AlphaTechnology IT Networking & Security Consultancy

Weekly security briefing · 2026

The latest in networking & security, week by week

Vulnerabilities, fixes, software updates, hardware, certifications and industry events across the platforms we engineer every day — Fortinet, Check Point, Cisco, Palo Alto, Juniper, F5 and AlgoSec — plus the frontier AI models reshaping security. Curated by AlphaTechnology, with a direct link to the original advisory for every item.

Updated 4 July 2026 Coverage: Week 01 – Week 27
Critical / High CVE Medium CVE Low / informational Software Updates Products & Hardware Certifications Industry event News

No reports match this filter combination

Try removing a filter or selecting a different period.

W27

Exploitation confirmed on Unified CM

29 Jun – 05 Jul
CVE-2026-20230CVSS 8.6CISA KEVCisco02 Jul 2026

Cisco confirms in-the-wild exploitation of Unified CM SSRF

A week after a public proof of concept appeared, Cisco confirmed active exploitation of the SSRF flaw in Unified Communications Manager and Unified CM SME. Crafted HTTP requests can drop arbitrary files on the underlying OS and be leveraged to reach root. Only appliances with the WebDialer service enabled (off by default) are exposed.

Resolution: Upgrade to Unified CM 14SU6 (patched early June); the fix also lands in 15SU5, expected in September. Disable WebDialer where it is not required and hunt for unexpected file writes since early June.

SecurityWeek
CiscoAI defenseJul 2026

Cisco ships “post-Mythos era” Resilient Infrastructure Services

The services announced at Cisco Live become available this month: a three-phase offering built on the premise that AI-enabled attacks have collapsed the exploit window from weeks to minutes. Cisco maps the attack surface, applies compensating controls where immediate patching is impossible, and drives estates to full remediation, alongside quantum-readiness assessments for “harvest now, decrypt later” exposure.

Cisco Executive Platform blog
OpenAIFrontier model29 Jun 2026

OpenAI releases GPT-5.5 with expanded agentic tooling

OpenAI shipped GPT-5.5, extending long-horizon agentic execution and native tool use, with an emphasis on enterprise security reviews and code-audit workflows that echo the frontier-defender race.

OpenAI
Check PointRelease29 Jun 2026

Check Point R82.10 maintenance train ships

The R82.10 maintenance release rolls up the IKEv1 hotfixes and stability improvements for Quantum and Spark gateways.

Check Point
CiscoHardware29 Jun 2026

Cisco unveils the Secure Firewall 1200 series

The compact 1200 series succeeds Firepower 1000 with integrated SD-WAN and an on-box AI assistant for branch sites.

Cisco
Palo AltoBeta29 Jun 2026

Palo Alto opens Cortex XSIAM 3.0 beta

The XSIAM 3.0 beta previews agentic triage and a rebuilt detection engine for early-access customers.

Palo Alto
FortinetFeature29 Jun 2026

Fortinet adds FortiAI SOC analyst

The agentic FortiAI SOC analyst now auto-triages alerts and drafts containment actions across the Security Fabric.

Fortinet
FortinetProgram update29 Jun 2026

Fortinet renews its NSE certification program

The overhaul brings back NSE numbering as exam levels under the FCF, FCA, FCP, FCSS and FCX credentials, with same-track pairing and role tracks for Secure Networking, SASE, Cloud Security and Security Operations.

Fortinet
W26

FortiBleed response & KEV deadlines

22 – 28 Jun
GuidanceFortinet22 Jun 2026

Fortinet responds to FortiBleed: credential reuse, not a new flaw

Fortinet published its position on the FortiBleed dataset, pointing to advisories including FG-IR-25-647 and assessing the activity as credential reuse from earlier incidents combined with brute force against devices lacking MFA and password hygiene, “not related to any recent incident or advisory”. CISA issued a complementary hardening alert. The practical takeaway stands: there is no patch for valid credentials.

Resolution: Rotate all admin and VPN credentials, enforce MFA everywhere, remove management and SSL-VPN exposure from the internet, and enable login-lockout-upon-weaker-encryption on 7.2.x / 7.4.x to purge legacy SHA-256 hashes.

Bitdefender technical advisory
CVE-2026-20230CISA KEVCisco24 Jun 2026

CISA sets urgent 28 June deadline for Unified CM flaw

After threat-detection firm Defused observed exploitation attempts writing arbitrary files to exposed endpoints, CISA added the Unified CM SSRF to the KEV catalog with an unusually short remediation window under BOD 26-04. PTC Windchill / FlexPLM RCE CVE-2026-12569 received the same 28 June deadline.

Resolution: Patch Unified CM to 14SU6 or apply vendor mitigations before the deadline; treat internet-reachable instances as priority one.

BleepingComputer
FortinetRelease22 Jun 2026

FortiOS 7.6.2 reaches general availability

Fortinet shipped FortiOS 7.6.2 as the recommended mature release, rolling up the FortiBleed hardening (PBKDF2 hashing, login lockout) and stability fixes across FortiGate, FortiProxy and FortiSASE.

Fortinet Docs
FortinetHardware22 Jun 2026

Fortinet launches the FortiGate 700G campus firewall

Built on the fifth-generation NP7 and CP9 ASICs, the FortiGate 700G targets campus edge deployments with multi-hundred-Gbps firewall throughput, integrated FortiAI and a native SASE onramp.

Fortinet
GoogleFrontier model22 Jun 2026

Google makes Gemini 3 generally available

Google DeepMind brought Gemini 3 to general availability across Workspace and Vertex AI, pushing multimodal reasoning and a hardened enterprise tier with data-residency and agent-governance controls.

Google DeepMind
JuniperRelease22 Jun 2026

Juniper Mist adds Marvis Actions AI update

The cloud update expands Marvis self-driving actions and AI root-cause across wired, wireless and WAN.

Juniper
Check PointHardware22 Jun 2026

Check Point unveils Quantum Rugged 1600

The ruggedised 1600 gateway targets OT and industrial edges with hardened enclosures and SCADA-aware inspection.

