Cyber999 Advisories

2 September 2026     Report

Quarter 2 2026 Cyber Incident Summary Report


Quarter 2 2026 Cyber Incident Summary Report

Cyber999 Incident Response Centre of CyberSecurity Malaysia

TLP WHITE

1.0 Introduction
The Cyber Incident Quarterly Summary Report Q2 2026 provides an overview of computer security incidents handled by the Cyber999 Incident Response Centre of CyberSecurity Malaysia in Q2 2026.

This quarterly Cyber Incident Report also highlights statistics of incidents dealt with by the Cyber999 Incident Response Centre in Q2 2026 according to their categories and security alerts and advisories released in this quarter. It should be noted that the statistics provided in this report reflect only the total number of incidents reported and handled by the Cyber999 Incident Response Centre, excluding elements such as monetary value or aftermaths of the incidents. Computer security incidents dealt with by the Cyber999 Incident Response Centre involved IP addresses and domains from Malaysia.

CyberSecurity Malaysia works closely with ISPs, CERTs, Special Interest Groups (SIGs) and Law Enforcement Agencies (LEAs), from local and international, to remediate and mitigate computer security incidents affecting Malaysia's organisations and the public.

2.0 Trends Q2 2026
There were 33.59 million internet users in Malaysia at the start of 2025, while Malaysia was home to 28.68 million social media users in January 2025, equating to 83.1 percent of the total population [1]. Meanwhile, a total of RM3.18 billion has been lost to online scams involving more than 95,800 victims between 2021 and April 2025 [2]. In general, the Cyber999 Incident Response Centre receives incident reports from Internet users, members of the public, home users, small and medium enterprises (SMEs), industries, academia, and non-profit organisations (NGOs). We proactively seek and gather insights on cyber threats through partnerships and collaborations worldwide that could impact Internet users and organisations in Malaysia and aid in mitigating these threats. The Cyber999 Incident Response Centre received 2,715 incidents in Q2 2026, compared to 2,188 incidents in Q1 2026. This indicates a 24.09% increase in Q2 2026.

Tables 1 to 3 below provide details of the incidents and their figures reported in Q1 2026 and Q2 2026.
Table 1: Comparison of Incidents Reported in Q1 2026 and Q2 2026

Categories of Incidents

Quarters

Percentage (%)

Q1 2026

Q2 2026

Denial of Service

5

1

     -80.00

Intrusion

64

51

-20.31

Data Breach

124

175

41.13

Intrusion Attempt

81

91

12.35

Vulnerabilities Report

26

17

-35.62

Malicious Codes

28

34

21.43

Fraud

1829

2314

26.52

Spam

31

32

3.23

TOTAL

2188

2715

    24.09

 

Table 2: Breakdown of Incidents Based on Months in Q2 2026

Categories of Incidents

April

May

June

Denial of Service

0

0

1

Intrusion

21

14

12

Data Breach

67

61

47

Intrusion Attempt

33

27

31

Vulnerabilities Report

4

4

9

Malicious Codes

12

11

11

Fraud

759

675

880

Spam

11

7

14

TOTAL

907

799

1005

 

Table 3: Breakdown of categories and sub-categories of incidents in Q2 2026

Categories and Sub-categories of Incidents

 April

May

June

Denial of Service

 

 

 

Denial of Service – DoS

0

0

1

Fraud

 

 

 

Fraud -- Bogus Email

7

8

10

Fraud – Business Email Compromise

0

0

1

Fraud – Fraud Site

9

6

3

Fraud – Impersonation & Spoofing

17

9

13

Fraud – Job Scam

2

0

1

Fraud – Love/Parcel Scam

0

0

0

Fraud -- Phishing

724

652

852

Vulnerabilities Report

 

 

 

Vulnerabilities Report – Misconfiguration Information Disclosure

2

1

 

        4

Vulnerabilities Report -- System

1

1

1

Vulnerabilities Report -- Web

1

2

4

Intrusion

 

 

 

Intrusion – Account Compromise

21

11

10

Intrusion -- Defacement

4

0

2

Intrusion Attempt

 

 

 

Intrusion Attempt – Login Brute Force

12

8

11

Intrusion Attempt – Port Scanning

1

0

0

Intrusion Attempt – Vulnerability Probes

20

19

20

Malicious Codes

 

 

 

Malicious Codes – Botnet C&C

0

1

0

Malicious Codes – Malware

7

8

10

Malicious Codes – Malware Hosting

5

2

1

 

 

 

 

Content Related 

 

 

 

Content Related – Data Breach

67

61

47

Spam

11

7

14

TOTAL

907

799

1005


Figure 1 illustrates and provides an overview of the incidents reported in Q2 2026 in a chart.  Figure 2 illustrates the percentage of incidents based on their classification.


