■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses. Curated from NCSC, CISA, FCA ScamSmart, and ICO intelligence feeds.

[ LAST UPDATED: 10 May 2026 at 10:26 UTC ]

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC FRI, 01 MAY 2026

Preparing for a ‘vulnerability patch wave’

Read NCSC Advisory →
NCSC MON, 27 APR 2026

Could your choice of metrics be harming your SOC?

Read NCSC Advisory →
NCSC THU, 23 APR 2026

Passkeys are more secure than traditional ways to log in

Read NCSC Advisory →
NCSC THU, 23 APR 2026

Executive Summary: Defending against China-nexus covert networks of compromised devices

Read NCSC Advisory →
NCSC THU, 23 APR 2026

Supporting AI adoption for UK cyber defence

Read NCSC Advisory →
NCSC THU, 23 APR 2026

Defending against China-nexus covert networks of compromised devices

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-05-08
CVE-2026-42208 — BerriAI | LiteLLM

BerriAI LiteLLM Vulnerability

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.

View CISA Advisory →
CISA KEV CRITICAL 2026-05-07
CVE-2026-6973 — Ivanti | Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

View CISA Advisory →
CISA KEV CRITICAL 2026-05-06
CVE-2026-0300 — Palo Alto Networks | PAN-OS

Palo Alto Networks PAN-OS Vulnerability

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

View CISA Advisory →
CISA KEV CRITICAL 2026-05-01
CVE-2026-31431 — Linux | Kernel

Linux Kernel Vulnerability

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

View CISA Advisory →
CISA KEV CRITICAL RANSOMWARE KNOWN 2026-04-30
CVE-2026-41940 — WebPros | cPanel & WHM and WP2 (WordPress Squared)

WebPros cPanel & WHM and WP2 (WordPress Squared) Vulnerability

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

View CISA Advisory →
CISA KEV CRITICAL 2026-04-28
CVE-2024-1708 — ConnectWise | ScreenConnect

ConnectWise ScreenConnect Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD FRIDAY, MAY 8, 2

Convicted money launderer sentenced to extra prison time

A convicted money launderer has been sentenced to an additional 499 daysin prison for failing to fully pay the money owed under a Confiscation Order. In 2021,RichardFaithfull,now36,wassentenced to5 years and 10 monthsin...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD FRIDAY, MAY 1, 2

Three arrested in FCA investigation into suspected unlawful financial promotions

Three people have been arrested as part of a crackdown on suspected illegal financial promotions. Two homes in the Chelmsford and Romford areas were searched, as part of an operation led by the FCA and the Eastern Regio...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, APRIL

A reform-minded regulator

Speech by Nikhil Rathi, FCA chief executive, at the Association of Foreign Banks (AFB) luncheon. When I saw that a boxing ring had been temporarily installed in this room last autumn, I wasn’t quite sure whether it was...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, APRIL

FCA charges Shaun Lawrence for unauthorised mortgage broking

The FCA has charged Shaun Lawrence for operating as a mortgage broker without authorisation. Mr Lawrence, who also goes by the names Shaun Lawrence-Bright and Shaun Bright, was previously authorised to give mortgage adv...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD WEDNESDAY, APRIL

LCM Family Limited enters administration

On 28 April 2026, LCM Family Limited (LCM) went into administration. Louise Longley and Gary Shankland of BTG Begbies Traynor (Central) LLP were appointed as joint administrators of the firm. The joint administrators ar...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.