■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement ■ GET-IT Intelligence

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses — plus original analysis, commentary, and real-world case studies from GET-IT. Curated from NCSC, CISA, FCA ScamSmart, ICO intelligence feeds, and our own research.

[ LAST UPDATED: 27 August 2026 at 10:29 UTC ]
█ New — MITRE-Lite Weekly

Our plain-English translation of the MITRE ATT&CK framework — who is targeting UK businesses this week, how they operate, and what to do about it. Updated every Monday.

Business Owner Edition → Technical Edition →

Analysis, Commentary & Case Studies

Browse all GET-IT Reads →

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC THU, 20 AUG 2026

Managing the cyber risk of agentic AI

Read NCSC Advisory →
NCSC THU, 13 AUG 2026

How BitLocker PINs help protect your data and devices

Read NCSC Advisory →
NCSC WED, 12 AUG 2026

Help shape the future of resilient private 5G

Read NCSC Advisory →
NCSC TUE, 11 AUG 2026

Water sector example added to the NCSC’s Secure connectivity principles

Read NCSC Advisory →
NCSC TUE, 04 AUG 2026

NCSC statement in response to recent incidents resulting from frontier AI evaluations

Read NCSC Advisory →
NCSC WED, 29 JUL 2026

Making forensic observability the norm for network devices

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-08-26
CVE-2021-23758 — Ajax.NET Professional | Ajax.NET Professional

Ajax.NET Professional Ajax.NET Professional Vulnerability

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-26
CVE-2015-3246 — Red Hat | Libuser

Red Hat Libuser Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-26
CVE-2015-5287 — Red Hat | Automatic Bug Reporting Tool

Red Hat Automatic Bug Reporting Tool Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-26
CVE-2022-0995 — Linux | Kernel

Linux Kernel Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-26
CVE-2026-8452 — Citrix | NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

View CISA Advisory →
CISA KEV CRITICAL 2026-08-26
CVE-2019-1068 — Microsoft | SQL Server

Microsoft SQL Server Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD WEDNESDAY, AUGUS

EGR Wealth Limited enters administration

On 24 August 2026, EGR Wealth Limited (EGR Wealth) entered administration. Robert Goodhew and Geoff Bouchier of Kroll Advisory Limited were appointed joint administrators. The joint administrators are responsible for ma...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, AUGUST

Consumers warned to beware of risky mini-bonds and loan notes

The FCA is warning consumers about the risks of investing in loan notes and mini-bonds issued by unregulated companies, after continuing to see people lose money in these high-risk investments. The recent failure of Woo...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, AUGUST

Unregulated loan notes and mini-bonds: don't risk your savings on promises of high returns

These high-risk investments should not usually be advertised widely to the public. We banned the marketing of speculative mini-bonds and loan notes to ordinary retail investors from 1 January 2021.We did this because th...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, JULY 3

Trial date set for individual charged with illegal promotions

On 30 July 2026, Lucy Beck attended Southwark Crown Court for a hearing in relation to unauthorised promotions on social media. Ms Beck entered a not guilty plea and the date of her trial has been set as 12 June 2028.It...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, JULY 3

Blue Motor Finance Limited enters administration

On 30 July 2026, Blue Motor Finance Limited (BMFL) was placed into administration. Simon Edel, Richard Barker and Alan Michael Hudson of Ernst & Young LLP were appointed as joint administrators. BMFL (firm reference...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.