Urgent Patches

Stories 130
Sources 385
Updated 2026.07.25
Rockwell patches four Arena Simulation software flaws that can let malicious files run code on Windows systems
Rockwell Automation fixed four vulnerabilities in its Arena Simulation software that could let an attacker run code if a user opens a booby-trapped simulation file. The flaws are CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314, all high-severity memory corruption bugs affecting Arena versions through 17.00.00; they are patched in 17.00.01. Exploitation requires user interaction rather than direct remote access, and CISA and Rockwell say there is no evidence of in-the-wild exploitation. — Organizations that use Arena in industrial, supply-chain, healthcare, or defense environments should update and treat Arena model and experiment files as potentially dangerous. The immediate action is to upgrade to 17.00.01 and warn users not to open untrusted Arena files sent by email or other channels.
Sources: Rockwell Patches Code Execution Flaws in Arena Simulation Software
Bluetooth flaw in KARR and SWDS dealer-installed car security systems can unlock or disable millions of vehicles
Researchers say at least 2.2 million vehicles with KARR and SWDS aftermarket security systems can be attacked over Bluetooth from nearby, allowing doors to be unlocked or a stopped car to be prevented from starting. UC San Diego found the Acrisure-made devices relied on the same cryptographic key across units, enabling unauthorized Bluetooth access within about five yards. Affected vehicles were reportedly sold through thousands of dealerships, especially Southern California Honda, Toyota, Mazda, Ford, and Jeep dealers, and KARR says firmware updates are available. — Car owners may be at risk even if they declined the dealer security service, because the hardware can remain installed and active. Anyone with an affected vehicle should check for KARR or SWDS equipment and apply the vendor's firmware update as soon as possible.
Sources: Millions of California-bought cars can be hijacked via Bluetooth, In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
CISA says attackers are exploiting PTC Windchill and FlexPLM remote-code-execution flaw CVE-2026-12569
Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog. — This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.
Sources: First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild, CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue, CISA sets urgent deadline to fix Cisco flaw exploited in attacks (+1 more)
Oracle's first monthly Critical Security Patch Update fixes 77 vulnerabilities across Database, E-Business Suite, REST Data Services and other products
Oracle released its first new monthly Critical Security Patch Update, fixing 77 vulnerabilities across several enterprise products used by businesses and public-sector organizations. The May 2026 update covers Oracle Database Server, REST Data Services, Communications, E-Business Suite, and Hospitality Applications, including about a dozen critical-severity flaws and multiple bugs that remote, unauthenticated attackers could exploit over a network. Oracle did not cite active exploitation in this notice but urged customers to patch quickly. — Organizations running affected Oracle software should treat this as a prompt patching event, especially where systems are internet-facing. Several flaws can be exploited remotely without logging in, so defenders should identify exposed Oracle services and apply the new updates as soon as possible.
Sources: Oracle’s First Monthly Patches Resolve 77 Vulnerabilities, Oracle’s Second Monthly Security Updates Deliver 245 Patches, Oracle drops 1,449 security patches like it's the new normal
RefluXFS Linux flaw can give local users root on default Red Hat Enterprise Linux systems
A newly publicized Linux vulnerability can let a normal user take full control of affected Red Hat Enterprise Linux systems. The flaw, dubbed RefluXFS, is described as a nine-year-old local privilege-escalation issue affecting default RHEL installations through the XFS file system; the article indicates local access is required and the impact is root-level compromise. The provided text does not include a CVE ID or patch details. — Organizations running RHEL should treat this as a high-priority hardening and patching issue because a low-privilege user or intruder who already has a foothold could turn that access into full system control. Admins should identify affected RHEL systems and review vendor guidance or updates immediately.
Sources: Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs, New RefluXFS Linux flaw lets attackers gain root privileges
Check Point patches SmartConsole zero-day CVE-2026-16232 after attacks bypassed authentication on management servers
Check Point says attackers are exploiting a flaw in its SmartConsole management software that can let outsiders get administrator-level access to some internet-exposed management servers. The zero-day, CVE-2026-16232, is an authentication bypass in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS); unauthenticated attackers can obtain an application login token and change security policies if the management server is reachable from the internet and Trusted Clients are not restricted. — Organizations using Check Point management servers could have their security settings changed by an attacker without a valid login, potentially weakening network defenses. This is urgent: patch immediately, restrict management access to trusted IPs, and review SmartConsole audit logs for the application-token indicators Check Point provided.
Sources: Check Point warns of SmartConsole zero-day exploited in attacks, Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access, New Check Point Zero-Day Vulnerability Exploited in the Wild
Adobe patched CVE-2026-48294 in Acrobat Chrome extension that could expose WhatsApp Web chats
Adobe fixed a flaw in its Acrobat extension for Chrome that could let a malicious website read private WhatsApp Web conversations from a victim's browser. Guardio tracked the issue as CVE-2026-48294, affecting Adobe Acrobat Chrome extension versions 26.5.2.1 and below; the attack used forged extension messages and WhatsApp integration features to redirect privileged page-control actions into an open WhatsApp Web tab, with no authentication needed beyond luring a user to an attacker-controlled page. — People using both WhatsApp Web and the Adobe Acrobat Chrome extension could have had chat contents exposed just by visiting a malicious page. Users should make sure the extension is updated to 26.5.2.3 or later, and organizations may want to review whether the extension is necessary in managed browsers.
Sources: Adobe Chrome extension flaw let sites access private WhatsApp chats, Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft, Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
CISA adds exploited Langflow remote-code-execution flaw CVE-2026-0770 to KEV and orders federal agencies to patch
CISA warned that attackers are actively exploiting a critical flaw in Langflow, an AI workflow framework, and told U.S. federal agencies to fix it by Friday. The bug, CVE-2026-0770, allows unauthenticated remote code execution as root via the /api/v1/validate/code endpoint through the exec_globals parameter. KEVIntel observed exploitation attempts and payloads aimed at reconnaissance, malware delivery, and theft of AWS credentials, environment variables, and container metadata. — Organizations running internet-exposed Langflow servers may already be at risk of full server compromise and cloud credential theft. Patch or isolate affected systems immediately, review logs for requests to the validation endpoint, and rotate potentially exposed secrets if compromise cannot be ruled out.
Sources: CISA orders urgent action on actively exploited Langflow RCE flaw
Oracle July 2026 Critical Patch Update fixes 1,434 CVEs across Database, E-Business Suite, PeopleSoft, MySQL, Java, and other products
Oracle released its July 2026 Critical Patch Update, fixing security flaws across hundreds of products used by businesses, governments, and healthcare organizations. Oracle says the update includes 1,449 patches for 1,434 unique CVEs across 334 products, with roughly 600 vulnerabilities remotely exploitable without authentication. Heavily affected product lines include E-Business Suite, Fusion Middleware, Communications, and PeopleSoft. — Organizations running Oracle software may be exposed to internet-reachable flaws that attackers can exploit without logging in, so this is a high-priority update cycle. Administrators should review Oracle’s July 2026 CPU immediately and patch exposed Oracle systems, especially E-Business Suite, Fusion Middleware, Communications, and PeopleSoft deployments.
Sources: Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Attackers exploit critical WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to install webshells
Hackers are actively breaking into vulnerable WordPress sites and planting backdoors that let them keep control of the server. The 'wp2shell' chain affects WordPress Core and abuses the REST API batch-processing feature to achieve unauthenticated remote code execution using CVE-2026-63030 and CVE-2026-60137. WordPress patched the issue in versions 7.0.2, 6.9.5, and 6.8.6, and researchers observed malicious plugins, rogue admin accounts, and PHP webshells being deployed. — WordPress powers a large share of the public web, so active exploitation creates immediate risk for website owners, businesses, and users of compromised sites. Organizations running WordPress should update immediately, review plugins and admin accounts, and check for webshells or unusual REST API activity.
