🚨 Overnight watchTowr rapidly reacted to CVE-2026-0300, an unauthenticated buffer overflow in Palo Alto PAN-OS User-ID Auth Portal. RCE as root on PA-/VM-Series. No patch. Palo Alto: limited ITW exploitation. Existing watchTowr clients aware of exposure. Reach out for support.
watchTowr clients had industry-first access to this research to understand their exposure - plus leveraged Active Defense for autonomous mitigation of CVE-2026-41940 at the network edge.
Research powers our Preemptive Exposure Management solution: the watchTowr Platform.
Rapid reaction gets you ahead. 6 days before CISA added CVE-2026-3055 to KEV, a Citrix NetScaler Memory Overread (CitrixBleed++) vulnerability, watchTowr clients were aware of their exposure.
Reach out via our website if you need support.
What number CitrixBleed are we on?
Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one.
Sigh.
https://t.co/cNFLboyvLx
watchTowr Intel is detecting active reconnaissance against NetScalers for CVE-2026-3055 through our Attacker Eye honeypot network.
Exploitation is likely imminent. Patch now.
watchTowr clients already have access to internal mechanisms to confidently identify their exposure.
Rapid reaction gets you ahead. 4 days before CISA added CVE-2026-33017 (Langflow RCE) to KEV, watchTowr clients were already aware of their exposure.
Reach out via our website (https://t.co/gzSQETs11l) if you need support.
It's Monday! We are currently rapidly reacting to CVE-2026-3055 - yet another unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances.
Active watchTowr Platform clients have been made aware of their exposure - reach out for support.
~150 S3 abandoned buckets. 8M+ requests. Two months. Software updates, binaries, VMs and more.
This week, AWS rolled out namespaces for new S3 buckets - finally.
This is why offensive security research is so important - to move the needle.
https://t.co/PCuioOBL1K
In 2025, we achieved pre-auth RCE against another solution in a ransomware gang favourite category. Today, we finally click publish.
Join us as we walk through a chain of vulnerabilities we identified in BMC’s FootPrints ITSM solution.
Enjoy!
https://t.co/gtCNb05QHu
Overnight we observed the first exploitation attempts against Cisco Catalyst SD-WAN in our honeypots.
Activity started around 03:00 UTC, leveraging the now-public PoC.
CVE-2026-20127
If you're running SD-WAN and haven't patched yet, now would be a good time.
@watchtowrcyber
Can you feel it too?
Join us today for our analysis of Juniper's recent pre-auth RCE - CVE-2026-21902 - affecting a very specific set of devices. Curious?
https://t.co/sziS0PBUmB
We promised we'd be back!
Join us on our journey, from repro'ing N-days to stumbling into 0-days in SolarWinds Web Help Desk, eventually achieving pre-auth RCE.
This research fuels the watchTowr Platform, our Preemptive Exposure Management technology.
https://t.co/TzNBT1Ghs7
When Ivanti disclosed EPMM RCEs (CVE-2026-1281, CVE-2026-1340) w/ active exploitation, watchTowr was already moving.
Instinct alerted. Rapid Reaction validated exposure. Attacker Eye captured backdoors. Active Defense auto-mitigated.
Know your exposure before the world does.
Thanks for joining us today! We hope you’ve come away with some great ideas on how to leverage #legaltech and leverage disruption to transform legal services within your business. #OslerInnovation https://t.co/V5bh49kha1 #legaltech
What is the most significant pain point when dealing with legal work? 67% of our audience said lack of up to date technology. https://t.co/V5bh49kha1 #OslerInnovation#legaltech
Our innovation tech fair is showcasing our #legaltech solutions including tools to target pain points in undertakings, starting a business in Canada, privacy and data, transactions, critical workplace documents, diligence, and discovery. https://t.co/V5bh49kha1 #OslerInnovation