מה מנוצל עכשיו — והאם זה נוגע לעסק בישראלWhat is being exploited now — and does it touch a business in Israel
קטלוג הפרצות המנוצלות בפועל של CISA, מסונן לשוק הישראלי ומוסבר בעבריתCISA's exploited-in-the-wild catalogue, filtered for the Israeli market and explained in Hebrew
אותות הקשר — מחוץ לרמהContext signals — outside the level
פרצות במוצר של יצרן ישראלי (90 יום)In a product from an Israeli vendor (90 days)הקשרcontext3 רשומות3 entries
הרשומות שנספרו כאן:The entries counted here: CVE-2026-66384 CVE-2026-16232 CVE-2026-50751
ניצול צפוי בהיקף רחב — EPSS מעל 50% (30 יום)Wide-scale exploitation expected — EPSS over 50% (30 days)הקשרcontext6 רשומות6 entries
הרשומות שנספרו כאן:The entries counted here: CVE-2019-1068 CVE-2026-33824 CVE-2026-8037 CVE-2026-63077 CVE-2026-34486 CVE-2026-18577
רכיבים היקפיים שתאריך היעד של CISA להם כבר עבר (30 יום)Perimeter products whose CISA due date has passed (30 days)הקשרcontext8 רשומות8 entries
הרשומות שנספרו כאן:The entries counted here: CVE-2026-8452 CVE-2026-73570 CVE-2026-55040 CVE-2026-20349 CVE-2026-8037 CVE-2026-63077 CVE-2026-18556 CVE-2026-18577
⚠️ לקרוא לפני שמסיקים מהצבע
- זו אינה בדיקה של הרשת שלכם. הדף קורא קטלוג ציבורי. הוא לא יודע אם FortiGate או SharePoint בכלל קיימים אצלכם, וכמה גרסאות אחורה אתם.
- "רלוונטי לישראל" הוא הערכה מקצועית מוצהרת, לא מדידה. אין מאגר חופשי שאומר כמה ארגונים בישראל מריצים מוצר מסוים. הדירוג כאן הוא שיפוט של יועץ אחד, עם נימוק כתוב לכל יצרן — כדי שיהיה אפשר לחלוק עליו.
- רשימה ריקה אינה תעודת ביטוח. קטלוג KEV כולל רק את מה שCISA אישרה שמנוצל בפועל. פרצה חדשה שעדיין לא נכנסה לקטלוג מסוכנת בדיוק כמו זו שכן.
- תאריכי היעד של CISA מחייבים גופי ממשל פדרליים בארה"ב — לא אתכם. הם מופיעים כאן רק כמדד לדחיפות שCISA עצמה מייחסת לפרצה.
- זהו פרויקט פרטי, לא גורם רשמי ולא ייעוץ אישי.
⚠️ Read this before reading the colour
- This is not a check of your network. The page reads a public catalogue. It does not know whether you even run FortiGate or SharePoint, or how many versions behind you are.
- "Relevant in Israel" is a declared professional estimate, not a measurement. No free dataset says how many Israeli organisations run a given product. The ranking here is one consultant's judgement, published with a written reason per vendor so it can be argued with.
- An empty list is not a clean bill of health. KEV covers only what CISA has confirmed is being exploited. A fresh vulnerability that has not entered the catalogue yet is exactly as dangerous as one that has.
- CISA due dates bind US federal agencies — not you. They appear here only as CISA's own measure of how urgent it considers the flaw.
- This is a private project, not an official body and not personal advice.
מה אומרות הרמות
הרמה סופרת מוצרים היקפיים בלבד — כאלה שתוקף מחו"ל יכול להגיע אליהם ישירות. פרצה בתחנת עבודה חשובה גם היא, אבל היא לא נספרת ברמה, כי היא דורשת שמישהו אצלכם ילחץ על משהו.
What the levels mean
The level counts perimeter products only — the ones an attacker abroad can reach directly. A workstation flaw matters too, but it is not in the level, because it needs somebody inside to click something.