Sources: Critical wp2shell WordPress flaws exploited to install webshells
OpenSSL fixes HollowByte denial-of-service flaw that can permanently bloat server memory with an 11-byte TLS payload
OpenSSL fixed a denial-of-service flaw called HollowByte that lets an unauthenticated attacker send a tiny crafted Transport Layer Security (TLS) handshake message and drive up server memory use. Okta said vulnerable OpenSSL versions allocate memory based on a claimed handshake length before the data arrives, allowing repeated 11-byte requests to fragment memory and keep resident memory high until restart. The fix is in OpenSSL 4.0.1 and backported to 3.6.3, 3.5.7, 3.4.6, and 3.0.21; no CVE was assigned. — OpenSSL sits underneath many web servers, apps, and Linux systems, so this can affect a wide range of internet-facing services even though it is not a code-execution bug. Organizations should update OpenSSL promptly and verify dependent services such as NGINX, Apache, and application runtimes are using fixed builds.
Sources: HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload, OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Fortinet patches critical FortiSandbox bug CVE-2026-25089 that lets attackers run code without logging in
Fortinet fixed a critical flaw in FortiSandbox that could let an attacker take over affected appliances over the internet without a password. The bug, CVE-2026-25089, is an OS command injection issue in the FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS web interface, exploitable via crafted HTTP requests for arbitrary command execution. Fixes shipped in FortiSandbox 5.0.6 and 4.4.9, FortiSandbox Cloud 5.0.6, and FortiSandbox PaaS 5.0.6; Fortinet also patched two medium-severity flaws in FortiOS, FortiProxy, and FortiPortal. — Organizations using FortiSandbox should update quickly because this is the kind of bug that can allow full remote compromise of a security appliance. Even though Fortinet says it has no evidence of attacks yet, internet-facing management interfaces are high-risk and should be patched or tightly restricted immediately.
Sources: Critical Vulnerabilities Patched in Fortinet, Ivanti Products, Critical Fortinet FortiSandbox flaws now exploited in attacks, Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week (+5 more)
CISA adds exploited Microsoft SharePoint zero-day CVE-2026-58644 to KEV catalog
CISA says a newly tracked Microsoft SharePoint server flaw is already being used in real attacks, putting organizations with exposed SharePoint systems at immediate risk. The agency added CVE-2026-58644, a remote-code-execution vulnerability, to its Known Exploited Vulnerabilities catalog, meaning attackers can run code on vulnerable servers; the article indicates active exploitation but the provided text does not include affected versions or patch details. — Organizations running SharePoint should treat this as urgent because attackers are already exploiting it in the wild. Defenders should identify exposed SharePoint servers, apply Microsoft fixes or mitigations as soon as available, and hunt for signs of compromise immediately.
Sources: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV, Fresh SharePoint Vulnerability Exploited Soon After Disclosure, Attackers target critical FortiSandbox flaws as CISA issues patch order
Google fixes Android 16 Gemini lock-screen bug that let attackers send SMS and WhatsApp messages without a PIN
Google says it is fixing an Android 16 bug that could let someone holding an unlocked phone use Gemini on the lock screen to send SMS or WhatsApp messages without entering the device PIN. The issue affects devices with Gemini lock-screen access enabled and relies on a specific multi-touch gesture that bypasses an authentication prompt when Gemini asks to open Messages or connect apps such as WhatsApp; no CVE is cited, and Google said the fix was scheduled to deploy this week. — Anyone whose phone is briefly stolen or handled by someone else could be impersonated in texts or messaging apps, which raises fraud and account-recovery risks. Android users should install the fix as soon as it arrives and consider disabling Gemini lock-screen access until patched.
Sources: Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
CISA says attackers are exploiting Microsoft SharePoint remote-code-execution flaw CVE-2026-45659
CISA warned that attackers are now actively exploiting a Microsoft SharePoint server flaw that can let a low-privilege user run code on vulnerable systems. The bug, CVE-2026-45659, is a deserialization issue in SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition; Microsoft released fixes on May 21, 2026 after the CVE was omitted from its May security update listing. CISA added it to the Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch by Saturday. — Organizations running on-premises SharePoint, especially internet-exposed servers, should treat this as urgent because attackers can exploit it remotely with only Site Member-level access. Patch immediately, review internet exposure, and check for signs of compromise on SharePoint servers.
Sources: CISA: Microsoft SharePoint RCE flaw now actively exploited, CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability, Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list (+4 more)
Attackers begin exploiting Oracle E-Business Suite Payments flaw CVE-2026-46817
Attackers have started probing and exploiting a critical Oracle E-Business Suite bug that can let outsiders take over the Payments component without logging in. The flaw, CVE-2026-46817, affects the File Transmissions component in Oracle E-Business Suite Payments and can be exploited over HTTP by an unauthenticated attacker. Oracle patched it in late May 2026 in its first monthly Critical Security Patch Update, and Defused says it saw the first exploitation attempts hit EBS honeypots over the weekend. — Organizations running Oracle E-Business Suite Payments now face real attack activity, not just a theoretical flaw. This is patch-now territory for internet-exposed systems, especially where payment workflows are involved.
Sources: Exploitation of Recent Oracle E-Business Suite Vulnerability Begins, Over 900 Oracle E-Business instances exposed to ongoing attacks, Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released (+1 more)
Zoom warns of critical Windows flaw CVE-2026-53412 that could let attackers take over accounts
Zoom says a critical flaw in its Windows desktop client and related software could let an unauthenticated attacker hijack user accounts over the network. The issue, CVE-2026-53412, is rated 9.8/10 and affects Zoom Workplace for Windows before 7.0.0, the Windows VDI client before 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before 7.0.0. Zoom described it as improper input validation and said users should install the latest updates; no in-the-wild exploitation was reported at disclosure. — Zoom is used by millions of people and organizations, so a network-reachable account-takeover flaw is high impact even without confirmed active attacks. Organizations and individual users running affected Windows versions should update immediately and review where Zoom Workplace, VDI deployments, or the Meeting SDK are installed.
Sources: Zoom warns of critical account takeover vulnerability, Zoom Patches Critical Windows Flaw That Could Enable Account Takeover, Splunk, Zoom Patch Critical Vulnerabilities
Splunk patches three product flaws in Splunk Enterprise, including path traversal and credential exposure bugs
Splunk released security updates for Splunk Enterprise that fix vulnerabilities attackers could use to access credentials and data, write files outside intended directories, or view stored credential hashes. The Splunk-specific issues are CVE-2026-20296, a high-severity command safeguards bypass; CVE-2026-20297, a high-severity path traversal flaw; and CVE-2026-20298, a medium-severity information disclosure bug. Fixes are in Splunk Enterprise 10.4.1, 10.2.5, 10.0.8, and 9.4.13. — Organizations running self-managed Splunk Enterprise should update promptly because these flaws could expose secrets and weaken controls on a central logging and security platform. Even without reported exploitation, affected servers often hold sensitive operational and credential data.