Check Point
W25

FortiBleed goes public

15 – 21 Jun
Campaign · no CVEFortinet15–19 Jun 2026

FortiBleed: cracked admin credentials for tens of thousands of FortiGates

Researchers uncovered a mass credential-compromise operation against internet-facing FortiGate firewalls and SSL-VPN gateways across 194 countries. Attackers harvested configuration files and cracked legacy SHA-256 password hashes; by 19 June validated credentials existed for roughly 86,600 devices, with SOCRadar confirming a database of 30,000+ working admin logins organized by country and sector. Because the logins are valid, no exploit signature fires.

Resolution: FortiOS 7.2.11 / 7.4.8 / 7.6.1 introduced PBKDF2 hashing, but old hashes persist until each admin logs in post-upgrade. Force those logins, rotate every admin and VPN credential, enforce MFA, and restrict management interfaces to trusted networks.

Arctic Wolf
CVE-2026-0266MediumPalo Alto15 Jun 2026

PAN-OS stored XSS in the management web interface

A malicious authenticated administrator can persist a JavaScript payload via the PAN-OS web UI on PA-Series, VM-Series and Panorama. Cloud NGFW and Prisma Access are not affected. Low urgency, but relevant wherever admin roles are delegated broadly.

Resolution: Upgrade to the fixed PAN-OS maintenance releases listed in the advisory and review admin role assignments.

Palo Alto Networks advisory
CiscoRelease · EoS15 Jun 2026

Cisco IOS XE 17.15.1 ships; 17.9 marked end-of-maintenance

The new extended-maintenance IOS XE 17.15.1 lands for Catalyst switching and SD-WAN edge, while Cisco set the end-of-software-maintenance date for the 17.9 train, pushing estates to plan upgrades before support lapses.

Cisco
CiscoEnd-of-life15 Jun 2026

Cisco announces end-of-life for the Firepower 1000 series

Cisco published the end-of-sale and end-of-life milestones for the Firepower 1000 appliances, steering customers toward the Secure Firewall 1200 series; the last day of support runs into 2030.

Cisco
MetaOpen weights15 Jun 2026

Meta publishes the Llama 4.2 open-weight models

Meta released the Llama 4.2 family under open weights, adding a long-context mixture-of-experts variant that security teams are already fine-tuning for on-prem detection and triage use cases.

Meta AI
Check PointRelease15 Jun 2026

Check Point ships Harmony Endpoint update

The endpoint release adds AI-driven behavioural detection and lighter agents for managed Windows and macOS fleets.

Check Point
Palo AltoFeature15 Jun 2026

Palo Alto extends Prisma AIRS AI security

Prisma AIRS adds runtime protection for enterprise AI agents, models and MCP tools against prompt-based attacks.

Palo Alto
W24

Check Point zero-day & Fable 5 launch

08 – 14 Jun
CVE-2026-50751CVSS 9.3CISA KEVCheck Point08 Jun 2026

Check Point IKEv1 VPN authentication bypass exploited by Qilin affiliate

A logic flaw in certificate validation for the deprecated IKEv1 key exchange lets an unauthenticated attacker establish a Remote Access or Mobile Access VPN session without a valid password. Exploitation dates back to 7 May across a few dozen organizations, with one intrusion tied to a Qilin ransomware affiliate whose infrastructure also targets Palo Alto, Fortinet and F5 VPN flaws. Spark firewalls are affected too. CISA added it to KEV with a three-day deadline. A second issue found during the investigation, CVE-2026-50752 (CVSS 7.4, IKEv1 site-to-site MITM), was fixed in the same hotfix.

Resolution: Install the hotfix takes from sk185033 (R81.20, R82, R82.10 Jumbo and Spark builds); R81.10 and older are end of support and need an upgrade path. Audit VPN logs and configuration history back to 7 May, and retire IKEv1 where possible.

Check Point blog / sk185033
AnthropicFrontier AI09 Jun 2026

Claude Fable 5 goes GA; Mythos 5 reaches vetted cyberdefenders

Anthropic released Claude Fable 5, the first Mythos-class model made generally available, with safeguards that reroute offensive-cyber and biology requests to the less capable Opus 4.8 (triggered in under 5% of sessions). The unrestricted Claude Mythos 5 went to Project Glasswing partners and select defenders, deployed in collaboration with the US government. Both are priced at 10 / 50 dollars per million input / output tokens.

SecurityWeek
CVE-2026-25089CVSS 9.8FortinetJun 2026

FortiSandbox: unauthenticated OS command injection patched

Fortinet fixed a critical, remotely exploitable command-injection flaw in the FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS web UI, the most severe of the month’s PSIRT batch. No in-the-wild exploitation was reported at disclosure. Ivanti patched a CVSS 10 Sentry command injection (CVE-2026-10520) the same week, keeping the pressure on edge appliances.

Resolution: Update FortiSandbox to the fixed releases in the June PSIRT advisories and keep the management UI off the internet.

SecurityWeek
CVE-2026-20262CVSS 6.5Cisco11 Jun 2026

SD-WAN Manager file-write flaw becomes the eighth exploited this year

Cisco patched a Catalyst SD-WAN Manager web-UI weakness that lets an authenticated user with write access create or overwrite arbitrary files and pivot to root; limited exploitation was observed in June, including a malicious “suspicious.war” deployment in shared IOCs. It joins seven other SD-WAN flaws flagged as exploited in 2026.

Resolution: Apply the fixed SD-WAN Manager releases, review deployment and service-proxy logs for unexpected WAR files, and keep controller access restricted to management networks.

The Hacker News
Palo AltoBeta / EA08 Jun 2026

PAN-OS 12.0 opens its early-availability preview

Palo Alto Networks opened the PAN-OS 12.0 early-availability program, previewing an AI-assisted policy analyzer and a dedicated cookie-signing certificate on by default; production GA is expected later in the year.

Palo Alto Networks
AppleOn-device AI08 Jun 2026

Apple Intelligence expands with a larger on-device model

At WWDC, Apple detailed a larger on-device foundation model and opened its models to third-party apps through an expanded framework, keeping inference private on Apple silicon.

