read article →ConnectWise ScreenConnect Unauthorized File Execution (CVE-2026-84869)
A security update released September 14, 2026, addresses CVE-2026-84869 in ConnectWise ScreenConnect, which could allow unauthorized file transfer and execution during active remote sessions.
Read article →Unauthenticated Remote Code Execution in Check Point Security Gateways (CVE-2026-85102)
Analysis of CVE-2026-85102, a vulnerability in Check Point Security Gateways that may allow unauthenticated remote attackers to execute arbitrary code and achieve complete device compromise.
Read article →PAN-OS Root-Level Execution and DoS Vulnerability (CVE-2026-0310)
Analysis of CVE-2026-0310 in PAN-OS, which could allow root-level arbitrary code execution or denial of service.
Read article →Remote Code Execution Vulnerabilities in Check Point VPN Components
Two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103) affecting Check Point Security Gateways, Management Servers, and Spark Firewalls allow unauthenticated remote code execution when VPN services are enabled.
Read article →GitLab Repository Commits API Path Traversal (CVE-2026-85706)
A path traversal vulnerability in GitLab Community and Enterprise Editions allows unauthenticated arbitrary file reads via the repository commits API. This analysis details remediation priorities and validation requirements for infrastructure owners.
Read article →ConnectWise ScreenConnect Unauthorized File Transfer and Execution (CVE-2026-84869)
Analysis of CVE-2026-84869 in ConnectWise ScreenConnect, focusing on improper privilege management and missing authorization that could allow unauthorized file transfer and execution during active sessions.
Read article →Privilege Escalation in JFrog Artifactory (CVE-2026-42016)
A validation failure in token scope processing within JFrog Artifactory allows for privilege escalation. This analysis examines the authorization flaw and the requirements for verifying remediation.
Read article →JFrog Artifactory Improper Authentication (CVE-2026-42018)
An improper authentication vulnerability in JFrog Artifactory may allow unauthenticated callers to obtain internal anonymous-user tokens, potentially exposing sensitive resources even when anonymous access is disabled.
Read article →MikroTik RouterOS Privilege Escalation (CVE-2026-86060)
A vulnerability in MikroTik RouterOS allows for the modification of trusted policy masks, enabling privilege escalation. This flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Read article →MikroTik RouterOS Kernel Memory Disclosure in btest Service
CVE-2026-67277 identifies a missing authentication vulnerability in the MikroTik RouterOS btest service, potentially leading to kernel memory disclosure and denial of service.
Read article →Citrix NetScaler ADC and Gateway Authentication Bypass (CVE-2026-19490)
An authentication bypass vulnerability in Citrix NetScaler ADC and Gateway allows unauthenticated remote actors to circumvent security controls on specific configurations, including AAA virtual servers and Gateways.
Read article →Page 2 of 22. This archive includes every published article; drafts and articles still processing are not public.
From government advisory to practical action
Vulnerability Assurance turns government cybersecurity reporting into original articles written for the people responsible for fixing vulnerabilities. Each analysis connects the source information to the decisions, corrective actions, and verification steps that matter in an affected environment.
Latest analysis
What our articles cover
- What happened: the vulnerability, the affected technology, and what the available evidence establishes.
- Who needs to act: relevant versions, configurations, exposure conditions, and operational dependencies.
- How to mitigate it: applicable patches, configuration changes, or compensating controls, with important limitations.
- How to verify the result: checks and retesting that can demonstrate whether the affected condition or exposure remains.
- What remains unresolved: uncertainty, residual risk, and follow-up work.
Analysis you can use here
Government advisories provide the evidence behind our reporting. Our articles explain that evidence in context and add practical mitigation and validation guidance. Source citations support the analysis; they do not replace it.
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