461.25.09.26- Critical WordPress Vulnerability CVE-2026-87902

461.25.09.26- Critical WordPress Vulnerability CVE-2026-87902

Severity: CriticalCVSS Score: 9.2Affected Product: WordPress CoreAffected Versions: WordPress 4.7.0 through 7.1.1 Overview TT-CSIRT is advising organizations using WordPress to urgently apply security updates for CVE-2026-87902, a critical WordPress Core vulnerability that allows attackers to access unintended PHP files and achieve remote code execution. Exploitation has also been observed using public scanning and proof-of-concept tools increasing […]

460.23.09.26- Critical Check Point Vulnerabilities Under Active Exploitation CVE-2026-85102 and CVE-2026-93616

Severity: Critical CVSS Score: 9.8 Affected Vendor: Check Point Software Technologies Exploitation Status: Active exploitation observed Date: 23 September 2026 Overview The Trinidad and Tobago Cyber Security Incident Response Team (TT-CSIRT) is advising organizations and system administrators of two (2) critical vulnerabilities affecting Check Point Security Gateway, Spark Firewall and Security Management products. The vulnerabilities […]

TT-CSIRT – 459.20.07.26 – SharePoint Hardening After New Exploitations (CVE-2026-58644)

Please be advised of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys […]

TT-CSIRT – 458.15.06.26- Critical Authentication bypass vulnerabilities in Palo Alto Networks PAN-OS (CVE-2026-0257)

Please be advised that a critical vulnerability, designated as CVE-2026-0257, has been identified in Palo Alto Networks PAN-OS, specifically affecting the portal and gateway components of the PAN-OS software. Successful exploitation of CVE-2026-0257 may allow threat actors to bypass security controls and establish unauthorized VPN connections. Please note: Palo Alto Networks has confirmed that this […]

TT-CSIRT – 457.10.06.26- Critical Check Point VPN Zero-Day

Please be advised that a critical vulnerability, CVE-2026-50751 has been identified in Check Point Remote Access VPN and Mobile Access solutions. The flaw allows an attacker to bypass user authentication by exploiting a logic weakness in certificate validation during IKEv1 VPN negotiation. This can allow unauthorized users to establish a remote VPN session without valid […]

TT-CSIRT – 456.08.05.26 – CYBERSECURITY ADVISORY: Critical Palo Alto Networks PAN-OS Vulnerability (CVE-2026-0300)

CVE-2026-0300 is a critical buffer overflow vulnerability affecting the User-ID™ Authentication Portal (also known as the Captive Portal) service in PAN-OS. Successful exploitation may allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series and VM-Series firewalls through specially crafted packets. Palo Alto Networks has confirmed that this vulnerability is […]

TT-CSIRT-454.17.04.26: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability (CVE-2026-32201)

Severity: Medium (Elevated due to active exploitation) Overview:A zero-day vulnerability in Microsoft SharePoint Server allows attackers to perform spoofing attacks due to improper input validation. The vulnerability is actively being exploited and can allow unauthorized access to SharePoint environments. Affected Systems:Microsoft SharePoint ServerSharePoint Server 2016SharePoint Server 2019SharePoint Subscription Edition Description:A spoofing vulnerability, tracked as CVE-2026-32201, exists in Microsoft […]

TT-CSIRT – 453.24.09.25 – Shai-Hulud Self-Replicating Worm Supply Chain Compromise

Please be advised, CISA has issued a critical alert regarding a widespread supply chain attack involving npmjs.com, the largest JavaScript package registry. A self-replicating worm named “Shai-Hulud” has compromised over 500 npm packages. After initial access, the attacker deployed malware scans for sensitive credentials such as GitHub Personal Access Tokens (PATs) and cloud service API […]

TT-CSIRT – 452.23.09.25 – Security Alert: New Inboxfuscation Tool That Bypasses Microsoft Exchange Inbox Rules and Evades Detection

Please be aware, newly discovered is a sophisticated new attack framework called Inboxfuscation, developed by Permiso Security to demonstrate critical vulnerabilities in Microsoft Exchange inbox rule detection systems. This Unicode-based obfuscation technique enables the creation of malicious inbox rules that can completely evade traditional security monitoring and detection mechanisms, representing a significant advancement in email-based […]