Apple
JuniperHardware08 Jun 2026

Juniper launches the QFX5240 800G switch

The QFX5240 brings 800GbE data-center fabric density on Trio silicon with Apstra-driven intent networking.

Juniper
F5Release08 Jun 2026

F5 updates Distributed Cloud WAAP

The SaaS update improves bot defence and API discovery and adds tighter policy sync with BIG-IP estates.

F5
F5Feature08 Jun 2026

F5 adds AI Gateway to Distributed Cloud

The new AI Gateway secures and load-balances LLM traffic with prompt inspection and token-aware rate limiting.

F5
Palo AltoProgram update08 Jun 2026

Palo Alto moves to a role-based certification framework

After retiring the PCNSE, Palo Alto's role-based tracks such as NGFW Engineer and Network Security Architect span Foundational to Architect levels, with exams now delivered in person only at Pearson VUE.

Palo Alto
W23

Cisco Live, Glasswing expansion & two Cisco zero-days

01 – 07 Jun
CiscoEventEarly Jun · Las Vegas

Cisco Live 2026: Cloud Control, Cisco IQ and the agentic network

Cisco’s flagship event centered on Cloud Control, an agentic management plane that takes operators from a single prompt to cross-domain troubleshooting, with zero trust, identity intelligence and AI guardrails built in, plus Splunk data unification for machine-speed response. Keynotes framed AI as both the attack accelerant and the defense, with Cisco IQ extending agentic operations into regulated and air-gapped environments.

Cisco Newsroom keynote recap
AnthropicFrontier AI02 Jun 2026

Project Glasswing expands to ~150 organizations; Claude Security released

Anthropic extended its trusted-access program for Mythos-class capability to roughly 150 new organizations in more than fifteen countries, adding power, water, healthcare, communications and hardware vendors whose compromise could affect over 100 million people each. Alongside it, Claude Security launched: codebase scanning and patch suggestions powered by public frontier models. Dragos, Tenable, Trend Micro, Netskope, BeyondTrust, Rubrik, BT and Hitachi confirmed participation.

Anthropic
CVE-2026-20245CVSS 7.8Cisco04 Jun 2026

SD-WAN Manager privilege escalation was exploited two months before disclosure

Cisco disclosed a CLI input-validation flaw in Catalyst SD-WAN Controller and Manager allowing an authenticated local attacker to run commands as root via a crafted CSV upload. Google Mandiant later showed exploitation as early as March, with the actor cleaning up files and reverting configs to erase traces, part of the “living off the edge” pattern. Cisco also patched the critical Unified CM SSRF (CVE-2026-20230) on 3 June, before exploitation began.

Resolution: Upgrade all Catalyst SD-WAN deployments (on-prem, cloud and FedRAMP) to fixed releases, and forensically review orchestrator activity back to March: peering events, config reverts and CSV uploads.

Infosecurity Magazine
AlgoSecFeature · Beta01 Jun 2026

AlgoSec Horizon adds AI application discovery, opens agentic beta

Horizon's new AI-driven application-discovery module reached general availability, mapping flows to business applications automatically; AlgoSec also opened a private beta for an agentic change-automation assistant.

AlgoSec
JuniperRelease01 Jun 2026

Juniper releases Junos 24.2R2 across MX and SRX

The service release addresses IKE and routing-daemon fixes and adds inline flow telemetry to the MX and SRX lines.

Juniper
FortinetBeta01 Jun 2026

Fortinet opens FortiOS 7.8 preview

The FortiOS 7.8 early preview showcases deeper agentic FortiAI automation and generative-AI governance controls.

Fortinet
CiscoHardware01 Jun 2026

Cisco launches Catalyst 9350 switches

The Catalyst 9350 access switches add high-density multi-gig, UPOE++ and built-in Cisco AI Assistant hooks.

Cisco
Check PointExam update01 Jun 2026

Check Point refreshes CCSA and CCSE for R82

The updated Certified Security Administrator and Expert exams align with R82, adding AI-assisted operations, Infinity and cloud-security content.

Check Point
W22

GlobalProtect flaw escalates

25 – 31 May
CVE-2026-0257CISA KEVPalo Alto29 May 2026

Public PoC lands for GlobalProtect bypass; PAN confirms exploitation

A proof of concept for the GlobalProtect authentication-override cookie bypass was released on 29 May, and Palo Alto Networks confirmed limited exploitation against unpatched, unmitigated devices. CISA’s KEV deadline was set at 1 June. Notably, PAN says it found the flaw internally using frontier AI tools, a live example of AI-assisted code auditing beating attackers to a bug, if only by days.

Resolution: Upgrade every portal and gateway to the fixed PAN-OS builds (users re-authenticate once as cookies are regenerated), or as interim mitigation use a dedicated cookie certificate or disable authentication override.

Unit 42 threat brief
JuniperHardware · Feature25 May 2026

Juniper ships the PTX10002-36QDD with 800G-native routing

The new fixed PTX10002-36QDD brings 800GbE-native core and peering density on Express 5 silicon, alongside Junos Evolved features for inline flow telemetry and post-quantum-ready MACsec.

Juniper
AlgoSecRelease25 May 2026

AlgoSec Horizon A34.00 rolls out

The A34.00 platform release adds broader multi-cloud connectivity and refreshed compliance packs for NIS2 and DORA.

AlgoSec
CiscoRelease25 May 2026

Cisco ships Meraki firmware MR 30.x

The cloud firmware brings Wi-Fi 7 improvements and AIOps insights to Meraki MR access points.

Cisco
FortinetHardware25 May 2026

Fortinet ships FortiGate 3800G

The data-center FortiGate 3800G delivers terabit firewalling with fifth-gen ASICs and hardware-accelerated SASE.

Fortinet
JuniperProgram update25 May 2026

Juniper aligns certifications under HPE and grows its Mist AI track

Following the HPE acquisition, Juniper streamlines its JNCIA to JNCIE tracks and expands the AI-Native Networking and Mist certifications for campus and data-center roles.