Sources: Splunk, Zoom Patch Critical Vulnerabilities
F5 issues out-of-band patches for critical NGINX flaw CVE-2026-42533 and other NGINX, Ingress Controller, and BIG-IP bugs
F5 released emergency security updates for NGINX and BIG-IP products, including a critical bug that can let specially crafted web requests crash or potentially compromise affected servers. The most severe issue, CVE-2026-42533, affects NGINX Plus and NGINX Open Source and can cause a heap buffer overflow; code execution is possible if Address Space Layout Randomization (ASLR) is disabled. F5 also fixed high-severity flaws in ngx_http_slice_module, ngx_http_ssi_module, NGINX Ingress Controller, and BIG-IP, including bugs that can leak memory, modify configuration, delete files, disable services, or cause denial of service. — Organizations running F5 NGINX, NGINX Ingress Controller, or BIG-IP should treat this as urgent because internet-facing systems could be crashed, manipulated, or in some setups remotely compromised. Apply F5's out-of-band updates promptly and review exposed NGINX and BIG-IP deployments, especially those handling public HTTP or HTTP/2 traffic.
Sources: F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Microsoft revokes old UEFI shims after Secure Boot bypass flaws CVE-2026-8863 and CVE-2026-10797
Microsoft-signed old Linux UEFI shim bootloaders could let attackers bypass Secure Boot on many PCs and servers, even if they do not run Linux. ESET says 11 legacy shims, mainly version 0.9 and earlier, remained trusted under Microsoft's third-party UEFI certificate and could be used to load vulnerable second-stage bootloaders or attacker-supplied components during startup. The issues are tracked as CVE-2026-8863 and CVE-2026-10797, and Microsoft revoked the affected binaries in the June 2026 Patch Tuesday UEFI DBX (Forbidden Signature Database) update. — This weakens a core startup security control that many organizations rely on to stop bootkits and other low-level malware. Enterprises and cloud operators should update trusted boot components first and then deploy the DBX revocations, because doing it in the wrong order can break system boot.
Sources: Old UEFI Shims Expose Systems to Secure Boot Bypass
Tenable, ESET, Tanium and Trend Micro release security fixes for severe flaws in endpoint and server products
Tenable, ESET, Tanium and Trend Micro have patched serious security flaws in products used to protect and manage enterprise systems. The updates include Tenable Agent path traversal CVE-2026-15265 that may allow remote code execution, ESET Inspect Connector for Windows local privilege escalation via crafted Advanced Local Procedure Call messages, a separate ESET Linux denial-of-service issue, a Tanium Server unauthenticated network-based denial-of-service flaw, and a Trend Micro Cleaner One Pro local privilege escalation bug. — Organizations using these products should review vendor advisories and update promptly, because security tools often run with elevated privileges and can become high-value targets themselves. Even without confirmed exploitation, the Tenable and ESET issues could help attackers gain deeper access or disrupt defenses.
Sources: Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
Microsoft July 2026 Patch Tuesday fixes 570 flaws, including exploited AD FS and SharePoint zero-days
Microsoft released its July 2026 Patch Tuesday updates to fix 570 security flaws, including two zero-days already being used in attacks and one publicly disclosed flaw. The exploited bugs are CVE-2026-56155 in Active Directory Federation Services (AD FS), a local privilege-escalation issue, and CVE-2026-56164 in Microsoft SharePoint Server, a network-reachable elevation-of-privilege flaw caused by missing authentication for a critical function; Microsoft also fixed the publicly disclosed BitLocker bypass CVE-2026-50661. — Organizations running affected Microsoft products should treat this as urgent because attackers were already exploiting two of the flaws before patches were available. Admins should prioritize patching AD FS and SharePoint servers immediately and apply Microsoft's SharePoint mitigations such as enabling Antimalware Scan Interface request-body scanning where applicable.
Sources: Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days, Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days, Microsoft Patches a Record 570 Security Flaws (+6 more)
Microsoft says three publicly dumped Windows zero-days are already being exploited after Nightmare Eclipse disclosures
A researcher’s public release of six Windows zero-days has already led attackers to exploit three of them, and Microsoft says more unpatched flaws remain. Microsoft named the bugs as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma; it said BlueHammer, RedSun, and UnDefend saw attacks after proof-of-concept exploit code was posted, while YellowKey is tracked as CVE-2026-45585 and, along with GreenPlasma and MiniPlasma, still lacks a fix. — Windows defenders may have little time between public disclosure and real-world attacks, especially when proof-of-concept exploit code is available. Organizations should review Microsoft mitigations immediately, monitor for compromise tied to these bug names and CVE-2026-45585, and prioritize hardening or temporary workarounds where patches do not yet exist.
Sources: Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops, Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more, Microsoft says it will not pursue security researchers after zero-day backlash (+11 more)
ServiceNow patches critical unauthenticated remote-code-execution flaw CVE-2026-6875 in its AI platform
ServiceNow fixed a critical security hole in its AI platform that could let an outsider run malicious code without logging in. The flaw, CVE-2026-6875, has a CVSS score of 9.5 and affects ServiceNow AI platform deployments; ServiceNow says it pushed fixes to hosted instances and provided updates to self-hosted customers and partners. The company said it is not aware of active exploitation. — Organizations using ServiceNow's AI platform should verify the update has been applied, especially self-hosted deployments, because unauthenticated code execution can lead to full system compromise. This is the kind of flaw that should be patched quickly even without confirmed in-the-wild attacks.
Sources: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
Progress tells ShareFile Storage Zone Controller customers to shut down on-premises servers over a credible security threat
Progress told organizations using ShareFile Storage Zone Controllers to immediately shut down the Windows servers running them because of a credible external security threat. The affected component is the on-premises Storage Zone Controller used in hybrid ShareFile deployments, where internet-facing servers handle file transfers between local storage and the ShareFile cloud. Progress says it has temporarily disabled access for affected accounts and has not yet disclosed a CVE, attack method, or confirmed compromise. — This is a high-urgency situation for organizations that run ShareFile with on-premises Storage Zone Controllers, because the vendor says disabling cloud access alone is not enough and manual server shutdown is required. Affected admins should treat this as an emergency mitigation, isolate or power down those servers, and watch for vendor updates within 24 hours.
Sources: Progress urges ShareFile admins to shut down servers over “credible” threat, URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat, Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown (+1 more)
Rockwell Automation patches critical and high-severity flaws in FactoryTalk, Logix controllers, Flex adapters, and RSLinx
Rockwell Automation released security fixes for multiple industrial control products used in factories and critical operations. The updates cover FactoryTalk Historian Site Edition flaws that can bypass authentication and cause denial of service, a FactoryTalk Analytics PavilionX improper API authorization bug that can allow unauthorized administrative actions, denial-of-service issues in CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers, and a critical unauthenticated flaw in Flex I/O dual-port Ethernet/IP adapters that can let an attacker change the web interface password and potentially take over access. CISA redistributed the advisories, and Rockwell said the newly patched issues are not known to be exploited in the wild. — Organizations running Rockwell industrial equipment should review and apply these updates promptly because the affected products can be used in operational technology environments where outages or unauthorized access can disrupt physical processes. Even without confirmed active exploitation, the mix of critical and high-severity bugs makes this a patch-now item for defenders responsible for ICS and OT systems.
Sources: Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software, ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Siemens fixes critical vulnerabilities in Opcenter X, Mendix, Simatic S7-1500, Desigo CC, and other ICS products
Siemens released July 2026 security advisories for multiple industrial products, including several critical flaws that can let attackers bypass authentication, run code, crash systems, steal data, or gain elevated access. The most severe issue is a CVSS 10.0 token invalidation flaw in Opcenter X that can allow authentication bypass and full application access; Siemens also patched or mitigated critical issues in Mendix, Sidis Secured SmartPlug, Simatic S7-1500, Cadra, and Desigo CC, alongside high-severity flaws in Simatic S7-PLCSIM, Ruggedcom APE1808, Comos, Designcenter, Simcenter, Solid Edge, and Tecnomatrix. — These products are used in industrial and building-control environments, so affected organizations should review Siemens advisories and patch or apply mitigations quickly. The risks include unauthorized control, outages, and compromise of sensitive operational systems.
