Resources

All official content published by AI SPERA is gathered in one place. From product updates to reports and case studies, you can explore it all here.

September 3, 2026

PaperCut NG/MF Vulnerabilities Exploited in Active Attacks: Analysis of Internet-Exposed Print Management Servers

Companies, schools, public institutions, and other organizations use centralized print management solutions to efficiently manage printers and multifunction devices. PaperCut NG/MF is one of the leading print management solutions widely used in these environments. An attack…

Blog
PaperCut NG/MF Vulnerabilities Exploited in Active Attacks: Analysis of Internet-Exposed Print Management Servers

September 1, 2026

NetScaler ADC·Gateway Authentication Bypass Vulnerability CVE-2026-19490 Analysis

On August 19, 2026, a critical authentication bypass vulnerability, CVE-2026-19490, was disclosed in NetScaler ADC and NetScaler Gateway, widely deployed enterprise appliances positioned at network perimeters. The vulnerability is rated CVSS v4.0 9.3 (Critical) and is classified…

Blog
NetScaler ADC·Gateway Authentication Bypass Vulnerability CVE-2026-19490 Analysis

August 28, 2026

Zimbra Vulnerability Allowing Unauthenticated OS Command Execution: CVE-2026-73570 and External Exposure Analysis

CVE-2026-73570, a vulnerability in Zimbra Collaboration that can lead to unauthenticated remote code execution, has been confirmed to be actively exploited. Zimbra Collaboration is a collaboration platform used by companies and public institutions to operate email, calendars,…

Blog
Zimbra Vulnerability Allowing Unauthenticated OS Command Execution: CVE-2026-73570 and External Exposure Analysis

August 26, 2026

GitLab GraphQL Code Injection Vulnerability CVE-2026-19478 Analysis

On August 17, 2026, GitLab, the self-managed Git platform, released an emergency security update outside its regular update cycle to address the critical vulnerability CVE-2026-19478. The vulnerability, rated CVSS v3.1 9.4 (Critical), is a code injection flaw (CWE-94) involving…

Blog
GitLab GraphQL Code Injection Vulnerability CVE-2026-19478 Analysis

August 26, 2026

Privacy Policy Update (Effective September 3, 2026)

Criminal IP will update its Privacy Policy effective September 3, 2026.This update reflects applicable laws and guidelines, current service operations, and improvements to how information regarding the processing of personal data is organized and presented. Key Updates (v1.3)…

Release Note
Privacy Policy Update (Effective September 3, 2026)

August 24, 2026

A CVSS 10.0 Vulnerability That Can Lead to Metabase Admin Compromise: CVE-2026-72898

In August 2026, a remotely exploitable SQL Injection vulnerability affecting the open-source analytics platform Metabase, tracked as CVE-2026-72898, was disclosed. The vulnerability was assigned a CVSS score of 10.0 (Critical), and it allows attackers to inject arbitrary SQL…

Blog
A CVSS 10.0 Vulnerability That Can Lead to Metabase Admin Compromise: CVE-2026-72898

August 20, 2026

VPN Vulnerability That Can Reboot Firewalls: Cisco ASA·FTD CVE-2026-20349

On August 11, 2026, Cisco warned that CVE-2026-20349, a denial-of-service (DoS) vulnerability affecting Secure Firewall ASA (Adaptive Security Appliance) and Secure Firewall Threat Defense (FTD) software, was being actively exploited in the wild. The vulnerability is rated 8.6…

Blog
VPN Vulnerability That Can Reboot Firewalls: Cisco ASA·FTD CVE-2026-20349

August 18, 2026

Unauthenticated Server-Side Code Execution in Adobe ColdFusion: CVE-2026-48362 and Analysis of Internet-Exposed Assets

On August 11, 2026, Adobe released security update APSB26-90 to address multiple vulnerabilities identified in ColdFusion 2025 and ColdFusion 2023. The update includes vulnerabilities that could lead to arbitrary code execution, privilege escalation, security feature bypass,…

Blog
Unauthenticated Server-Side Code Execution in Adobe ColdFusion: CVE-2026-48362 and Analysis of Internet-Exposed Assets

August 13, 2026

WordPress Vulnerability CVE-2026-64638: Login Page XSS to Server-Side Code Execution

In August 2026, a pre-authentication XSS vulnerability, CVE-2026-64638, was disclosed in the WordPress Core login screen. Dubbed XSS2Shell, the vulnerability originates from a Reflected XSS in the input-handling process of wp-login.php and can potentially be chained with the…

Blog
WordPress Vulnerability CVE-2026-64638: Login Page XSS to Server-Side Code Execution

August 12, 2026

Unauthenticated Server File Read in Gitea: CVE-2026-59774 Analysis

On August 2, 2026, a critical vulnerability, CVE-2026-59774, was disclosed in Gitea, a self-hosted Git platform, allowing unauthenticated attackers to read arbitrary files from the server. The vulnerability is rated CVSS v3.1 9.8 (Critical) and is classified as an…

Blog
Unauthenticated Server File Read in Gitea: CVE-2026-59774 Analysis

August 10, 2026

N-able N-central Authentication Bypass: CVE-2026-18577 Analysis

In late July 2026, CVE-2026-18577, an authentication bypass vulnerability affecting the N-able N-central remote monitoring and management platform, was confirmed to have been actively exploited in attacks. N-central is a Remote Monitoring and Management (RMM) platform used by…

Blog
N-able N-central Authentication Bypass: CVE-2026-18577 Analysis

August 7, 2026

Multi-Product Visibility and Certificate Risk Detection Update

This update enhances IP asset analysis by displaying multiple products associated with an open port and introduces three new certificate risk categories for identifying potentially unsafe or improperly configured TLS certificates. Maintenance Schedule v1.104.0: 2026.08.06…

Release Note
Multi-Product Visibility and Certificate Risk Detection Update

Business Customer Reports

Experienced any inconvenience?

Let us know right away.

Contact US

Join AI SPERA

Be part of the AI SPERA journey.

Contact US