Welcome to our LGA Monthly Security Bytes!
Here, you’ll find bite-sized security developments and practical insights to help you stay ahead of day-to-day security operations.
Enterprise infrastructure is facing renewed security scrutiny following newly disclosed vulnerabilities affecting VMware and Cisco Catalyst SD-WAN.
The vulnerabilities could enable attackers to gain unauthorised access, execute malicious code, escalate privileges, or compromise systems that organisations depend on for day-to-day operations.
For organisations using these technologies, successful exploitation could impact critical workloads, network connectivity, and operational continuity.
LGA helps organisations maintain greater visibility across their infrastructure, identify suspicious activity early, and respond to potential threats before they escalate into wider operational impact.
Security researchers have identified multiple critical vulnerabilities in VMware products that could allow attackers to bypass authentication, execute arbitrary code, steal sensitive data, and take full control of virtual environments.
These vulnerabilities affect widely used VMware platforms, including vCenter Server, ESXi, Workstation, and Fusion, putting both cloud-based and on-premises virtual infrastructure at risk. Since these platforms are core to enterprise IT operations, organizations that delay patching face a heightened risk of data breaches, service disruption, and full-scale system compromise.
Critical Vulnerabilities were identified in the following: CVE-2026-59309 & CVE-2026-59310
CVE-2026-47876
CVE-2026-41703
|
Security researchers have identified critical vulnerabilities in Cisco Catalyst SD-WAN Software that could create direct pathways for unauthorized access, system compromise, and exposure of sensitive enterprise data.
These vulnerabilities affect a wide range of software releases, from versions earlier than 20.9 through the latest 26.1 release, leaving a broad range of Cisco SD-WAN deployments exposed. Since SD-WAN infrastructure connects and manages traffic across distributed enterprise networks, timely patching is essential to prevent connectivity disruption, data breaches, and unauthorized network access.
Critical Vulnerabilities were identified in the following:
Key vulnerabilities include CVE-2026-59309 (CVSS 9.8), CVE-2026-59310 (CVSS 9.8), CVE-2026-47876 (CVSS 9.3), and CVE-2026-41703 (CVSS 7.6). Recommended Action: Update affected Cisco Catalyst SD-WAN systems to reduce the risk of unauthorised access, data exposure, and network compromise. |
With our 24/7 Security Monitoring, suspicious activity across critical infrastructure can be identified earlier, enabling faster detection and response before threats escalate.
All-in-One IT Solutions: Secure, Connected and Cloud-Ready with LGA
© 2025 LGA Telecom Pte Ltd. All Rights Reserved.