Sources: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Schneider Electric fixes high-severity flaws in IGSS SCADA and EcoStruxure Cybersecurity Admin Expert
Schneider Electric published two July 2026 advisories covering high-severity vulnerabilities in industrial software used to monitor and manage operations. One flaw in IGSS (Interactive Graphical SCADA System) can let an attacker run arbitrary code through specially crafted files, and another in EcoStruxure Cybersecurity Admin Expert is a local authentication-bypass issue that can let an attacker compromise managed devices. — Organizations using these Schneider products should patch promptly because the flaws can lead to system compromise in industrial environments. Even when one issue requires local access, the affected software is used to administer devices that may be critical to operations.
Sources: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Mozilla releases Firefox 152 and ESR updates to fix 40 vulnerabilities, including high-severity bugs that could allow code execution
Mozilla released Firefox 152, Firefox ESR, Thunderbird, and Firefox for iOS updates to fix 40 security vulnerabilities affecting users across desktop and mobile products. The fixes include 13 high-severity issues such as use-after-free memory bugs, privilege-escalation flaws, sandbox escapes, incorrect boundary conditions, and JIT miscompilation problems; Mozilla said some memory-safety flaws could potentially allow arbitrary code execution. — People and organizations using Firefox or Thunderbird should update promptly because some of the patched bugs could let a malicious website or content run code or break browser protections. This affects both everyday users and enterprises that rely on Firefox ESR for managed deployments.
Sources: Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities, Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Google Chrome 150 security update fixes 27 vulnerabilities, including two critical use-after-free bugs
Google released Chrome 150 with security fixes for 27 vulnerabilities affecting users on Windows, macOS, and Linux. The update patches two critical use-after-free memory-safety flaws in Chrome’s Ozone and Views components, plus 11 other use-after-free bugs and additional issues including integer overflow, out-of-bounds read and write, and insufficient validation. Affected versions were updated to 150.0.7871.114/.115 for Windows and macOS and 150.0.7871.114 for Linux. — Chrome is widely used, so even non-exploited critical browser bugs matter because they can quickly become useful to attackers once patch details are public. Users and organizations should update Chrome promptly across managed and personal devices.
Sources: Chrome 150 Update Patches 27 Vulnerabilities, Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
SonicWall says attackers are exploiting SMA1000 zero-day flaws CVE-2026-15409 and CVE-2026-15410
SonicWall says attackers are actively exploiting two previously unpatched flaws in its SMA1000 secure remote-access appliances, and customers should install emergency updates now. The bugs are CVE-2026-15409, a critical server-side request forgery issue in the Work Place interface that can be triggered remotely without logging in, and CVE-2026-15410, a code-injection flaw in the Management Console that requires an authenticated administrator. Affected SMA1000 models include the 6210, 7210, and 8200v on specified 12.4.3 and 12.5.0 hotfix builds; fixes are in 12.4.3-03453 and 12.5.0-02835 and later. — These devices sit at the edge of corporate networks, so active exploitation can put remote access infrastructure at immediate risk. Organizations using SMA1000 should patch now, check SonicWall’s indicators of compromise, and if compromise is found, re-image or redeploy appliances and reset passwords and TOTP tokens.
Sources: SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now, SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits, Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Microsoft June 2026 Patch Tuesday fixes 200 flaws, including Windows zero-days CVE-2026-45586 and CVE-2026-50507
Microsoft released its June 2026 security updates to fix 200 vulnerabilities, including three publicly disclosed zero-days in Windows. The zero-days include CVE-2026-45586, a local privilege-escalation flaw in the Windows Collaborative Translation Framework (CTFMON) that can grant SYSTEM access, CVE-2026-49160 in HTTP.sys, and CVE-2026-50507, a BitLocker security-feature bypass requiring physical access. Microsoft says none of the three were known to be exploited at patch time. — Windows systems across enterprises and consumer devices may be exposed to newly public attack methods until they are patched. Organizations should prioritize June Patch Tuesday deployment and review Microsoft’s HTTP.sys mitigation guidance, while users should install Windows updates promptly.
Sources: Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws, Windows 11 KB5094126 & KB5093998 cumulative updates released, Microsoft releases Windows 10 KB5094127 extended security update (+8 more)
Microsoft extends free Windows 10 Extended Security Updates for consumers to October 2027
Microsoft has quietly extended its free Windows 10 Extended Security Updates program for personal devices by one year, so enrolled users can keep getting security patches until October 12, 2027. Windows 10 reached end of support on October 14, 2025, and Microsoft updated its ESU documentation and blog post to reflect the new date. The consumer ESU program applies to personal Windows 10 devices, not systems managed through Active Directory domains, Microsoft Entra, or mobile device management, though Entra-registered devices remain eligible. — This gives people and small organizations still on Windows 10 more time to keep receiving security fixes instead of running an unpatched operating system. Affected users should verify whether their devices are enrolled in ESU and use the extra year to plan a move to Windows 11 or other supported systems.
Sources: Microsoft quietly extends free Windows 10 ESU support to October 2027, Microsoft releases Windows 10 KB5099539 extended security update
SAP fixes critical NetWeaver and Commerce flaws including NetWeaver SAML bug CVE-2026-44748
SAP released June 2026 security updates for critical flaws in NetWeaver, Commerce Cloud, and Data Hub that could let attackers access sensitive data, crash systems, or bypass normal protections. The most severe issues are CVE-2026-44748, an XML Signature Wrapping flaw in NetWeaver AS ABAP and ABAP Platform SAML authentication rated 9.9; CVE-2026-27671, a 9.8 memory-corruption bug in the SAP kernel's RFC handling affecting NetWeaver and ABAP Platform; CVE-2026-22732, a 9.1 Spring Security header-handling issue affecting Commerce Cloud and Data Hub; and CVE-2026-40128, a 9.0 directory traversal flaw in NetWeaver Application Server Java reachable through crafted HTTP logon requests. — SAP systems often sit at the core of large companies' business operations, so critical flaws in NetWeaver and Commerce can have broad operational and data-security impact. Organizations using affected SAP products should review SAP's June 2026 notes, apply patches promptly, and use temporary mitigations such as disabling SAML where needed until updates are installed.
Sources: SAP Patches Critical NetWeaver, Commerce Vulnerabilities, SAP fixes critical flaws in NetWeaver and Commerce Cloud, SAP warns of critical flaws in NetWeaver and Commerce Cloud (+2 more)
Microsoft releases July 2026 Windows 11 security updates KB5101650 and KB5099414
Microsoft released mandatory July 2026 security updates for Windows 11, affecting supported 25H2, 24H2, and 23H2 systems. The cumulative updates KB5101650 and KB5099414 include Patch Tuesday fixes for 571 previously disclosed vulnerabilities, though this article does not identify specific CVEs in the Windows 11 packages. The release also includes non-security fixes such as Bluetooth reliability improvements and File Explorer changes. — Windows 11 users and administrators should install these updates promptly because they bundle Microsoft’s latest monthly security fixes. Even without a highlighted zero-day in this article, Patch Tuesday updates are routine high-priority maintenance for reducing exposure to known flaws.