מה ברשימה עכשיו — והאם זה נוגע לכם
What is on the list now — and whether it touches you
מסודר לפי: רכיב היקפי לפני פנימי, יצרן נפוץ בישראל לפני פחות נפוץ, פרצה ששימשה לכופרה ו-EPSS גבוה לפני אלה שלא, וחדש לפני ישן. אין משקלות נסתרים. ההסבר בעברית מורכב אך ורק משדות שקיימים ברשומה עצמה — שדה חסר מוריד משפט, ולא ממציא אותו. פתחו שורה עם + לקבלת ההסבר המלא.
Ordered by: perimeter before internal, vendors common in Israel before less common ones, ransomware-linked and high-EPSS before neither, newer before older. No hidden weights. The Hebrew explanation is assembled strictly from fields present in the record — a missing field drops a sentence rather than inventing one. The English line below each entry is CISA's own description. Open a row with + for the full explanation.
SonicWall SMA1000 Appliancesשער גישה מרחוקinternet-facingשימש לכופרהused in ransomwareCVE-2026-15409 · EPSS 84% · נוסף 2026-07-14CVE-2026-15409 · EPSS 84% · added 2026-07-14
SonicWall SMA1000 Appliances הוא שער גישה מרחוק. סוג הפרצה: הכרחת השרת לפנות ליעד פנימי (SSRF). CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 84% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: חומות אש ו-SSL VPN נפוצים מאוד בעסקים קטנים ובינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-17 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Microsoft SharePoint Serverשרת שיתוף מסמכים, לרוב חשוף לאינטרנטinternet-facingשימש לכופרהused in ransomwareCVE-2026-45659 · EPSS 76% · נוסף 2026-07-01CVE-2026-45659 · EPSS 76% · added 2026-07-01
Microsoft SharePoint Server הוא שרת שיתוף מסמכים, לרוב חשוף לאינטרנט. סוג הפרצה: פענוח אובייקט לא מהימן. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 76% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: כמעט כל ארגון בישראל מריץ Windows, Microsoft 365 או שניהם. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-04 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Check Point Security Gatewayשער בקצה הרשתinternet-facingשימש לכופרהused in ransomware🇮🇱 צ'ק פוינט — תל אביבIsraeli vendorCVE-2026-50751 · EPSS 84% · נוסף 2026-06-08CVE-2026-50751 · EPSS 84% · added 2026-06-08
Check Point Security Gateway הוא שער בקצה הרשת. סוג הפרצה: עקיפת אימות זהות. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 84% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: יצרן ישראלי עם חדירה גבוהה במיוחד בארגונים הגדולים ובמגזר הציבורי בישראל. (הערכה מקצועית, לא מדידה.) יצרן ישראלי — צ'ק פוינט — תל אביב. תאריך היעד של CISA הוא 2026-06-11 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
SonicWall SMA1000 Appliancesשער גישה מרחוקinternet-facingשימש לכופרהused in ransomwareCVE-2026-15410 · EPSS 12% · נוסף 2026-07-14CVE-2026-15410 · EPSS 12% · added 2026-07-14
SonicWall SMA1000 Appliances הוא שער גישה מרחוק. סוג הפרצה: הרצת קוד זר. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. CISA מסמנת שהפרצה הזו כבר שימשה בקמפיין כופרה. EPSS (FIRST.org): 12% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: חומות אש ו-SSL VPN נפוצים מאוד בעסקים קטנים ובינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-17 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Microsoft SharePointשרת שיתוף מסמכים, לרוב חשוף לאינטרנטinternet-facingCVE-2026-50522 · EPSS 85% · נוסף 2026-07-22CVE-2026-50522 · EPSS 85% · added 2026-07-22
Microsoft SharePoint הוא שרת שיתוף מסמכים, לרוב חשוף לאינטרנט. סוג הפרצה: פענוח אובייקט לא מהימן. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 85% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: כמעט כל ארגון בישראל מריץ Windows, Microsoft 365 או שניהם. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-25 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
WordPress Coreמערכת ניהול תוכן שמריצה אתר אינטרנט חשוףinternet-facingCVE-2026-60137 · EPSS 78% · נוסף 2026-07-21CVE-2026-60137 · EPSS 78% · added 2026-07-21