Juniper
W21

First GlobalProtect victims

18 – 24 May
CVE-2026-0257CVSS 7.8Palo Alto17 & 21 May 2026

Rapid7 observes two exploitation waves against GlobalProtect

Days after disclosure, Rapid7 recorded successful bypasses across multiple customer environments, with a first wave on 17 May and a second on 21 May attributed to the same actor; in two cases the attacker obtained a VPN IP assignment and internal network reach. The pattern echoes the year’s theme: edge VPN flaws are weaponized within days of publication.

Resolution: Patch on an emergency basis and hunt GlobalProtect logs for gateway-connected events with anomalous host IDs and device names.

CyberScoop
Nvidia · OracleAI compute18 May 2026

Nvidia and Oracle expand sovereign AI-compute capacity

Nvidia's next-generation accelerators began shipping into Oracle Cloud's expanded AI regions, part of a wave of sovereign-compute buildouts that underpin the frontier-model and security-tooling boom.

Nvidia
FortinetRelease18 May 2026

Fortinet ships FortiManager and FortiAnalyzer 7.6.2

The management-plane update aligns policy automation with FortiOS 7.6 and adds agentic FortiAI incident summaries.

Fortinet
F5Hardware18 May 2026

F5 expands VELOS with a new high-density blade

The new BX-series blade doubles VELOS chassis throughput and adds hardware SSL offload for large service providers.

F5
JuniperRelease18 May 2026

Juniper releases Paragon Automation 24.2

The automation suite adds closed-loop assurance and expanded device onboarding for service-provider networks.

Juniper
Check PointFeature18 May 2026

Check Point adds Infinity AI Copilot skills

The Infinity AI Copilot gains new skills for policy authoring, incident summaries and guided troubleshooting.

Check Point
CiscoExam update18 May 2026

Cisco launches CCNA v2.0 with an AI-first blueprint

The biggest CCNA revision in years adds a security-first mindset and a pillar on AI in network operations, while the CCIE lab now includes a mandatory AI-assisted troubleshooting module.

Cisco
W20

The heaviest patch week of the year

11 – 17 May
CVE-2026-20182CVSS 10.0CISA KEVCisco14 May 2026

Maximum-severity SD-WAN Controller zero-day exploited by UAT-8616

Cisco patched a peering-authentication bypass in Catalyst SD-WAN Controller and Manager that grants remote attackers high-privileged access via crafted packets, exploited since mid-April by the UAT-8616 cluster to register rogue peers inside SD-WAN fabrics. It was the sixth exploited SD-WAN flaw of 2026; Talos documented ten activity clusters delivering miners, stealers and webshells through the family. CISA gave agencies three days.

Resolution: Upgrade to fixed releases (no workaround exists), restrict control-plane and management interfaces to trusted networks, and validate every peering event in controller logs against change records.

BleepingComputer
CVE-2026-0257 · CVE-2026-02657.8 / 7.2Palo Alto13 May 2026

PAN-OS May advisories: GlobalProtect and Cloud Authentication Service bypasses

Palo Alto’s monthly drop included two authentication bypasses: CVE-2026-0257 abuses reused certificates behind GlobalProtect authentication-override cookies to establish unauthorized VPN sessions, while CVE-2026-0265 lets an unauthenticated attacker bypass login on interfaces with Cloud Authentication Service enabled on PA-Series, VM-Series and Panorama.

Resolution: Patch per the product-status tables (remaining 0265 streams landed 28 May). Interim: dedicated certificate for auth-override cookies, or disable the feature; verify whether any CAS-enabled auth profile is attached to a login interface.

Palo Alto Networks advisory
CVE-2026-42945 +50CVSS 9.2F513 May 2026

F5 May quarterly: 51 fixes across BIG-IP, BIG-IQ and NGINX

F5’s Q2 notification resolved 19 high and 32 medium issues. The standout is CVE-2026-42945, a heap overflow in NGINX’s rewrite module that crashes workers and can reach code execution if ASLR is off; CVE-2026-41225 (8.6) allows command execution via iControl REST for Manager-role users, plus three authenticated RCE / command-injection bugs in BIG-IP. Nothing exploited in the wild at publication.

Resolution: Apply the K000160932 release matrix during the next maintenance window, prioritizing internet-facing NGINX and any BIG-IP with broad iControl REST role assignments.

SecurityWeek / K000160932
F5End-of-life11 May 2026

F5 confirms BIG-IP 15.1.x end-of-software-development

F5 published the end-of-software-development notice for the BIG-IP 15.1.x branch, with technical support ending in 2027; customers are advised to migrate to 17.5.x or the new 21.x line.

F5
Check PointHardware11 May 2026

Check Point debuts the Quantum Force 19000 appliance

The data-center Quantum Force 19000 targets high-throughput AI-era workloads with terabit firewalling and Maestro scaling.

Check Point
AlgoSecRelease11 May 2026

AlgoSec releases ASMS A33.60

The on-prem suite update refreshes risk analytics and adds new device support for hybrid firewall estates.

AlgoSec
JuniperHardware11 May 2026

Juniper unveils PTX10008 line card

A new Express 5 line card boosts PTX10008 core and peering density with native 800GbE and inline MACsec.

Juniper
W19

PAN-OS Captive Portal RCE

04 – 10 May
CVE-2026-0300CVSS 9.3CISA KEVPalo Alto06 May 2026

Unauthenticated root RCE in the PAN-OS User-ID Authentication Portal

A buffer overflow in the Captive Portal service (ports 6081 / 6082) allows crafted packets to trigger an out-of-bounds write and execute code as root. Palo Alto confirmed limited in-the-wild exploitation against exposed instances and CISA added the flaw to KEV on 6 May. Wiz measured publicly exposed PAN-OS in about 7% of environments.

Resolution: Upgrade to the fixed PAN-OS releases and never expose the Authentication Portal to untrusted networks; verify 6081 / 6082 reachability from the internet as the primary exploitability check.

