An unauthenticated attacker can exploit vulnerable PAN-OS GlobalProtect configurations to execute arbitrary commands with root privileges. CISA added the issue to its Known Exploited Vulnerabilities Catalog.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe product-security incidents through ENISA’s Single Reporting Platform.
24h early warning72h full notification14d / 1mo final report
Choose a scenario to see how technical facts become a regulatory reporting decision.
COMPLYIT ASSESSMENT
Likely reportable
Start the NIS2 assessment immediately. Preserve detection time, affected services, impact, indicators and the decision trail for the 24-hour early warning.
A first-time sign-in from an unexpected country reaches a managed service environment. Is it a security event, a significant incident or a reportable personal data breach?
Malicious code in XZ Utils 5.6.0 and 5.6.1 can modify liblzma during the build process. Identify affected Linux packages and replace them with trusted versions.
A signal-handler race condition in vulnerable OpenSSH servers may allow unauthenticated remote code execution. Upgrade to a fixed release and restart sshd.