Weekly Cybersecurity News Recap — 25 May 2026
Originally reported viaKrebs on Security · Bleeping Computer · CISA Advisories — Week of 19–25 May 2026The week of 19–25 May 2026 brought three significant CVE advisories, two major incident disclosures, and continued activity from the RansomHub and Cl0p groups. Here is the operational intelligence summary for security teams.
Critical CVEs: week of 25 May
CVE-2026-29812 (Cisco IOS XE Web UI RCE, CVSS 9.8): Cisco disclosed a critical unauthenticated remote code execution vulnerability in the IOS XE web management interface. Active scanning for vulnerable devices was observed within 6 hours of disclosure. CVE-2026-30140 (VMware vSphere ESXi heap overflow, CVSS 9.1): VMware issued emergency patches for an ESXi hypervisor vulnerability affecting all supported versions. CVE-2026-28900 (Citrix NetScaler NULL pointer dereference leading to DoS/RCE, CVSS 8.6).
Notable incidents this week
A FTSE 100 financial services firm disclosed a breach affecting approximately 400,000 customer records, attributed to a compromised third-party data analytics vendor. The Canvas/Instructure incident timeline continued with Instructure issuing an updated notice confirming that student grade data was included in the exfiltrated dataset for approximately 12% of affected institutions.
- Patch CVE-2026-29812 (Cisco IOS XE) immediately on all internet-exposed management interfaces — active exploitation is confirmed.
- Apply VMware ESXi patches for CVE-2026-30140 within 72 hours — hypervisor vulnerabilities represent maximum blast-radius risk.
- If using Canvas LMS, request updated scope information from Instructure regarding grade data exposure for your institution.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.