Wiz research
CiscoRelease04 May 2026

Cisco releases NX-OS 10.5(2) for Nexus

The data-center release adds telemetry and automation improvements for Nexus 9000 fabrics plus assorted security fixes.

Cisco
AlgoSecFeature04 May 2026

AlgoSec brings CloudFlow risk remediation to GA

CloudFlow's guided risk-remediation for cloud security groups reaches general availability across AWS, Azure and GCP.

AlgoSec
Palo AltoRelease04 May 2026

Palo Alto ships PAN-OS 11.1.6 maintenance

The maintenance build resolves Captive Portal and User-ID issues and refreshes content-update handling.

Palo Alto
F5Feature04 May 2026

F5 adds API security to Distributed Cloud

New API-security features add automated discovery, schema enforcement and abuse detection for exposed APIs.

F5
AlgoSecProgram update04 May 2026

AlgoSec updates its certification and enablement program

AlgoSec refreshes its certified-professional curriculum around the Horizon platform, adding application-centric policy and cloud-security modules.

AlgoSec
W17

SD-WAN campaign widens

20 – 26 Apr
CVE-2026-20133CISA KEVCisco20 Apr 2026

CISA adds a fourth exploited Catalyst SD-WAN flaw to KEV

CISA updated its ongoing SD-WAN alert to add CVE-2026-20133 to the Known Exploited Vulnerabilities catalog, extending the global campaign first flagged in February under Emergency Directive 26-03. The mid-April timeframe also marks the earliest observed exploitation of what would later be disclosed as CVE-2026-20182.

Resolution: Follow the ED 26-03 sequence: inventory SD-WAN systems, capture snapshots and logs for threat hunting, patch to fixed releases, then hunt using the joint CISA / NSA / international threat-hunt guide.

CISA joint alert
Palo AltoRelease20 Apr 2026

Palo Alto refreshes Prisma Access cloud

The rolling cloud update brings AI-powered app acceleration and tightened default posture for the SASE service.

Palo Alto
FortinetHardware20 Apr 2026

Fortinet launches FortiAP Wi-Fi 7 access points

The new FortiAP 4xxK series adds Wi-Fi 7 throughput with tighter integration into the FortiGate-secured LAN edge.

Fortinet
Check PointRelease20 Apr 2026

Check Point updates CloudGuard posture

The CloudGuard update expands CNAPP coverage with AI risk scoring across AWS, Azure and GCP workloads.

Check Point
Palo AltoFeature20 Apr 2026

Palo Alto expands Cortex Cloud runtime

Cortex Cloud adds unified CNAPP runtime protection with agentic remediation across multi-cloud estates.

Palo Alto
FortinetRetirement20 Apr 2026

Fortinet retires legacy NSE exam versions

Older 7.2 and 7.4 exam versions are retired as Fortinet consolidates its tracks; existing certifications stay valid until expiry and renew with the new exams.

Fortinet
W15

Mythos Preview & Juniper quarterly

06 – 12 Apr
AnthropicFrontier AI07 Apr 2026

Claude Mythos Preview: n-day exploits in hours, thousands of new vulnerabilities found

Anthropic published its cybersecurity assessment of Mythos Preview, the restricted model behind Project Glasswing. Against roughly 7,000 OSS-Fuzz entry points it achieved full control-flow hijack on ten fully patched targets where prior frontier models managed almost none, and it surfaced thousands of high and critical vulnerabilities now moving through coordinated disclosure, with expert reviewers agreeing with the model’s severity call in 89% of sampled reports. The industry conversation about patch-window economics changed in one week.

Anthropic Red Team
2026-04 bulletinMultipleJuniper08–09 Apr 2026

Juniper April security bulletins: 25+ CVEs across Junos and Junos Evolved

The quarterly cycle addressed DoS, privilege escalation, information disclosure and filter-bypass issues, including CVE-2026-33778 where a malformed first ISAKMP packet crashes kmd / iked on SRX and MX platforms, plus lo0 and IRB egress-filter enforcement bugs relevant to anyone using firewall filters as a control plane guard.

Resolution: Apply the fixed Junos / Junos Evolved releases from the 2026-04 bulletins; prioritize IKE-terminating SRX clusters and boxes relying on lo0 filters in the default routing instance.

Juniper 2026-04 bulletins (via HKCERT)
F5Release06 Apr 2026

F5 ships NGINX Plus R34

NGINX Plus R34 lands on the 1.29 core with HTTP/3 refinements and native OpenTelemetry for app-delivery fleets.

F5
CiscoEnd-of-life06 Apr 2026

Cisco announces end-of-life for Catalyst 9200L

Cisco published end-of-sale and end-of-life milestones for the Catalyst 9200L switches, pointing to the 9300X line.

Cisco
JuniperRelease06 Apr 2026

Juniper Apstra 5.1 adds intent assurance

Apstra 5.1 broadens multivendor data-center automation with richer intent validation and drift remediation.

Juniper
JuniperFeature06 Apr 2026

Juniper Mist adds Wired Assurance AI

Wired Assurance gains AI-native switch health and Marvis conversational troubleshooting for campus fabrics.

Juniper
F5Exam update06 Apr 2026

F5 revamps the BIG-IP Administrator certification

The refreshed F5 Certified Administrator, BIG-IP replaces two 90-minute exams with five 30-minute topic exams, and F5 begins offering online-proctored delivery via Certiverse.

F5
W14

Cisco IMC batch

30 Mar – 05 Apr
CVE-2026-20093CriticalCisco02 Apr 2026

Ten IMC flaws fixed, led by an authentication bypass that changes admin passwords

Cisco patched ten vulnerabilities in the Integrated Management Controller of UCS C-Series servers, including CVE-2026-20093, where a crafted HTTP request abuses password-change handling to seize the BMC, below the OS and every EDR / SIEM control. Four companion bugs allow authenticated root command execution and five are XSS. Many Cisco appliances built on UCS C-Series (APIC, Secure Firewall Management Center and others) inherit the exposure. No exploitation observed.

Resolution: Install the April IMC updates (no workarounds exist) and treat out-of-band management as a Tier-0 asset: never internet-facing, strictly segmented, VPN or zero-trust access only.

