VYPR
AI Brief2026-08-01· generated Aug 1, 2026

Critical Exploited Vulnerabilities Hit Zoho, Cleo, Citrix, Fortinet

Multiple critical vulnerabilities in Zoho, Cleo, SysAid, Citrix, and Fortinet products are actively exploited, posing significant risks to organizations.

Multiple Zoho ManageEngine on-premise products are affected by CVE-2022-47966, a critical remote code execution vulnerability stemming from the use of an outdated version of Apache Santuario xmlsec. This flaw allows attackers to leverage XML Security features for code execution. Given its critical severity and presence in widely used IT management tools, this vulnerability poses a significant risk to organizations relying on these products for service desk and other operations. Patches and mitigation strategies should be prioritized.

CVE-2024-50623, a critical vulnerability in Cleo Harmony, VLTrader, and LexiCom, allows for remote code execution through unrestricted file upload and download. This flaw, present in versions before 5.8.0.21, has been observed to be under widespread attack, as reported by Risky Business. The ease of exploitation and the potential for full system compromise make this a high-priority threat for organizations using these file transfer solutions.

SysAid On-Premise versions prior to 23.3.36 are vulnerable to CVE-2023-47246, a critical path traversal vulnerability that can lead to code execution. Attackers can exploit this by writing a file to the Tomcat webroot, a method that was actively exploited in the wild in November 2023. This vulnerability underscores the importance of timely patching for on-premise systems, especially those exposed to the internet.

A critical information disclosure vulnerability, CVE-2023-4966, affects Citrix NetScaler ADC and NetScaler Gateway when configured in specific gateway or AAA virtual server modes. This flaw has been actively exploited by ransomware gangs, including INC Ransomware, and has been the subject of multiple news reports, such as those from Cyber Security News. The potential for sensitive data exfiltration makes this a significant concern for organizations relying on Citrix for secure remote access.

Fortinet products, including FortiOS and FortiProxy, are impacted by CVE-2023-27997, a critical heap-based buffer overflow vulnerability. This flaw exists in multiple older versions of FortiOS and FortiProxy. It has been linked to exploitation by ransomware groups and has been highlighted in security analyses, including reports from SecurityWeek and Dark Reading. Organizations using these Fortinet products should ensure they are running the latest supported versions to mitigate this risk.

Several Linux kernel vulnerabilities have been disclosed, including CVE-2024-4944 affecting WatchGuard Mobile VPN with SSL client on Windows and CVE-2023-4244, CVE-2023-3609, CVE-2023-1281, CVE-2021-23134, and CVE-2021-27365, all related to local privilege escalation. These Linux kernel flaws, particularly those involving use-after-free in netfilter and net/sched components, can allow local users to gain elevated privileges, posing a risk to system integrity. Prompt patching of affected Linux systems is crucial.

Microsoft Windows is affected by CVE-2024-21338, a high-severity elevation of privilege vulnerability in the Windows Kernel. While not as critical as some of the other vulnerabilities, kernel-level privilege escalation can be a stepping stone for more advanced attacks. Organizations should ensure their Windows systems are up-to-date to protect against potential exploitation.

Python's tarfile module is vulnerable to CVE-2025-4517, a critical arbitrary filesystem write vulnerability when extracting untrusted tar archives using extractall() with filter="data". This flaw could allow attackers to write files outside the intended extraction directory, potentially leading to code execution or system compromise. Developers using this module should exercise caution and ensure proper validation of tar archives.

Synthesized by Vypr AI
Critical Exploited Vulnerabilities Hit Zoho, Cleo, Citrix, Fortinet · VYPR