Figure 1: Breakdown of incidents based on categories in Q2 2026

 

Figure 2: Percentage of incidents reported by categories in Q2 2026

Based on the above statistics, total incidents reported to us increased by 24.09 percent in Q2 2026 (2,715incidents) compared to Q1 2026 (2,188 incidents). In Q2 2026, the most frequently reported incidents were Fraud, Data Breach, and Intrusion Attempt. Fraud accounted for the majority, representing 85.23 percent of all reported cases (2,314 incidents), followed by Data Breach at 6.45 percent (175 incidents) and Intrusion Attempt at 3.35 percent (91 incidents). Based on the current trends, fraud incidents will most likely continue to grow in Malaysia in 2026. Data breach incidents have increased by 41.13 percent for this quarter (175 incidents compared to 124 in Q1 2026). However, organisations and Internet users are urged to take proper security measures to prevent data breaches. Meanwhile, for fraud incidents other than phishing URLs, new tactics and techniques in online scams that concatenate social engineering and malicious code could grow in Malaysian cyberspace.

2.1 Top Fraud Incidents Reported in Q2 2026
Fraud continues to prevail within the community, targeting various citizens, end users and organisations, from students to professionals, and from large to small organisations. It has become a preferred method for criminals as awareness is still lacking among the public, making them an easier target. Two thousand three hundred and fourteen fraud incidents were handled this quarter, representing a 26.52 percent increase compared to Q1 2026. All the fraud incidents were received from organisations and public users. The top fraud incidents reported to the Cyber999

Incident Response Centre are as follows:
Table 4: Top Fraud Incidents Reported in Q2 2026

Top Fraud incidents

Number of Incidents

Phishing

2228

Impersonation and Spoofing

39

Bogus Email

25

Fraudulent Website

18

Job Scam

3

Business Email compromised – BEC scam

1

Love and parcel scam

0

Our statistics show that over three-quarters of fraud incidents reported are phishing, representing 68 percent of total fraud incidents reported in Q2 2026. We observed the following phishing trends in Malaysia based on the incidents reported to us. These trends are similar in the previous quarter, Q1 2026.

a. Contextualised and Localised Phishing Themes 
Government Aid Scams: Phishing emails or SMS impersonate legitimate government programs (e.g., bantuan/sumbangan kerajaan), offering financial aid but requiring victims to provide personal details or click malicious links.  

Fake Promotions and Discounts: Popular brands like Lazada, Shopee, or local retailers are spoofed, luring victims with fraudulent discounts or free vouchers. 

Traffic Summons Scams: Messages claim unpaid police summons, providing fake payment links to steal financial credentials. 

Subscription Services: Services like Netflix or Spotify are impersonated, tricking victims into renewing subscriptions or fixing payment issues on fake websites. 

b. Mobile-Focused Phishing (Smishing and App-Based) 
Smishing (SMS Phishing): Attackers send fraudulent SMS messages mimicking banks, e-wallets, or delivery services (e.g., J&T, Pos Malaysia) with malicious links. 

c. Phishing Calls (Vishing) 
Phone Scams: Attackers impersonate government agencies (e.g., police or LHDN, MCMC), banks, companies, or even CyberSecurity Malaysia, pressuring victims to disclose sensitive information. Common tactics include threats of legal action, account suspension, or overdue payments. 

Therefore, Internet users and organisations must be vigilant when conducting online transactions or performing e-commerce transactions to avoid becoming victims of online fraud.

 
2.2 Top Malware Incidents Reported in Q2 2026
The top malware incidents include malware hosting, ransomware, malicious APK, backdoors, and trojans. The top reported malware incidents are related to malicious APKs. This type of incident is typically received from Internet banking users and sometimes from local financial institutions.

A malicious APK is an Android Package (APK) file containing malware designed to harm devices, steal data, or perform unauthorised actions. APK files are used to distribute and install applications on Android devices, and malicious versions exploit this format to spread malware. They often mimic popular apps (e.g., social media, games, or utilities) to trick users into downloading. Attackers may distribute these files through phishing emails, social media, fake websites, or third-party app stores.

Table 5: Types of Malicious APKs Reported in Q2 2026

Malicious APK

Total

com.amazon.venezia

1

collector.navigator.aggregator

1

MaxTagDiscount.apk

1

StatementofDebts-.vbs

2

Klinik Pergigian Ophelia.vbs

1

irm steamox.com|iex

1

Steamweb64.exe

1

Unknown APK

1

The second top-reported incident within the malware category is malware hosting. Malware hosting primarily targeted vulnerable servers with outdated security patches and updates. These incidents are usually received from foreign entities, such as antivirus vendors and special interest groups, regarding servers in Malaysia that are hosting malware. System Administrators must be vigilant and keep systems up to date with the latest patches and security updates to prevent servers from being compromised and hosting malware.