Help Net Security
Check PointRelease30 Mar 2026

Check Point pushes Quantum Spark firmware update

The SMB firmware update hardens IKEv1 handling and improves cloud management for Quantum Spark appliances.

Check Point
Palo AltoHardware30 Mar 2026

Palo Alto announces the PA-1500 series

The new PA-1500 branch firewalls roughly double throughput over the PA-1400 while keeping the single-slot form factor.

Palo Alto
CiscoRelease30 Mar 2026

Cisco releases ISE 3.4 patch

The identity-services patch improves posture assessment and adds resilience for large policy deployments.

Cisco
AlgoSecFeature30 Mar 2026

AlgoSec adds NIS2 compliance reporting

A new out-of-the-box pack adds NIS2 and DORA compliance reporting mapped to firewall and cloud policy state.

AlgoSec
W13

RSAC 2026

23 – 29 Mar
EventAI theme23–26 Mar · San Francisco

RSAC 2026 turns 35: the agentic enterprise takes center stage

The 35th RSAC Conference at Moscone drew 700+ speakers and 600+ exhibitors under the theme “Power of Community”. Agentic AI dominated: Cisco’s Jeetu Patel argued security must protect agents from the world, protect the world from agents, and respond at machine speed, while the Innovation Sandbox crown went to Geordie AI for real-time visibility and governance of enterprise AI-agent footprints. Fortinet, Check Point, F5 and the rest of the vendor landscape exhibited.

RSAC press release
AlgoSecRecognition25 Mar 2026

AlgoSec Horizon wins the 2026 SC Award for risk and policy management

Horizon took Best Risk / Policy Management Solution at the SC Awards for its application-centric, AI-assisted approach to policy automation across virtual, cloud and physical estates, following a Globee Gold and a Global InfoSec award for AI-powered cybersecurity earlier in the month. Useful validation for teams standardizing multi-vendor policy hygiene on the platform.

SC Media
JuniperEnd-of-support23 Mar 2026

Juniper sets Junos 21.4 end-of-engineering

The 21.4 train reaches end-of-engineering, with Juniper steering customers to 23.4R2 or the 24.x releases.

Juniper
F5End-of-life23 Mar 2026

F5 sets BIG-IP iSeries end-of-sale

F5 published end-of-sale dates for several BIG-IP iSeries appliances, steering customers to the rSeries platform.

F5
FortinetRelease23 Mar 2026

Fortinet updates FortiSASE cloud

The FortiSASE update expands global PoPs and adds unified ZTNA and inline CASB with agentic monitoring.

Fortinet
Check PointHardware23 Mar 2026

Check Point ships Maestro Hyperscale 2

The next-gen Maestro orchestrator scales gateways into multi-terabit security groups for large data centers.

Check Point
W11

Fortinet Accelerate 2026

09 – 15 Mar
FortinetEvent09–13 Mar · Las Vegas

Accelerate 2026: FortiOS 8.0 and agentic FortiAI headline Mandalay Bay

Fortinet’s flagship event marked 25 years of FortiOS with the 8.0 release, positioning AI-native controls for generative-AI governance directly in the fabric. The FortiAI story shifted from assistant to agentic: autonomous alert triage, risk-based prioritization and containment playbooks that execute without waiting for an analyst, plus multimodal input up to topology-diagram uploads. Ken Xie set the tone: security operations must run at the same speed and coordination as the attackers. Customer sessions came from Lowe’s, TJX, Adobe, the International Red Cross and ExxonMobil.

Field report: Forge Technologies
CiscoResearch11 Mar 2026

Rapid7 publishes the full root cause of CVE-2026-20127

Rapid7 Labs detailed how the February SD-WAN Controller authentication bypass lets an attacker inject a malicious SSH key and reach the NETCONF service, the mechanism behind the rogue-peer intrusions. Essential reading for anyone writing detections around Catalyst SD-WAN control-plane events.

Rapid7 analysis
AlgoSecRelease09 Mar 2026

AlgoSec FireFlow gains cloud-native work orders

The change-management release adds native work-order support for AWS, Azure and GCP firewall policies.

AlgoSec
Check PointFeature09 Mar 2026

Check Point adds Harmony SASE private-access controls

New Harmony SASE capabilities extend zero-trust private access with device posture and agentless clientless options.

Check Point
F5Release09 Mar 2026

F5 ships NGINX Ingress Controller 4.0

The Kubernetes ingress release adds gateway-API support and stronger mTLS defaults for containerised apps.

F5
CiscoFeature09 Mar 2026

Cisco adds AI Defense to Secure Access

Cisco AI Defense extends its SSE with model validation and runtime guardrails for enterprise generative-AI use.

Cisco
W09

Two edge zero-days in one day

23 Feb – 01 Mar
CVE-2026-20127CriticalCISA KEVCisco25 Feb 2026

Catalyst SD-WAN Controller auth bypass exploited; CISA issues Emergency Directive 26-03

Cisco disclosed an authentication bypass in Catalyst SD-WAN Controller and Manager exploited in the wild by UAT-8616, who downgraded compromised systems to re-expose CVE-2022-20775 and escalate to root. CISA added both CVEs to KEV the same day, gave federal agencies roughly 48 hours, and co-published a threat-hunt guide with NSA, ACSC, the Canadian Cyber Centre, NCSC-NZ and NCSC-UK.

Resolution: Upgrade per branch: 20.9.8.2, 20.12.5.3 / 20.12.6.1, or 20.15.4.2 and above; anything below 20.9 must migrate. Manually validate every control-connection peering event against maintenance windows and documented device assignments.

CISA joint alert
CVE-2026-21902CriticalJuniper25 Feb 2026

Junos OS Evolved on PTX: unauthenticated remote code execution as root

An out-of-cycle Juniper bulletin fixed an incorrect-permission flaw in the On-Box Anomaly detection framework of Junos OS Evolved on PTX Series: an internal REST service that schedules shell-command workflows was reachable on an externally exposed port, handing a network-based attacker code execution as root on core and peering routers. watchTowr later demonstrated how directly the command DAGs could be driven.