WordPress Core הוא מערכת ניהול תוכן שמריצה אתר אינטרנט חשוף. סוג הפרצה: הזרקת SQL. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 78% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: הפלטפורמה שעליה יושבים רוב אתרי העסקים הקטנים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-04 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
WordPress Coreמערכת ניהול תוכן שמריצה אתר אינטרנט חשוףinternet-facingCVE-2026-63030 · EPSS 97% · נוסף 2026-07-21CVE-2026-63030 · EPSS 97% · added 2026-07-21
WordPress Core הוא מערכת ניהול תוכן שמריצה אתר אינטרנט חשוף. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 97% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: הפלטפורמה שעליה יושבים רוב אתרי העסקים הקטנים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-24 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fortinet FortiSandboxמערכת ניתוח קבצים בפריסת רשתinternet-facingCVE-2026-25089 · EPSS 76% · נוסף 2026-07-16CVE-2026-25089 · EPSS 76% · added 2026-07-16
Fortinet FortiSandbox הוא מערכת ניתוח קבצים בפריסת רשת. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 76% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: FortiGate היא אחת מחומות האש הנפוצות ביותר בשוק העסקים הקטנים והבינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-19 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fortinet FortiSandboxמערכת ניתוח קבצים בפריסת רשתinternet-facingCVE-2026-39808 · EPSS 93% · נוסף 2026-07-16CVE-2026-39808 · EPSS 93% · added 2026-07-16
Fortinet FortiSandbox הוא מערכת ניתוח קבצים בפריסת רשת. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 93% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: FortiGate היא אחת מחומות האש הנפוצות ביותר בשוק העסקים הקטנים והבינוניים בישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-07-19 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Ivanti Sentryשער אבטחה למכשירים ניידיםinternet-facingCVE-2026-10520 · EPSS 100% · נוסף 2026-06-11CVE-2026-10520 · EPSS 100% · added 2026-06-11
Ivanti Sentry הוא שער אבטחה למכשירים ניידים. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 100% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: שערי גישה מרחוק וניהול מכשירים; יעד חוזר ונשנה של תקיפות בעולם ובישראל. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-06-14 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Citrix NetScaler ADC and NetScaler Gatewayשער גישה מרחוק / מאזן עומסיםinternet-facingCVE-2026-8452 · EPSS 2% · נוסף 2026-08-26CVE-2026-8452 · EPSS 2% · added 2026-08-26
Citrix NetScaler ADC and NetScaler Gateway הוא שער גישה מרחוק / מאזן עומסים. סוג הפרצה: חריגה מגבולות זיכרון. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 2% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: NetScaler וגישה מרחוק — נפוץ בבריאות, בפיננסים ובממשלה. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-29 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Synacor Zimbra Collaboration Suite (ZCS)שרת דואר ושיתוף פעולהinternet-facingCVE-2026-73570 · EPSS 21% · נוסף 2026-08-21CVE-2026-73570 · EPSS 21% · added 2026-08-21
Synacor Zimbra Collaboration Suite (ZCS) הוא שרת דואר ושיתוף פעולה. סוג הפרצה: הרצת פקודות מערכת מרחוק. CISA מאשרת שהפרצה מנוצלת בפועל בתקיפות, לא רק תיאורטית. זה רכיב שיושב על גבול הרשת — תוקף מחו"ל יכול להגיע אליו בלי שאף אחד אצלכם ילחץ על כלום. EPSS (FIRST.org): 21% סיכוי משוער לניצול ב-30 הימים הקרובים. למה זה רלוונטי בישראל: המוצר הוא Zimbra — שרת דואר שנפוץ בישראל במוסדות אקדמיים, ברשויות מקומיות ובעסקים שלא עברו ל-Exchange. (הערכה מקצועית, לא מדידה.) תאריך היעד של CISA הוא 2026-08-24 — שכבר עבר. הוא מחייב גופי ממשל פדרליים בארה"ב בלבד; בישראל אין חובה כזו, והוא מופיע כאן רק כמדד לדחיפות ש-CISA עצמה מייחסת לפרצה.
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
הפעולה ש-CISA דורשת — בלשונה, כפי שפורסמה (אנגלית)CISA's required action — verbatim, as publishedApply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
מגמת הרמה — 7 הימים האחרונים
ציר Y: הרמה (0–3) — 0 רגוע, 3 קריטי. ציר X: זמן אמת, שעון ישראל.
