Security Alerts: What Is Being Exploited Right Now
Threats & VulnerabilitiesHome & Business
These are the security alerts that matter to UK home users and small businesses, explained in plain English. For each one you get who it affects, how serious it is and what to do.
We pick items from the National Cyber Security Centre (NCSC) and CISA, the US cyber security agency, then rewrite them without the jargon. Every entry links to the original. This is a selection, not a list of every vulnerability.
How we rate each alert
The rating is ours, based on who is likely to be affected. It is not the rating the source gives.
High
Known to be used in real attacks, and it affects software or devices many of our readers use. Act today.
Medium
Known to be used in real attacks, but it affects a smaller group, such as one make of device or a specific set-up. Check whether it applies to you.
Low
Worth knowing about. No known attacks yet, or very limited reach.
Latest alerts
Severity: MediumHome usersData breach
ASOS customers: NCSC says assume your details were accessed after a cyber incident
ASOS has said it is investigating a cyber incident after some customers received an unauthorised push notification on 6 October 2026. The company says names and contact details may have been accessed, and it does not believe payment card details or account passwords were affected. The NCSC says that if you are an ASOS customer you should assume you are affected, even if you did not get the notification.
What to do
Treat any message that appears to come from ASOS with care, including push notifications, texts and emails, and do not click links in them. Scam messages can arrive some time after a breach. Even though ASOS does not believe passwords were affected, it is a good moment to use a strong, separate password for each account with two-step verification turned on, or a passkey. If you think you have been targeted by a scam, report it through Stop! Think Fraud.
Fortinet FortiMail flaw is being used in attacks and needs no login
A flaw in Fortinet's FortiMail email security product could let someone with no login write files onto the underlying system by sending specially crafted web requests. CISA added it to its list of vulnerabilities known to be used in real attacks on 1 October 2026. Fortinet has published a security advisory and rates the flaw as critical.
What to do
This only affects organisations that run FortiMail themselves. If your business, or the IT company that looks after it, uses FortiMail, ask them to read Fortinet's advisory FG-IR-26-175 and follow the steps it gives as soon as possible. If you have never heard of FortiMail, this almost certainly does not apply to you.
Apple fixes an iPhone, iPad and Mac flaw that attackers are already using
A flaw in CoreGraphics, the part of Apple's software that handles graphics, could let an attacker run their own code on an iPhone, iPad or Mac that processes a specially crafted file. CISA, the US cyber security agency, added it to its list of vulnerabilities known to be used in real attacks on 29 September 2026. Apple has fixed it in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
What to do
Update now. On an iPhone or iPad, go to Settings, then General, then Software Update. On a Mac, go to System Settings, then General, then Software Update. Turn on Automatic Updates on the same screen so the next fix installs without you having to remember.
NCSC urges organisations to fix Citrix NetScaler flaws that attackers are using
Citrix has published fixes for eight flaws in NetScaler ADC and NetScaler Gateway. Two of them are confirmed as being used in real attacks, and one of those lets an attacker with no login run commands on the device. The NCSC is urging UK organisations to act quickly. It only affects organisations that run NetScaler themselves, on their own equipment.
What to do
If your business, or the IT company that looks after it, runs NetScaler ADC or Gateway on its own equipment, ask them to read the Citrix security bulletin and install the latest update straight away. The affected versions are listed in the NCSC alert. If you have never heard of NetScaler, this alert almost certainly does not apply to you.
MikroTik routers: two flaws that work together are known to be exploited
Two flaws in MikroTik's RouterOS software can be chained together. One lets an attacker raise their own access level on the router. The other, added to CISA's list on 25 September 2026, lets someone with no login open a session and send commands to the router. Used together, someone with no login could gain high-level access. Both are on CISA's list of vulnerabilities known to be used in real attacks.
What to do
This only affects routers that run MikroTik RouterOS. If your router came from your broadband provider, you probably do not have one. If you do, read the MikroTik September 2026 security page and update RouterOS. Check that the router's remote management is not open to the internet.
WordPress core flaw could let attackers run code on a website
A flaw in the core WordPress software could let someone with no login make a site run a file it should not, which can lead to them running their own code on the site. CISA added it to its list of vulnerabilities known to be used in real attacks on 25 September 2026. WordPress has published a security advisory.
What to do
If you run a WordPress site, go to Dashboard, then Updates, and install the latest WordPress version. If a web host or developer looks after the site for you, ask them to confirm it has been updated. Switching on automatic updates for WordPress core means the next fix does not wait for you.
Zyxel GS1900 switches: update for a flaw that attackers on your network can use
A flaw in the Zyxel GS1900 series of network switches could let an attacker who is already on your local network run commands on the switch by sending it a specially crafted web request, with no login needed. CISA added it to its list of vulnerabilities known to be used in real attacks on 21 September 2026. Zyxel has released fixed firmware, the switch's built-in software, for the models it still supports.
What to do
This only affects Zyxel GS1900 series switches. If you have one, find the model name on its label, then look it up in the table in Zyxel's security advisory and install the fixed firmware shown for it. Zyxel says other models still on sale are not affected.
Three Linux kernel flaws are known to be used in attacks
CISA added three Linux kernel flaws to its list of vulnerabilities known to be used in real attacks on 18 September 2026. One lets an attacker write data into memory they should not be able to reach, through a network filtering feature called ebtables. One is a timing problem in how the kernel handles a type of network connection, and one is in how it handles encrypted (TLS) network traffic. CISA says two of the three may affect kernels that are end of life, which means they no longer get official updates.
What to do
If you run Linux, install your distribution's latest updates and restart the computer so the new kernel loads. If your system uses a kernel that no longer gets updates, plan to move to a supported release. If you only use Windows, a Mac or an iPhone, this does not apply to you.
Google Pixel phones: update for a flaw in the mobile modem
A flaw in the cellular modem of Google Pixel phones could let an attacker get around permission checks and give themselves more access than they should have. CISA added it to its list of vulnerabilities known to be used in real attacks on 16 September 2026, and points to Google's September 2026 Pixel security bulletin for the fix.
What to do
On a Pixel, go to Settings, then System, then Software updates, then System update, and install the latest update. This alert names Pixel phones only.
Cyber Nova AI does not find or test vulnerabilities. We summarise what others have published. The summaries are written with AI assistance and checked by a person before they go live. If anything here differs from the original, the original is right.
Contains public sector information published by the National Cyber Security Centre and licensed under the Open Government Licence v3.0.