Resolution: Upgrade to 25.4R1-S1-EVO or the equivalent fixed EVO releases per the bulletin, and filter management-plane reachability on PTX platforms in the interim.

watchTowr Labs
FortinetRelease23 Feb 2026

Fortinet publishes FortiOS 7.4.9 mature release

The recommended 7.4.9 build consolidates SSL-VPN hardening and PBKDF2 password migration for the 7.4 branch.

Fortinet
JuniperHardware23 Feb 2026

Juniper introduces the ACX7020 metro router

The compact ACX7020 brings 400G metro-aggregation and hardened timing for 5G transport and edge deployments.

Juniper
CiscoRelease23 Feb 2026

Cisco releases Catalyst SD-WAN 20.15

The SD-WAN release hardens controller peering after the year's incidents and adds AI-driven path insights.

Cisco
FortinetHardware23 Feb 2026

Fortinet ships FortiManager 3000G appliance

The high-capacity management appliance scales policy orchestration and analytics for very large Fabric deployments.

Fortinet
W08

CPX becomes Engage

16 – 22 Feb
Check PointEventFeb 2026

Check Point retires the single CPX and launches the Engage 2026 world tour

Instead of one flagship CPX per region, Check Point announced Engage 2026: a two-day format travelling to roughly ten global cities through the year, aimed at both executives and practitioners. Tracks cover Hybrid Mesh Network Security, Workspace Security, AI Security and Exposure Management, with 2026 roadmap previews from the executive team. CheckMates reaction was mixed; deep-technical R82.10 content remains concentrated in the community webinars.

Check Point CheckMates
CiscoPatch16 Feb 2026

Cisco issues IOS XE 17.12 maintenance rebuild

The maintenance rebuild ships cumulative security fixes for Catalyst switching and wireless controllers.

Cisco
AlgoSecFeature16 Feb 2026

AlgoSec AppViz gains AI application mapping

AppViz adds AI-assisted discovery that infers business-application connectivity from live flows to speed rule recertification.

AlgoSec
JuniperRelease16 Feb 2026

Juniper releases Junos Space 24.1

The management platform update improves device lifecycle workflows and hardens role-based access control.

Juniper
F5Hardware16 Feb 2026

F5 launches rSeries r10000 appliance

The high-end r10000 brings F5OS tenancy and hardware acceleration to demanding service-provider app delivery.

F5
W06

F5 quarterly & the state of network security

02 – 08 Feb
CVE-2026-22548 · CVE-2026-1642CVSS 8.2F504 Feb 2026

F5 February quarterly: WAF process crash, NGINX MitM injection, SMTP exposure

The Q1 notification fixed a bd-process DoS in BIG-IP Advanced WAF / ASM (CVSS 4.0 score 8.2), an NGINX flaw letting a man-in-the-middle inject responses on proxied upstream TLS, and issues in Container Ingress Services and Edge Client. F5 also flagged a BIG-IP SMTP configuration exposure (K000156643) enabling unauthorized relay.

Resolution: Patch per K000159076 and apply the SMTP configuration hardening introduced in 17.5.1.4 / 21.0.0.1; prioritize virtual servers running AWAF / ASM policies.

SecurityWeek / K000159076
CVE-2026-20119HighCisco04 Feb 2026

TelePresence and RoomOS DoS via a crafted meeting invite

A remote, unauthenticated attacker can knock over TelePresence CE and RoomOS endpoints simply by sending a malicious meeting invitation; Cisco fixed it alongside a Meeting Management input-validation bug (CVE-2026-20098) exploitable by authenticated users.

Resolution: Update to CE / RoomOS 11.27.5.0 or 11.32.3.0 and Meeting Management 3.12.1 MR.

SecurityWeek
AlgoSecReport04 Feb 2026

2026 State of Network Security: AI attacks reshape strategy, Fortinet edges Cisco in SD-WAN

AlgoSec’s vendor-agnostic survey of 500+ professionals across 28 countries found 65% have already adapted their security strategy to AI-powered attacks, consolidation replacing sprawl as the dominant architecture goal, Fortinet becoming the most used SD-WAN at 31% just ahead of Cisco at 30.7%, and organizations without any SASE solution dropping to 27.5%.

AlgoSec report
Palo AltoRelease02 Feb 2026

Palo Alto ships PAN-OS 11.2.5 maintenance

The maintenance build resolves management-UI and GlobalProtect issues and refreshes threat-prevention content handling.

Palo Alto
FortinetHardware02 Feb 2026

Fortinet ships the FortiSwitch 700 series

The FortiSwitch 700 access line adds multi-gig PoE and tighter Security Fabric integration for the secured LAN edge.

Fortinet
AlgoSecRelease02 Feb 2026

AlgoSec releases Prevasio update

The agentless cloud-security update expands container and IaC scanning with prioritised attack-path analysis.

AlgoSec
CiscoHardware02 Feb 2026

Cisco unveils Nexus 9800 spine switch

The modular Nexus 9800 spine adds 800G data-center fabric density with Silicon One and telemetry at scale.

Cisco
CiscoProgram update02 Feb 2026

Cisco migrates DevNet certifications into the Automation track

Active DevNet certifications automatically move to CCNA, CCNP and CCIE Automation, with revamped exams emphasising infrastructure-as-code and AI-ready networking.

Cisco
W05

FortiCloud SSO bypass, formalized

26 Jan – 01 Feb
CVE-2026-24858CVSS 9.4CISA KEVFortinet27 Jan 2026

FortiCloud SSO authentication bypass across FortiOS, FortiManager and FortiAnalyzer

The abuse seen the previous week received its CVE: any attacker holding a FortiCloud account and one registered device could log in to other customers’ devices wherever FortiCloud SSO was enabled, even on units already patched for December’s CVE-2025-59718 / 59719. Fortinet globally disabled FortiCloud SSO on 26 January and restored it a day later only for patched devices; CISA added the flaw to KEV on 27 January with a 30 January federal deadline. FortiWeb and FortiProxy are also in scope.

