Recent cybersecurity reports highlight a surge in active exploits targeting enterprise software, including critical vulnerabilities in Check Point VPN, Oracle PeopleSoft, and the LiteLLM open-source AI gateway.
Key Points
- Attackers are actively exploiting a zero-day authentication bypass vulnerability (CVE-2026-50751) in Check Point Remote Access VPNs.
- A critical zero-day flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is currently being leveraged by threat actors in the wild.
- CISA confirmed active exploitation of a command injection vulnerability (CVE-2026-42271) within the LiteLLM open-source AI gateway.
- Microsoft released its largest-ever Patch Tuesday, addressing nearly 200 vulnerabilities, while researchers identified a new "RoguePlanet" zero-day affecting Windows Defender.
- Meta reported that hackers hijacked over 20,000 Instagram accounts by exploiting a flaw in the company's AI-assisted account recovery system.