Sources: Windows 11 KB5101650 & KB5099414 cumulative updates released
Adobe patches seven critical ColdFusion and Campaign Classic flaws that can lead to remote code execution
Adobe released security updates for ColdFusion and Adobe Campaign Classic to fix seven maximum-severity vulnerabilities that could let attackers run code on affected servers. The ColdFusion issues include CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282, affecting versions 2025.9, 2023.20, and earlier; Adobe says they can be exploited by unauthenticated attackers in low-complexity attacks. CVE-2026-48286 affects on-premises Campaign Classic 7.4.3 build 9396 and earlier; Adobe says hosted instances were already patched. — Organizations running these Adobe products could be exposed to server compromise if they delay patching. Adobe assigned the flaws Priority 1 and recommends installing updates within 72 hours, especially for internet-facing ColdFusion and on-premises Campaign systems.
Sources: Adobe patches seven max severity ColdFusion, Campaign flaws, Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities, Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic (+2 more)
Broadcom patches seven serious VMware Avi Load Balancer flaws, including auth bypass and remote code execution bugs
Broadcom released updates for VMware Avi Load Balancer to fix seven serious security flaws that could let attackers break into or take control of affected systems. The issues include critical authentication bypass CVE-2026-47865, high-severity flaws CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, and CVE-2026-47871, enabling authentication bypass, remote code execution, privilege escalation to root, and directory traversal. Broadcom said there is no reported in-the-wild exploitation in the advisory. — Organizations using VMware Avi Load Balancer for application delivery and security should update promptly because several of these bugs could let a network-accessible attacker bypass login protections or gain elevated control. For defenders, this is a straightforward patch-now advisory even without confirmed active exploitation.
Sources: 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
CISA adds exploited Joomla extension flaws CVE-2026-48908 and CVE-2026-56290 to KEV after web-shell attacks
CISA says attackers are actively exploiting two Joomla page-builder extensions and agencies must patch by July 10. The flaws are CVE-2026-48908 in JoomShaper SP Page Builder before 6.6.2 and CVE-2026-56290 in Joomlack Page Builder CK before 3.6.0. Both are unauthenticated file-upload or access-control bugs that can lead to remote code execution, and reports say attackers have used them to plant hidden admin accounts, web shells, and PHP file manager backdoors. — Website owners using these Joomla extensions could have their sites quietly taken over and used to host backdoors or malicious content. Patch immediately, check for unexpected administrator accounts and uploaded PHP files, and review server logs for suspicious uploads.
Sources: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws, Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
Squid Proxy flaw CVE-2026-47729 can leak other users’ web requests from shared proxies
A newly disclosed flaw in Squid Proxy can expose data from other users who share the same proxy server. Tracked as CVE-2026-47729 and dubbed 'Squidbleed,' the bug is a memory over-read in Squid’s FTP parser that has reportedly existed since 1997. An attacker must control an FTP server reachable through the proxy, and the leak can expose prior users’ cleartext HTTP request data, including credentials, session tokens, and API keys. A fix was merged for Squid 8 in April 2026 and released in Squid 7.6 in June 2026; disabling FTP support is a mitigation. — Organizations using Squid in shared environments such as companies, schools, and public hotspots may be exposing sensitive web traffic if they have not updated. Admins should upgrade to fixed versions or disable FTP support, especially where cleartext HTTP is still in use or Squid terminates Transport Layer Security (TLS).
Sources: Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data, 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests, Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era (+1 more)
Zimbra urges customers to patch critical Classic Web Client XSS flaw in Zimbra Collaboration 10.1.19
Zimbra warned customers to quickly update its email and collaboration software after finding a critical flaw in the Classic Web Client that can be triggered by opening a malicious email. Zimbra fixed the stored cross-site scripting issue in Zimbra Collaboration Suite version 10.1.19; it has no CVE yet. The bug affects the Classic UI webmail interface and could let attackers steal session data, mailbox contents, or account settings. — Organizations using Zimbra webmail, especially the Classic interface, should treat this as urgent because a single crafted email could put user accounts and messages at risk. Update to 10.1.19 as soon as possible and limit or disable use of the Classic client if patching will take time.
Sources: Zimbra urges customers to patch critical web client XSS flaw
Palo Alto Networks patches 13 vulnerabilities in PAN-OS and Prisma Access Agent, including high-urgency firewall flaw CVE-2026-0288
Palo Alto Networks released fixes for 13 security flaws affecting its firewall and remote-access products. The most serious issue, CVE-2026-0288, is a high-severity PAN-OS buffer-overflow flaw that can let an unauthenticated attacker with network access crash a firewall and potentially run code via specially crafted traffic against the User-ID Terminal Server Agent feature. Other patched flaws affect PAN-OS and Prisma Access Agent, including command injection, server-side request forgery (making the product send unauthorized internal requests), authentication bypass, information disclosure, privilege escalation, and VPN traffic interception or data loss prevention bypass. — Organizations using Palo Alto firewalls or Prisma Access Agent should review the advisories and patch promptly, especially if exposed management or TSA-related access is broader than best practice. Even though Palo Alto says it has not seen active exploitation, firewall and VPN flaws are routinely targeted once patches are available.
Sources: Palo Alto Networks Patches 13 Vulnerabilities
Microsoft patches Windows Defender zero-day RoguePlanet (CVE-2026-50656) that could give attackers SYSTEM access
Microsoft has released a fix for a Windows Defender zero-day called RoguePlanet that could let attackers gain full SYSTEM-level control on Windows 10 and Windows 11 devices. The flaw is tracked as CVE-2026-50656 and was publicly disclosed with proof-of-concept code by the researcher using the handle Nightmare Eclipse after June 2026 Patch Tuesday. Microsoft says the issue is fixed in Microsoft Malware Protection Engine version 1.1.26060.3008, the scanning engine used by Defender and related security products. — This affects widely used built-in Windows security software on fully patched consumer and enterprise systems, so defenders should verify the updated Malware Protection Engine version is installed as soon as possible. Public exploit code exists, which raises the risk of copycat abuse even if exploitation is unreliable.
Sources: Microsoft patches RoguePlanet Defender zero-day vulnerability, Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges, Microsoft Patches Defender ‘RoguePlanet’ Vulnerability (+1 more)
Ubiquiti patches seven critical UniFi OS flaws, including command-injection bug CVE-2026-50746
Ubiquiti released fixes for seven critical security flaws in UniFi OS and related applications that could let attackers on the network take over affected devices and services. The most severe issue, CVE-2026-50746, is a command-injection vulnerability in UniFi Connect Application 3.4.16 and earlier; Ubiquiti says users should update to 3.4.20 or later. Additional critical CVEs affect UniFi Talk, UniFi Access, UniFi Protect, UniFi OS Server, and various routers, gateways, NAS, and surveillance products, with six described as low-complexity and requiring no user interaction. — Organizations using UniFi gear, especially internet-exposed deployments, may be at risk of device compromise and follow-on abuse if they do not patch quickly. Admins should identify affected UniFi OS and application versions and update immediately.
Sources: Ubiquiti warns of new max severity UniFi OS vulnerability, Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Anthropic silently patched Claude Code sandbox bypass enabling outbound network policy evasion
SecurityWeek reports that Anthropic patched a Claude Code network sandbox bypass caused by a SOCKS5 hostname null-byte injection flaw that could let attackers evade outbound allowlist restrictions and exfiltrate data. Researcher Aonan Guan said the issue affected Claude Code from October 20, 2025 until fixes shipped in Claude Code 2.1.88/2.1.90 in March-April 2026. The article also references an earlier related bypass, CVE-2025-66479, involving outbound policy misinterpretation. — Organizations using Claude Code in production may have relied on sandboxing to prevent agent-driven data exfiltration, especially in prompt-injection scenarios. Users should update Claude Code and review whether sensitive credentials, tokens, or environment data could have been exposed through sandbox bypasses.