Resolution: Upgrade all affected products per FG-IR-26-060. Where IoCs are present, treat the device as breached: restore a known-clean configuration, rotate local and connected LDAP / AD credentials, and keep management access behind local-in policies.

CISA guidance / FG-IR-26-060
F5Release26 Jan 2026

F5 releases BIG-IP 17.5.1 point release

The point release rolls up Advanced WAF, iControl REST and SMTP configuration fixes across the platform.

F5
CiscoFeature26 Jan 2026

Cisco Meraki adds cloud-managed SD-WAN plus

Meraki introduced an SD-WAN Plus tier with AIOps path selection and unified policy across MX and Catalyst edges.

Cisco
FortinetRelease26 Jan 2026

Fortinet updates FortiSwitchManager

The switch-management update improves fabric provisioning and adds richer PoE analytics for the secured LAN.

Fortinet
AlgoSecFeature26 Jan 2026

AlgoSec Horizon adds risk dashboards

New executive risk dashboards roll up application, cloud and firewall exposure into board-ready security posture views.

AlgoSec
W04

SSO abuse detected & Horizon A33.20

19 – 25 Jan
Pre-CVE activityFortinet21–23 Jan 2026

Malicious configuration changes on FortiGates via FortiCloud SSO accounts

Arctic Wolf reported unexpected SSO logins creating local admin accounts and exfiltrating configurations, including on devices fully patched at the time, pointing to a new attack path. Fortinet’s PSIRT confirmed the investigation on 22 January and disabled the abused FortiCloud accounts on 23 January, recommending local-in policies to restrict administrative reachability while analysis continued.

Resolution (interim): Restrict admin interfaces with local-in policy, review admin accounts and recent config exports, and monitor the PSIRT feed; the formal fix followed in Week 05.

Fortinet PSIRT blog
AlgoSecRelease22 Jan 2026

AlgoSec A33.20 lands in the Horizon platform

The release adds FireFlow work-order support for Google Cloud Network Firewall Policy, report-driven remediation straight from Disabled Rules and Unused Rules analytics, application-context risk prioritization to simplify rule recertification, and out-of-the-box compliance packs including a CIS baseline for Palo Alto Networks plus NIS2 and SOC 2 mapped controls.

AlgoSec press release
Check PointPatch19 Jan 2026

Check Point ships R81.20 Jumbo Hotfix

A new recommended Jumbo Hotfix take consolidates stability and security fixes for R81.20 gateways and management.

Check Point
Palo AltoFeature19 Jan 2026

Palo Alto expands Cortex XSIAM with agentic response

New XSIAM capabilities add agentic investigation and auto-containment playbooks driven by Palo Alto's security models.

Palo Alto
Palo AltoRelease19 Jan 2026

Palo Alto updates Prisma SD-WAN

The Prisma SD-WAN update adds autonomous path health and tighter integration with Prisma Access SASE.

Palo Alto
JuniperHardware19 Jan 2026

Juniper introduces SRX2300 firewall

The SRX2300 brings AI-predictive threat prevention and higher throughput to campus and branch security.

Juniper
W03

Juniper January advisories

12 – 18 Jan
AV26-041MultipleJuniper14 Jan 2026

Fixes for Policy Enforcer and Paragon Automation

Juniper’s January advisory round addressed vulnerabilities in management-plane products, covering Policy Enforcer releases prior to 24.1R3 and Paragon Automation prior to 24.1.1. Lower drama than the quarters that followed, but management and automation platforms remain a favorite pivot point once an edge device falls.

Resolution: Upgrade Policy Enforcer to 24.1R3+ and Paragon Automation to 24.1.1+ per the January bulletins.

Canadian Centre for Cyber Security
JuniperRelease12 Jan 2026

Juniper releases Junos 23.4R2 service release

The service release stabilises the 23.4 train with routing, filter and management-plane fixes across SRX and MX.

Juniper
F5Hardware12 Jan 2026

F5 launches the rSeries r5000 appliance

The mid-range r5000 brings F5OS containerised tenancy and hardware acceleration to enterprise app-delivery estates.

F5
CiscoRelease12 Jan 2026

Cisco releases Secure Firewall 7.7

The Secure Firewall software adds encrypted-visibility improvements and an AI assistant for policy authoring.

Cisco
FortinetFeature12 Jan 2026

Fortinet adds FortiSASE AI onramp

A new FortiSASE capability secures enterprise access to public generative-AI services with DLP and usage governance.

Fortinet
W02

2026 opens at full speed

05 – 11 Jan
CVE-2026-21509 · CVE-2026-20045ExploitedMicrosoft · CiscoJan 2026

The year begins with a zero-day avalanche

2026 opened with in-the-wild exploitation of a Microsoft Office zero-day (CVE-2026-21509) and a critical Cisco flaw (CVE-2026-20045), setting the tempo for the quarter before Fortinet’s SSO bypass joined them late in the month. Context from the Verizon DBIR: vulnerability exploitation is up 34% year over year and now drives one in five breaches, with the median time to mass exploitation still shrinking.

Resolution: Apply the January cumulative updates and vendor advisories for both CVEs, and assume edge and productivity zero-days will be weaponized before public disclosure when planning patch SLAs for the year.

SOC Prime recap
FortinetRelease05 Jan 2026

Fortinet updates FortiClient EMS 7.4

The endpoint-management update improves ZTNA posture checks and adds cloud EMS onboarding for hybrid fleets.

Fortinet
Check PointFeature05 Jan 2026

Check Point extends Infinity Playblocks automation

New Playblocks automations coordinate cross-product response across Quantum, Harmony and CloudGuard from a single console.

Check Point
Check PointRelease05 Jan 2026

Check Point ships Quantum SD-WAN update

The gateway update embeds SD-WAN steering with threat prevention and centralised Infinity management.

Check Point
Palo AltoHardware05 Jan 2026

Palo Alto ships PA-460 branch firewall

The compact PA-460 refreshes the small-branch line with higher throughput and cloud-delivered security services.

Palo Alto