Ransomware incidents remained steady at 12 incidents in Q2 2026 (the same as 12 incidents in Q1 2026). Nevertheless, organisations must remain vigilant. Ransomware is malicious software (malware) that infects a computer and restricts access until the requested ransom is paid. It is also considered one of the costliest and most devastating attacks, as it is enormous to recover all the data and rectify infected machines.

Our findings identified that businesses are most impacted by ransomware incidents in Malaysia, consistent with trends across the globe. Active Directory (AD) servers have become primary targets in Malaysia. Compromising AD servers can significantly amplify the impact of a ransomware attack. Using tools like PsExec, Group Policy Objects (GPOs), or Windows Management Instrumentation (WMI) to execute ransomware on all connected systems. Ryuk and Conti have been observed targeting AD servers for mass deployment and faster network-wide encryption. We also observed attackers exploiting vulnerabilities in virtualisation platforms like VMware, and ESXi servers can be targeted directly, allowing attackers to gain control over multiple VMs simultaneously. Ransomware operators use phishing attacks, brute force, or stolen credentials to access VM management consoles or servers. LockBit has been observed deploying scripts to attack VMware environments, including deleting backups and snapshots.

Looking at the current trends, ransomware incidents will continue to grow in Malaysia in 2026. Organisations, especially businesses, must always take proper security measures against ransomware incidents. Good backup management, system and network configuration, patch management and password security, with cyber security awareness are essential in combating ransomware. Implementing good backup procedures, policies, and best practices among organisations and public users is also essential in mitigating ransomware attacks.

Table 6: Ransomware Variants Reported in Q2 2026

Ransomware Variant 

Number of Incidents

SHINYHUNTERS Ransomware

1

Payload Ransomware

1

Mario Ransomware

1

White Rabbit Ransomware

1

BlackCat (ALPHV)

1

Gentlemen Ransomware

1

MedusaLocker Ransomware

2

Lamashtu Ransomware

1

Qilin Ransomware

1

NA (Not identified specific name of the ransomware)

4

Apart from ransomware and malware hosting, we also handled incidents related to infostealers in Q2 2026. Infostealer is malicious software created to breach computer systems and steal sensitive information, including login details. Generally, data from the infostealers contained login credentials from various sources, including information saved on web browsers (such as passwords and credit logins), auto-filled logins, FTP clients, email apps, instant messaging clients, and VPNs.

Below is a list of infostealers associated with data breaches reported to us in Q2 2026:

Table 7: Info stealers reported in Q2 2026

Types of Info Stealers

Number of Incidents

PRIMO CLOUD InfoStealer

1

FRESH InfoStealer

1

ClickFix

1

VIDAR Stealer

8

 

2.3 Data Breach Incidents Growing in Malaysia
Data breach incidents are growing in Malaysia, with a 41.13 percent increase this quarter (175 cases in Q2 2026 compared to 124 cases in Q1 2026), underscoring the need for better security measures to ensure national security and public trust. High-profile breaches often involve massive datasets, including personal identifier information (PII) like identification numbers, addresses, and financial details, and often involve PII from national databases. Serious security measures must consistently be implemented to prevent and mitigate data breaches, especially for personal data.

We identified that a large number of data breaches are preceded by ransomware attacks, whereby attackers exfiltrate data from ransomware-impacted organisations and sell them in the dark web. Perpetrators exfiltrate or steal sensitive data from organisations and hold the data hostage in the majority of ransomware attacks. Perpetrators will then threaten the organisation to release or sell the data on the dark web unless the organisation pays ransom within a timeframe set by the perpetrators. In the case of extortion by perpetrators, we always advise organisations to refer the matter to the LEAs, such as the police, for assistance. Other trends we observed in this quarter include the resurfacing of previous data breaches. Perpetrators claimed and posted on the dark web that they have recently breached data belonging to specific organisations.

However, our cross-checks confirmed these are resurfacings of previous data breaches that happened a few years back and not new breaches.

Table 8: Data Breaches Reported in Q2 2026

Types of Data Breach

 

Description

Personal Identifier Information (PII)

Full name, identity card numbers, home address, age, handphone

number, date of birth, and salary.

 

Account Credential

Username and password of email accounts, username and password

of Internet banking accounts.

 

Appliances Credential

Admin panel access, Joomla, wordpress, ftp access, wp-admin access and etc.