Sources: Anthropic Silently Patches Claude Code Sandbox Bypass, Even Claude agrees: hole in its sandbox was real and dangerous, China tells devs to ditch Claude Code over 'backdoor code' fears
Attackers exploit unpatched Langflow flaw CVE-2026-5027 to run code on exposed AI workflow servers
Attackers are exploiting a security hole in Langflow that can let outsiders take over internet-exposed servers without logging in. The flaw, CVE-2026-5027, is an unauthenticated remote-code-execution bug affecting Langflow, an open-source tool for building AI workflows; exploitation means attackers can send crafted requests to run their own commands on vulnerable systems, and the article says no patch is available yet. — Organizations using Langflow should treat this as urgent because an exposed server could be fully compromised with no valid account needed. If you run Langflow, restrict internet access, apply any vendor mitigations, monitor for compromise, and patch immediately once a fix is released.
Sources: Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE, Path traversal flaw in AI dev platform Langflow exploited in attacks, Hackers Exploit Langflow Vulnerability for Remote Code Execution (+4 more)
Attackers begin exploiting critical Adobe ColdFusion flaw CVE-2026-48282 shortly after patch release
Attackers are already using a newly patched Adobe ColdFusion bug to break into vulnerable servers. The flaw, CVE-2026-48282, is a critical path traversal issue rated 10.0 that can lead to arbitrary code execution in ColdFusion 2025 and 2023; Adobe fixed it on June 30 in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21, and external reporting says exploitation began within hours of public disclosure. — Organizations running Adobe ColdFusion should treat this as an immediate patching priority because internet-facing servers may already be targeted. Apply Adobe's June 30 updates now and review exposed ColdFusion systems for signs of compromise.
Sources: Critical Adobe ColdFusion Vulnerability Exploited in Attacks, CISA orders feds to patch max severity ColdFusion flaw by Friday, CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
CISA adds exploited Langflow cross-tenant flaw CVE-2026-55255 to KEV after attackers chain it with older RCE bug
CISA says attackers are already exploiting a critical Langflow flaw and federal agencies must patch it by July 10. The bug, CVE-2026-55255, is a cross-tenant insecure direct object reference issue fixed in Langflow 1.9.1 that lets attackers execute other users’ flows by supplying a flow UUID. Sysdig said attackers paired it with previously patched Langflow remote code execution flaw CVE-2026-33017 after doing host reconnaissance and harvesting flow IDs. — Organizations running Langflow should treat this as urgent because attackers are already chaining it with another flaw to gain code execution. Update to 1.9.1 immediately and review exposed Langflow servers for unauthorized flow execution, reconnaissance, and post-compromise activity.
Sources: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
CISA adds actively exploited Adobe Commerce and Magento remote-code-execution flaw CVE-2026-45247 to KEV catalog
CISA says attackers are exploiting a serious Adobe Commerce and Magento flaw that can let them take over vulnerable online store servers. The issue, CVE-2026-45247, is a remote-code-execution vulnerability, meaning an attacker can run their own commands on the target system from afar; CISA added it to the Known Exploited Vulnerabilities catalog, which federal agencies use to prioritize urgent fixes. Affected product and version details would follow Adobe’s advisory, and internet-exposed commerce systems are the most immediate concern. — Organizations running Adobe Commerce or Magento should treat this as urgent because CISA only adds bugs to KEV when there is evidence of real-world exploitation. For online stores, the risk can include site takeover, payment-data exposure, and malware implantation, so defenders should identify affected instances and patch or mitigate immediately.
Sources: CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog, Mirasvit Vulnerability Exploited to Execute Code on Magento Servers, CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
Joomla warns attackers are actively exploiting JCE flaw CVE-2026-48907 to upload files and run code on websites
Joomla site owners using the JCE editor plugin are being targeted in active attacks that can let outsiders take over websites. The flaw, CVE-2026-48907, affects JCE Pro versions before 2.9.99.5 and lets unauthenticated attackers upload editor profiles and then arbitrary files, leading to PHP code execution on the server. Joomla says public exploit code exists, attacks are automated, and version 2.9.99.6 adds further protections and indicators of compromise. — This is urgent for organizations and individuals running Joomla sites because attackers can break in without an account and leave backdoors behind. Update immediately, then check for compromise because patching closes the hole but does not remove anything attackers already installed.
Sources: Joomla, LiteSpeed Vulnerabilities Exploited in Attacks, CISA orders feds to patch max severity Joomla plugin flaw by Friday, CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
BeyondTrust patches critical authentication-bypass flaws in Remote Support and Privileged Remote Access
BeyondTrust warned customers to urgently patch critical flaws in its Remote Support and Privileged Remote Access products that could let attackers get in without proper authentication. The issues include CVE-2026-40138 and CVE-2026-40139, affecting RS and PRA versions 25.3.2 and earlier, and can allow unauthorized access under specific authentication configurations; two additional high-severity flaws, CVE-2026-40140 and CVE-2026-40141, can cause denial of service or expose restricted resources. Cloud customers were patched by April 21, 2026, while self-hosted customers must apply the April security rollup or upgrade to 25.3.3 or later. — Organizations using BeyondTrust for remote administration could be exposed to break-ins that bypass login controls, including access to privileged accounts. This is high priority for defenders because internet-facing management tools are frequent intrusion targets, so self-hosted customers should update immediately and review exposed appliances.
Sources: BeyondTrust warns of critical flaws in remote access software
Gitea CVE-2026-27771 let anyone pull private container images from thousands of self-hosted servers
A flaw in Gitea could let outsiders download supposedly private software container images from many self-hosted code servers. NoScope says CVE-2026-27771 is an access-control bug in Gitea’s built-in container registry, also affecting Forgejo, where anonymous Docker/OCI pull requests could retrieve private images; Gitea patched it in version 1.26.2, and Shodan data suggested roughly 31,750 internet-facing instances were likely vulnerable. — Private container images can contain source code, credentials, and details about production systems, so this exposure could hand attackers valuable access and intelligence. Organizations running self-hosted Gitea or Forgejo should update to 1.26.2 immediately or enforce authentication for all content access if possible.
Sources: Gitea Vulnerability Exposed 30,000 Deployments to Attacks, In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
Unpatched Gogs zero-day lets attackers run code on self-hosted Git servers
A newly disclosed flaw in Gogs can let attackers take over internet-exposed code servers if they can register a normal user account. The unpatched argument-injection vulnerability, not yet assigned a CVE, affects Gogs 0.14.2 and 0.15.0+dev and is triggered during the "Rebase before merging" pull-request flow; because open registration is enabled by default, many default-configured servers may be reachable by unauthenticated attackers who simply sign up first. Rapid7 says successful exploitation can lead to remote code execution as the server process user, access to private repositories, and theft of password hashes, API tokens, SSH keys, and 2FA secrets. — Organizations running self-hosted Gogs should treat this as urgent because exposed servers may be compromiseable even without an existing attacker account. Until a fix is available, admins should disable open registration, restrict internet exposure, and review whether rebase-merging can be turned off or tightly limited.
Sources: New Gogs zero-day flaw lets hackers get remote code execution, Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code, Gogs Zero-Day Exposes Servers to Remote Code Execution (+3 more)
FortiBleed campaign compromised more than 30,000 Fortinet firewalls and VPN gateways worldwide
Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries. — Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.
Sources: 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs, FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices., Massive password-stealing attack hits 75k Fortinet firewalls (+11 more)
Citrix patches NetScaler information disclosure flaw CVE-2026-8451 and five other vulnerabilities in ADC and Gateway
Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could expose sensitive memory, crash devices, or allow unauthorized file access. The fixes cover CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, another medium-severity out-of-bounds read issue, and the NetScaler-specific HTTP/2 Bomb CVE-2026-13474; affected releases include 14.1-72.61 and 13.1-63.18, with FIPS and NDcPP builds also updated. WatchTowr says CVE-2026-8451 is a CitrixBleed-style memory disclosure bug tied to the XML parser and exploitable when NetScaler is configured as a Security Assertion Markup Language identity provider. — Organizations running self-managed NetScaler systems should treat this as a prompt patching issue because one flaw can leak memory and may help attackers chain toward full appliance compromise. Admins should update affected versions quickly and verify whether exposed features such as Security Assertion Markup Language identity provider mode are enabled.
Sources: Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack, New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
Cisco patches Cisco Unified CM flaw CVE-2026-20230 that could lead to root access, warns public PoC exists
Cisco released fixes for a serious security flaw in Cisco Unified Communications Manager and Unified Communications Manager Session Management Edition that could let remote attackers gain a path to full control of affected appliances. The bug, CVE-2026-20230, is a server-side request forgery issue caused by improper validation of certain HTTP requests; on systems with the WebDialer service enabled, an unauthenticated attacker can send crafted requests to write files to the underlying operating system and potentially escalate to root. Cisco fixed it in Unified CM and Unified CM SME 14SU6 and plans to include fixes in 15SU5. — Organizations running affected Cisco call-management systems should check whether WebDialer is enabled and apply updates quickly, especially because proof-of-concept exploit code is already public. Even without confirmed in-the-wild exploitation, the flaw could give attackers a foothold that leads to full device compromise.
Sources: Cisco Warns of Available PoC for Critical Unified CM Vulnerability, Cisco warns of critical Unified CM flaw with PoC exploit code, Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public (+6 more)
HTTP/2 Bomb denial-of-service attack chain hits default NGINX, Apache, IIS, Envoy and Pingora web server setups
Researchers say a new HTTP/2 attack chain can knock major web servers offline within seconds, potentially affecting more than 880,000 websites using default configurations. The technique combines an HPACK header-compression bomb with Slowloris-style connection holding to exhaust memory; it builds on CVE-2016-6581, CVE-2016-8740, CVE-2016-1546, Apache's 2025 fix CVE-2025-53020, and newly assigned Apache CVE-2026-49975. NGINX reportedly fixed the issue in April, Apache in late May, while Microsoft IIS, Envoy, and Cloudflare Pingora had not yet been patched at publication. — Organizations running internet-facing HTTP/2 servers could be taken offline by a relatively low-resource attacker, so this is operationally urgent even though it is a denial-of-service issue rather than data theft. Admins should review vendor advisories, apply available fixes for NGINX and Apache, and add mitigations or rate-limiting for IIS, Envoy, and Pingora until patches arrive.
Sources: ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds, New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute, OpenAI's agent chained decade-old DoS attacks to crash web servers in seconds (+3 more)
Apple ships iOS, iPadOS, macOS Tahoe, and Safari updates fixing dozens of security flaws
Apple released security updates for iPhone, iPad, Mac, and Safari users to fix dozens of vulnerabilities that could be triggered by malicious websites or lead to crashes, memory corruption, data leaks, and clipboard hijacking. The updates include iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, with 26 WebKit flaws and additional bugs in the kernel, IOGPUFamily, libxslt, Web Extensions, and WebRTC; Apple said it has no evidence of active exploitation. — These are broad platform patches for devices many people use every day, and many of the bugs can be triggered just by visiting a malicious website. Users and organizations should update Apple devices and Safari promptly, especially where internet-facing browsing is common.
Sources: Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
Google releases Chrome 151 security update fixing 382 vulnerabilities, including 15 critical flaws
Google released Chrome 151 with security fixes for 382 browser vulnerabilities affecting Chrome users across supported platforms. Google says 15 of the bugs are rated critical and 67 high severity; many involve memory-safety issues such as use-after-free, type confusion, out-of-bounds access, and input-validation flaws in the renderer that can be triggered by crafted web content and may allow code execution in the browser sandbox or help attackers escape it. No in-the-wild exploitation was disclosed for this batch. — Chrome is one of the most widely used pieces of software, so a large patch batch with multiple critical bugs is broadly important even without confirmed active exploitation. Users and organizations should update browsers promptly through normal patch channels to reduce exposure to malicious websites and drive-by attacks.
Sources: Google Patches 382 Chrome Vulnerabilities
SimpleHelp fixes critical CVE-2026-48558 that lets attackers create rogue remote support accounts
A critical flaw in SimpleHelp remote management software can let an outsider create a privileged support account on vulnerable servers. The bug, CVE-2026-48558, affects SimpleHelp 5.5.15 and earlier plus 6.0 pre-release builds when OpenID Connect (OIDC) login is enabled and certain technician-group settings are in use. An unauthenticated attacker can bypass normal identity checks and multi-factor authentication to gain technician access; fixes are in 5.5.16 and 6.0RC2. — Organizations using SimpleHelp for remote administration could hand attackers the same kind of access trusted support staff have, including remote control of managed devices and script execution. This is urgent for anyone exposing SimpleHelp to the internet: update now, and if you cannot patch immediately, restrict technician logins with IP allowlists and review logs for suspicious new technician accounts.
Sources: SimpleHelp bug lets hackers create rogue remote support accounts, Critical SimpleHelp Vulnerability Exploited for Malware Delivery, Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer (+1 more)
Critical libssh2 flaw CVE-2026-55200 could let a malicious SSH server run code on vulnerable clients
A critical bug in the widely used libssh2 SSH client library could let a hostile SSH server compromise computers and devices that connect to it. Arctic Wolf says CVE-2026-55200 is a pre-authentication memory-corruption flaw in ssh2_transport_read() affecting libssh2 1.11.1 and earlier, triggered by a crafted packet_length value; public proof-of-concept code is available, an upstream patch has been merged but no formal tagged release was available at publication, and many downstream tools may be hard to patch because they statically embed the library. — This is urgent because affected software can be exposed just by connecting to a malicious or compromised SSH server, with no credentials or user interaction required. Organizations should inventory anything that uses libssh2, apply source or downstream patches, and restrict outbound SSH connections to trusted hosts until fixes are in place.
Sources: Critical Remote Code Execution Vulnerability in libssh2 Client Library Require Urgent Mitigation
CISA adds seven actively exploited flaws, including Microsoft Defender CVE-2026-41091 and CVE-2026-45498, to KEV catalog
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026, citing evidence of active exploitation. The additions include legacy Microsoft Windows, DirectX, Internet Explorer, and Adobe Reader bugs, plus Microsoft Defender flaws CVE-2026-41091 (elevation of privilege) and CVE-2026-45498 (denial of service). Federal agencies must remediate by the deadlines set under BOD 22-01. — KEV additions indicate real-world exploitation and help defenders prioritize patching and mitigations. Organizations, especially federal agencies, should urgently assess exposure to the newly listed Microsoft Defender and legacy Windows-related vulnerabilities.
