SMB Security

Critical Zero-Click Outlook RCE: CVE-2026-40361 Demands Immediate Patching

A zero-click remote code execution vulnerability in Microsoft Outlook (CVE-2026-40361) allows attackers to compromise any Outlook user by simply sending a crafted email — no clicks required. Patched in Microsoft's May 2026 Patch Tuesday update, this CVSS 8.4 flaw affects all supported Office and Microsoft 365 Apps versions. SMBs must patch immediately.

Continue Reading

Critical Palo Alto PAN-OS Zero-Day (CVE-2026-0300): What SMBs Must Do Now

A critical, unauthenticated remote code execution vulnerability (CVE-2026-0300, CVSS 9.3) in Palo Alto Networks PAN-OS firewalls is being actively exploited by a state-sponsored threat group. Patches are not yet available. Here is what SMBs need to do right now to protect their networks.

Continue Reading
Scroll to top