 

 

3.0 Security Advisories and Alerts Released in Q2 2026
In Q2 2026, the Cyber999 Incident Response Centre issued 73 Security Advisories and one Alert. Each with descriptions, mitigation steps, and recommendations for organisations and Internet users to follow. The security advisories involved Mozilla, Microsoft, Apple, VMware, and several other CVEs listed in Table 10. The security alerts concern growing online fraud and malware threats that we identified as potentially serious to citizens and organisations in Malaysia. If not correctly identified and mitigated, such threats could have serious consequences for citizens and organisations.

Table 10: List of Significant CVEs in Q2 2026
Here is the table with the CVEs and their descriptions:

CVE ID

Description

CVE-2026-41940

 WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

 

May allow an unauthenticated attacker to bypass authentication and gain administrative-level access to affected cPanel, WHM, or WP Squared (WP2) systems.

CVE-2026-7431

Remote code execution vulnerability in Ivanti Secure Access Client.

 

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.

CVE-2026-7432

Privilege escalation / information disclosure vulnerability in Ivanti Secure Access Client.

 

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

CVE-2026-8043

Unauthorized access or possible code execution vulnerability in Ivanti Xtraction.

 

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

CVE-2026-8051

Service disruption or remote code execution vulnerability in Ivanti Virtual Traffic Manager (vTM)

 

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVE-2026-8110

Privilege escalation vulnerability in Ivanti Endpoint Manager (EPM).

 

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

CVE-2026-8111

Information disclosure vulnerability in Ivanti Endpoint Manager (EPM).

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

CVE-2026-0300

PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal

 

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses. Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.

CVE-2026-23918

Apache HTTP Server: http2: double free and possible RCE on early reset

 

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-24072

Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr

 

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-28780

Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()

 

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-29168

Apache HTTP Server: mod_md unrestricted OCSP response

 

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-29169

Apache HTTP Server: mod_dav_lock indirect lock crash

 

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

CVE-2026-33006

Apache HTTP Server: mod_auth_digest timing attack

 

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-33007

Apache HTTP Server: mod_authn_socache crash

 

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVE-2026-33523

Apache HTTP Server: HTTP response splitting forwarding malicious status line

 

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-33857

Apache HTTP Server: Off-by-one OOB reads in AJP getter functions

 

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-34059

Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()

 

Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVE-2026-42838

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

 

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-40416

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

 

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network

CVE-2026-41107

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

 

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

CVE-2026-42838

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

 

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-34291

Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE

 

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

 

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root. Note: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root. Note: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.

CVE-2022-0492

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

CVE-2026-28318

SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability

 

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update

CVE-2026-50751

User Authentication Bypass in VPN Remote Access and Mobile Access

 

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVE-2026-11645

Out of bounds read and write in V8 in Google Chrome

 

Allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2026-20245

Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

 

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user. To exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices. Cisco recommends that customers upgrade to the fixed software that is documented in the that was published on May 14, 2026, and verify the configuration of the edge devices.

CVE-2026-20262

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

 

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

CVE-2026-35273

PeopleSoft Enterprise PeopleTools

 

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools.

CVE-2026-54420

Remote Administration Daemon component

 

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data.

CVE-2026-49261

MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`

 

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a workaround, anyone who cannot upgrade now should disable `wsrep_notify_cmd`.

CVE-2026-48165

MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side

 

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

CVE-2026-48163

MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)

 

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the rsync SST method. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

CVE-2026-42530

NGINX Open-Source ngx_http_v3_module vulnerability

 

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42055

NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability

 

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

 

4.0 Conclusion
Overall, the number of computer security incidents reported to the Cyber999 Incident Response Centre in Q2 2026 was 2,715, representing an increase of 24% compared to Q1 2026. No significant or severe incidents were observed during this quarter. Nevertheless, organisations and individuals must always be vigilant with readiness and preventive and mitigation steps against potential threats. Perpetrators are very motivated, eager, and determined to use new and sophisticated tactics and techniques to execute cyber-attacks.

Hence, we strongly recommend that all internet users be constantly aware of today's cybercrime trends and adhere to the best cyber hygiene practices. This also includes secure handling of emails from unknown sources, safe web browsing, purchasing goods online, and using social media applications. Users must keep systems up to date with the latest security patches and updates to prevent their computers from being compromised or infected with malware. Always check the legitimacy of the applications, portals, merchants, services, and products before conducting any online transaction.

As the complexity of cyber threats continues to increase, organisations and individuals could be potential targets if they are not equipped with security awareness. Providing security awareness campaigns to citizens and organisations is among the best efforts to improve national cyber security and public trust

Malaysian Internet users and organisations may contact us to report cyber security incidents at the below contact:

E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 08:30 -17:30 MYT
Web: https://www.cybersecurity.my


5.0 References:

[1] https://datareportal.com/reports/digital-2025-malaysia

[2] https://www.nst.com.my/business/economy/2025/08/1090337/rm32b-lost-online-scams-between-2021-and-april-2025-gobind

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed