Skip to content

company

WatchTowr

WatchTowr is a cybersecurity research firm whose watchTowr Labs and Attacker Eye units track real-world exploitation of newly disclosed vulnerabilities.

Known aliases

  • Attacker Eye
  • watchtower
  • WatchTowr
  • watchTowr Intel
  • watchTowr Labs
  • watchtwr

Relationships

No evidence-backed relationships are recorded.

Current stories

security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
security5 publishers

SharePoint flaw CVE-2026-65660 came under attack within days of Viettel's technical write-up

Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 68%
Investor
Investor 6%

Reality

Evidence74
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence70
security5 publishers

Exploited within hours: MLflow SSRF and FUXA auth bypass join the emergency patch list

watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence72
Adoption55
Hype gap+20
Incentives35
Confidence70
security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
security5 publishers

Kiteworks tells customers to shut down even internal file-sharing servers for six hours

Kiteworks told customers worldwide to power off its file-sharing servers for six hours on September 26 after a federal warning of a possible attack. Servers with no internet exposure are included, so being on release 9.5.1 with every known fix does not by itself clear a customer.

Perspective Coverage

5 publishers
Builder
Builder 18%
Operator
Operator 73%
Investor
Investor 9%

Reality

Evidence58
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence62
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74
security10 publishers

Chained PaperCut flaws let unauthenticated requests load attacker Java into the server process

Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.

Perspective Coverage

10 publishers
Builder
Builder 27%
Operator
Operator 60%
Investor
Investor 13%

Reality

Evidence85
Adoption70
Hype gap−10
Incentives40
Confidence78
security6 publishers

Unauthenticated attackers can forge admin tokens on default self-managed Artifactory installs

CVE-2026-82329 is reported as a pre-auth authentication bypass in JFrog Artifactory's Access microservice, and it reaches every dependency your builds pull from the platform. One publisher, no vendor advisory.

Publishers:bleepingcomputer.comcvereports.comdocs.jfrog.comscworld.comsecurityweek.comthehackernews.com

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 63%
Investor
Investor 9%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence64
security13 publishers

CISA's seven new KEV entries put SonicWall gateways and Artifactory on one patch clock

SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.

Perspective Coverage

13 publishers
Builder
Builder 24%
Operator
Operator 63%
Investor
Investor 13%

Reality

Evidence72
Adoption30
Hype gap+15
Incentives55
Confidence68
build3 publishers

A file.path parameter in GitLab's commit API reads server files before authentication

The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.

Publishers:dev.todocs.gitlab.comwatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 73%
Investor
Investor 5%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives45
Confidence74

Earlier coverage

  1. Two Artifactory flaws turned an anonymous JWT into admin in under five minutes

    Security · September 11, 2026 · 4 publishers

  2. CISA sets a September 13 deadline for the MikroTrick RouterOS chain

    Security · September 12, 2026 · 13 publishers

  3. Forged admin JWTs are landing on WSO2 API Manager four months after the fix shipped

    Security · September 16, 2026 · 2 publishers

  4. Attackers began probing WSO2's JWT bypass 133 days after the fixes went out

    Build · September 17, 2026 · 2 publishers

  5. Artifactory's access layer trusted an empty join key in a default install

    Build · September 19, 2026 · 1 publisher

  6. F5 fixes CVE-2026-94127 by capping the Authorization header at 16,640 bytes

    Security · September 23, 2026 · 1 publisher

  7. N-able's fourth hotfix is the one that closes the N-central code injection

    Build · September 19, 2026 · 1 publisher

  8. An empty string in Artifactory's default join keys mints a platform admin token

    Build · September 17, 2026 · 1 publisher

  9. Scanning for CVE-2026-82329 hit 406,000 attempts five days after JFrog disclosed it

    Security · September 17, 2026 · 3 publishers

  10. Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest

    Build · September 14, 2026 · 1 publisher

  11. Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers

    Security · September 5, 2026 · 4 publishers

  12. A manipulated Bearer header escalates privileges in Cleo Harmony through 5.8.1.10

    Security · September 3, 2026 · 2 publishers

  13. Artifactory's default configuration hands admin tokens to unauthenticated callers

    Build · September 1, 2026 · 1 publisher

  14. A NetScaler web shell survives the patch that closes CVE-2026-8452

    Build · August 29, 2026 · 1 publisher

  15. GeoServer's jsonArrayContains filter is being probed at scale, with no patch and no CVE

    Build · August 14, 2026 · 1 publisher