H-ISAC: White Reports

On August 14, 2026, researchers at watchTowr published a technical write-up and working proof-of-concept exploit for CVE-2026-8452 (CVSS 8.8), a pre-authentication vulnerability in Citrix NetScaler ADC and Gateway.
Fortinet has released security advisories patching multiple vulnerabilities across its product suite, including high-severity authentication flaws in FortiWeb, FortiManager, and FortiClient for Windows.
This report, published once a month, is an in-depth analysis of a geopolitical trend whose cascading consequences adversely impact the healthcare sector.
On June 29, 2026, eSentire’s Threat Response Unit (TRU) identified active, in-the-wild exploitation attempts targeting a critical flaw in Progress Kemp LoadMaster appliances, tracked as CVE-2026-8037.
On May 12, 2026, Ivanti disclosed a critical vulnerability, tracked as CVE-2026-8043, in its Xtraction platform, carrying a near-maximum CVSS score of 9.6.
This report, published once a month, is an in-depth analysis of a geopolitical trend whose cascading consequences adversely impact the healthcare sector.
On March 11, 2026, Cisco released an advisory for IOS XR software, addressing two high-severity vulnerabilities, CVE-2026-20040 and CVE-2026-20046, which allow authenticated users to gain root and administrative access.
Palo Alto Networks Unit 42 recently published a report detailing the active, in-the-wild exploitation of CVE-2026-1731. The vulnerability is a pre-authentication remote code execution (RCE) flaw affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). Threat actors are…
On February 6, 2026, BeyondTrust released a security advisory, disclosing a critical pre-authentication Remote Code Execution (RCE) vulnerability tracked as CVE-2026-1731.