Level over time — the last 7 days
Y axis: the level (0–3) — 0 calm, 3 critical. X axis: real time, Israel time.
החלון קבוע על 7 ימים גם כשההיסטוריה קצרה ממנו, כדי שלא ייווצר רושם שהמערכת מודדת כבר שבוע. בחלון הזה יש 14 דגימות אמיתיות, הראשונה ב-27/08/2026 07:25 והאחרונה ב-02/09/2026 19:25. הקו הוא קו מדרגה: רמה מוצגת כמוחזקת מרגע המדידה ועד המדידה הבאה. אין החלקה, אין ממוצע ואין נקודות מומצאות — כל קודקוד בקו הוא שורה שקיימת בקובץ הנתונים. פער של יותר מ-13 שעות בין דגימות נחתך בקו ומסומן בהצללה: חור בנתונים אינו רגיעה.
The window stays fixed at 7 days even when the history is shorter, so the page never implies it has been measuring all week. This window holds 14 real samples, the first at 27/08/2026 07:25 and the last at 02/09/2026 19:25. The line is a step line: a level is drawn as held from the sample that measured it until the next one. No smoothing, no averaging, no invented points — every vertex is a row that exists in the data file. A gap of more than 13 hours between samples cuts the line and is hatched: a hole in the data is not calm.
איך זה עובד, בקצרה
הדף קורא פעמיים ביום את קטלוג CISA KEV — רשימת הפרצות שCISA אישרה שמנוצלות בפועל בתקיפות, לא תיאורטית. הקטלוג הוא ציבורי, ללא מפתח, ומכיל אלפי רשומות שרובן חסרות משמעות לקורא ישראלי.
מכאן הכול נמצא בסינון. לכל רשומה מחושבות שלוש תכונות נפרדות, ובכוונה לא באותה רמת ודאות:
- עובדה — מה שכתוב בקטלוג עצמו: איזה CVE, איזה יצרן, מתי נוסף, מה תאריך היעד של CISA, והאם היא מסמנת שהפרצה שימשה בקמפיין כופרה. בנוסף ציון EPSS של FIRST.org — הערכה מפורסמת לסיכוי שהפרצה תנוצל ב-30 הימים הקרובים.
- מבנית — האם סוג המוצר יושב על גבול הרשת (חומת אש, VPN, שרת דואר, אתר, כלי ניהול מרחוק). זו תכונה של המוצר, לא של ישראל, והיא ההבדל בין "לעדכן החודש" ל"לעדכן הלילה".
- הערכה — כמה המוצר נפוץ בארגונים בישראל. זו לא מדידה. אין מקור חופשי שסופר מה מותקן בישראל, ולכן זו הערכה מקצועית מוצהרת, עם נימוק כתוב לכל יצרן.
הרמה 0–3 היא ספירה אחת ויחידה: כמה מוצרים היקפיים שנפוצים בישראל נוספו לקטלוג ב-7 הימים האחרונים. הספים לא נוחשו — הם נקבעו אחרי מדידה של 52 השבועות הקודמים על הקטלוג האמיתי.
How this works, briefly
Twice a day the page reads the CISA KEV catalogue — the list of vulnerabilities CISA has confirmed are being exploited in real attacks, not theoretically. It is public, keyless, and holds thousands of entries, most of them meaningless to an Israeli reader.
Everything from there is the filter. Each entry gets three separate properties, deliberately not at the same level of certainty:
- Fact — what the catalogue itself says: which CVE, which vendor, when CISA added it, CISA's due date, and whether it is flagged as used in a ransomware campaign. Plus the EPSS score from FIRST.org, a published estimate of the chance it is exploited in the next 30 days.
- Structural — whether the product class sits on the internet perimeter (firewall, VPN, mail server, website, remote-management tool). A property of the product, not of Israel, and the difference between "patch this month" and "patch tonight".
- Estimate — how widespread the product is in Israeli organisations. This is not a measurement. No free source counts what is installed in Israel, so it is a declared professional estimate with a written reason per vendor.
The 0–3 level is one single count: how many perimeter products common in Israel entered the catalogue in the last 7 days. The thresholds were not guessed — they were set after measuring the previous 52 weeks against the real catalogue.