Palo Alto, CA, USA
2017
  |  By Igal Zeifman
CVE-2026-21589 is an arbitrary file access flaw affecting most of Atlassian’s self-hosted Data Center product line. CISA classifies it as CWE-552, files or directories accessible to external parties. An unauthenticated remote attacker can read specific files inside the web application root directory. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.
  |  By Igal Zeifman
CVE-2026-94483 is a server-side request forgery flaw in the Image Optimization feature of Next.js, the React framework maintained by Vercel. It is classified as CWE-918. Image Optimization fetches a remote image on the server and re-encodes it. Before fetching, it checks the requested URL against the images.remotePatterns allow-list. The flaw is that the allow-list check and the fetch resolve DNS separately, so a host that passes the check can resolve to a different address by the time the fetch happens.
  |  By Igal Zeifman
CVE-2026-84411 is an integer underflow in the web management service of MikroTik RouterOS, classified as CWE-191. The flaw sits in the service’s HTTP request body handling and is reachable before authentication. A single crafted request lets an unauthenticated network attacker execute arbitrary code as root, or crash the device. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical).
  |  By Igal Zeifman
CVE-2026-86858 is an improper access control flaw in the ServiceNow AI Platform, classified as CWE-284. ServiceNow describes it as an unauthenticated privilege escalation reachable through GraphQL. In certain circumstances an unauthenticated user can create, modify, or delete instance data beyond what was intended. The vulnerability carries a CVSS v4.0 base score of 8.7 (High). Attack vector is network, attack complexity is low, and neither privileges nor user interaction are required.
  |  By Igal Zeifman
CVE-2026-94545 is a remote code execution vulnerability in the next/og ImageResponse API of Next.js, the React framework maintained by Vercel. ImageResponse generates images on the server, typically Open Graph preview cards, by rendering markup through the Satori library into SVG and then into a raster image.
  |  By Igal Zeifman
CVE-2026-69197 is an authorization flaw in the Content Delivery API of Umbraco CMS, an open source ASP.NET content management system. The Delivery API enforces member and Public Access checks on the node a caller directly requests, but it does not apply those same checks to nodes referenced through Content Picker or Multi-Node Tree Picker properties. The gap extends to pickers nested inside Block List, Block Grid, and Rich Text Editor blocks.
  |  By Igal Zeifman
CVE-2026-70756 is a vulnerability in the Core component of Oracle WebLogic Server, part of Oracle Fusion Middleware. An unauthenticated attacker with network access over the T3 or IIOP protocols can compromise the server and take full control of it. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical). Oracle rates it as easily exploitable, with no privileges and no user interaction required. Confidentiality, integrity, and availability impacts are all rated high.
  |  By Igal Zeifman
CVE-2026-76461 is a SQL injection vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, caused by insufficient validation of message content before it reaches a database query. An attacker who sends a crafted email message containing SQL statements can have those statements executed by the appliance as it processes the message. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
  |  By Igal Zeifman
Today we are happy to announce the beta release of the CyCognito MCP server, which makes your external attack surface data consumable by any AI client that speaks the Model Context Protocol, including Claude, Cursor, and ChatGPT. The server runs on CyQL, the proprietary query language behind advanced search in our platform. CyQL is designed to ask precise questions about an attack surface, using operators suited to each type of asset, issue, and relationship.
  |  By Igal Zeifman
CVE-2026-78006 is a deserialization of untrusted data vulnerability (CWE-502) in The Events Calendar, a WordPress plugin published by StellarWP, that allows an attacker to achieve remote code execution on the underlying host. The flaw sits in the is_safe_widget_instance function, whose guard against unsafe object data can be bypassed.
  |  By CyCognito
Join CyCognito’s CEO Rob N. Gurzeev and Commvault’s Ben Herzberg to uncover what enforcing data security at scale actually requires and how to close the gap between policy and ground truth.
  |  By CyCognito
-Recent breaches show AI risk is already present in many environments, often entering through suppliers, data flows, and integrations. But awareness alone is not enough. CISOs and security leaders must actively manage the expanded attack surface AI creates. In this session, experts from CyCognito and Panorays help you understand how to identify AI relationships, assess the risks they pose, and remediate vulnerabilities before they lead to an incident. You’ll learn.
  |  By CyCognito
See the CyCognito platform in action to understand how it can help you identify, prioritize and eliminate your most critical risks.
  |  By CyCognito
"CyCognito is worth every cent we pay and it helps me sleep better because I know we’re checking our internet-facing assets on a regular basis.” —Benjamin Bachmann | Vice President, Group CISO | Ströer.
  |  By CyCognito
“CyCognito provides our company with cutting-edge technology enabling my team to have global visibility into our web-facing assets in an easy-to-use interface.” — Alex Schuchman | Chief Information Security Officer | Colgate-Palmolive Company.
  |  By CyCognito
“I can’t point to another tool that does as thorough a job of exploring and exposing those assets that you didn’t even know you had. It’s so valuable." — Kevin Kealy | Chief Information Security Officer | Scientific Games.
  |  By CyCognito
Hear first hand from Chief Technical Officer, Randy Watkins, as he explains why attack surface mapping is critical to an organization’s security posture and managing their IT assets. Learn how prioritizing security risk helps to cut through a sea of security issues and gives focus to security teams on what is critical.
  |  By CyCognito
Streamline Security Testing with Analytics, Trends, and Reporting: New Cybersecurity Automation Features to Streamline Attack Surface Protection.
  |  By CyCognito
See How CyCognito Monitors Your Subsidiaries for Security Risk.
  |  By CyCognito
Your attack surface has grown, it's now in cloud infrastructure and across subsidiaries and unknown, unmanaged assets are everywhere. How are you finding these? Attackers look for, find and attack these unknown assets and when there are externally exposed risks, sensitive data and critical systems are put in danger. Read now, External Exposure & Attack Surface Management For Dummies.
  |  By CyCognito
CTEM, a comprehensive risk reduction framework, integrates visibility risk assessment, issue prioritization, and validation. This approach facilitates the continuous identification and testing of exposed systems, enhancing decision-making and enabling a more proactive threat response. Download the white paper, Understanding Continuous Threat Exposure Management, to learn about CTEM's core components and how they contribute to cybersecurity resilience, how CTEM addresses the challenge of managing risk on attack surfaces, and how CyCognito's capabilities align with CTEM's requirements.
  |  By CyCognito
With the ever-growing volume of cybersecurity alerts and attacks bombarding security teams, more CISOs are taking a hard look at External Attack Surface Management (EASM) platforms to better understand how adversaries get into systems and how to keep them out. It's not surprising that EASM products have captured the industry's attention, as many organizations are seeing growth of their attack surfaces' growth outpace their detection and remediation abilities. Some of the driving causes: digital transformation, the cloud, third-party dependencies, subsidiary sprawl, and more.
  |  By CyCognito
Your pen testing team is working hard, but they are facing an operational challenge due to the large number of assets they need to test and the time required to complete each test. As the fundamental approach to penetration testing has not changed much since the first test over 50 years ago, it's worth exploring whether the tool is still sufficient for securing today's IT environment.

CyCognito solves one of the most fundamental business problems in cybersecurity: seeing how attackers view your organization, where they are most likely to break in, what systems and assets are at risk and how you can eliminate the exposure.

Founded by national intelligence agency veterans, CyCognito has a deep understanding of how attackers exploit blind spots and a path of least resistance. Based in Palo Alto, CyCognito serves a number of large enterprises and Fortune 500 organizations, including Colgate-Palmolive, Tesco and many others.

Automated external attack surface management and continuous testing reduces your overall risk:

  • Discovery: Proactively uncover exposed external assets — without input or configuration — using attacker reconnaissance approaches.
  • Contextualization: Empower your team to know what an asset does, where it’s located, what other assets it connects to, and how attractive it is from that attacker perspective.
  • Active Security Testing: Launch security testing across your full inventory of external assets, enabling a new level of visibility into risk and the steps needed to reduce it.
  • Prioritization: Automate risk prioritization for external assets to focus your security team’s attention and energy on the 10 to 50 most critical exploited assets that matter the most.
  • Remediation Acceleration: Quickly repair exploitable assets and reduce validation time from months to hours to swiftly prevent data breaches.

Discover, test and prioritize all of your web assets and applications.