Sources: CISA Adds Seven Known Exploited Vulnerabilities to Catalog, Microsoft warns of new Defender zero-days exploited in attacks, Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days (+2 more)
CISA says Microsoft Defender zero-day BlueHammer CVE-2026-33825 was used in ransomware attacks
A Microsoft Defender security flaw was exploited before a patch was available, and U.S. officials now say ransomware attackers used it in real intrusions. The bug, tracked as BlueHammer and CVE-2026-33825, is a local privilege-escalation flaw in Microsoft Defender; it was publicly disclosed on April 2, patched on April 14, added to CISA’s Known Exploited Vulnerabilities catalog on April 22, and CISA has now updated that entry to specify ransomware use. Huntress said it observed zero-day exploitation before Microsoft released fixes. — Organizations using Windows systems with Microsoft Defender should treat this as a high-priority post-zero-day issue and verify patching immediately. The new ransomware tie raises the urgency because attackers used the flaw to gain higher privileges that can help them take over systems and deploy follow-on malware.
Sources: BlueHammer Vulnerability Exploited in Ransomware Attacks
ShinyHunters targets Oracle PeopleSoft servers in data-theft attacks against more than 100 organizations
Oracle PeopleSoft customers are being hit in ongoing break-ins and extortion attacks that ShinyHunters says have affected more than 100 organizations and 300 PeopleSoft instances. The campaign reportedly targets both cloud and on-premises PeopleSoft deployments, with the attackers claiming to use a chain of older bugs and at least one zero-day, though no CVE has been confirmed by Oracle. Reported evidence includes extortion notes, exposed attacker tooling, and IP-based indicators of compromise tied to infrastructure previously linked to ShinyHunters. — PeopleSoft is widely used for payroll, HR, finance, procurement, and student systems, so a compromise can expose highly sensitive employee, customer, or student data. Organizations running PeopleSoft should urgently review logs for the listed IPs, investigate possible unauthorized SSH access, and prepare incident response while waiting for Oracle guidance.
Sources: Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks, Nottingham University data breach affects over 450,000 students, Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks (+6 more)
CISA warns Daktronics display controller flaws can let attackers remotely hijack highway signs and digital billboards
CISA warned that vulnerabilities in Daktronics display controllers could let attackers remotely tamper with highway signs, digital billboards, and other large electronic displays. The advisory covers Daktronics VFC-DMP-5000, DMP-5000, and DMP-8000 controllers and includes an unauthenticated path traversal flaw, an authenticated arbitrary file upload flaw, and default administrator credentials; together they can enable root-level control. Daktronics released patched firmware, and researchers found multiple internet-exposed controllers still reachable online. — Organizations using these controllers could have public-facing signs altered to show false or malicious messages, and exposed devices may be fully compromised. This is an urgent patch-and-hardening story for operators of transportation, advertising, venue, and airport display systems: update firmware, remove internet exposure, and change default passwords immediately.
Sources: New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking
AWS patches Amazon Q Developer flaw CVE-2026-12957 that lets malicious repositories steal cloud credentials
AWS patched a flaw in Amazon Q Developer that could let a booby-trapped code repository steal a developer’s cloud credentials just by being opened in a supported development tool. Wiz said Amazon Q Developer would automatically act on workspace configuration files without user approval, enabling background command execution and credential theft from active environments; AWS assigned CVE-2026-12957 and also fixed related symbolic-link handling issue CVE-2026-12958 across VS Code, JetBrains, Eclipse, Visual Studio plugins, and the language server in version 1.65.0. — Developers and organizations using Amazon Q could have exposed AWS or other cloud access keys simply by opening a malicious repository, pull request, or fake coding test. Update the Amazon Q Developer plugin and ensure the language server is on 1.65.0 or later, especially where auto-update may be blocked.
Sources: Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories, Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
CISA says attackers are exploiting Lantronix EDS5000 command-injection flaw CVE-2025-67038
CISA says hackers are actively exploiting a critical flaw in Lantronix EDS5000 serial-to-Ethernet servers, and affected organizations should patch quickly. The bug, CVE-2025-67038, affects EDS5000 firmware 2.1.0.0R3 and stems from unsanitized input in the HTTP remote-procedure-call module, allowing remote root-level command injection; Lantronix says users should upgrade to version 2.2.0.0R1. — Organizations using these device-management servers could be exposed to full remote takeover if they have not updated. This is urgent because CISA has confirmed exploitation in the wild and federal agencies have a three-day remediation deadline.
Sources: CISA warns of max severity Ubiquiti flaws exploited in attacks, CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited, Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
GitLab fixes 13 security flaws in CE and EE, including high-severity XSS and data-exposure bugs
GitLab released security updates for its self-managed Community Edition and Enterprise Edition platforms, fixing 13 vulnerabilities that could let attackers run code in users’ browsers or expose sensitive project data. The most serious issues are CVE-2026-10086, an authenticated cross-site scripting flaw in the GitLab EE Analytics dashboard; CVE-2026-10712, an unauthenticated cross-site scripting flaw in the Web IDE workbench asset handler; and CVE-2026-12053, an information disclosure bug in Duo Workflows. Fixes are in GitLab CE/EE 19.1.1, 19.0.3, and 18.11.6. — Organizations running self-managed GitLab should update quickly, because these flaws can help attackers hijack browser sessions, tamper with settings, or expose sensitive development data and secrets. GitLab.com is already patched, but private GitLab servers remain the admins’ responsibility.
Sources: GitLab Patches Code Execution, Information Disclosure Vulnerabilities
Curl patches 18 vulnerabilities, including 25-year-old libcurl authentication-bypass flaw CVE-2026-8932
Curl released an update fixing 18 security vulnerabilities, including a 25-year-old flaw in libcurl that could let applications reuse the wrong mutual-TLS identity and bypass authentication. The bugs affect curl/libcurl, with four rated medium and 14 low severity; the oldest, CVE-2026-8932, was introduced in curl 7.7 in 2001 and affects libcurl applications rather than the curl command-line tool. Other fixed issues include CVE-2026-8926, CVE-2026-8925, CVE-2026-9080, CVE-2026-10536, and CVE-2026-9547. — Curl and libcurl are embedded across servers, apps, phones, cars, and enterprise software, so even medium-severity flaws can have broad downstream impact. Organizations and software vendors that ship or depend on libcurl should update promptly and review where client-certificate authentication is used.
Sources: 25-Year-Old Vulnerability Patched in Curl
Google Chrome 149 security update fixes 18 severe browser vulnerabilities
Google released a Chrome 149 security update that fixes 18 serious browser flaws affecting Windows, macOS, and Linux users. The batch includes four critical and 14 high-severity vulnerabilities in Chrome 149.0.7827.196/197 for Windows and macOS and 149.0.7827.196 for Linux; more than half are use-after-free memory-corruption bugs that can potentially lead to remote code execution, alongside out-of-bounds read, uninitialized use, insufficient validation of untrusted input, and implementation flaws. Google said none are known to be exploited in the wild. — Chrome is widely used, so browser security fixes can quickly affect large numbers of people and organizations. Users and IT teams should update Chrome promptly because several of the patched bugs could potentially let attackers run code through a malicious webpage.
Sources: Chrome 149 Update Resolves 18 Severe Vulnerabilities
Cisco discloses exploited Catalyst SD-WAN Manager zero-day CVE-2026-20245 with no patch yet
Cisco says attackers are exploiting a new zero-day in Catalyst SD-WAN Manager, and affected organizations do not yet have a patch. The flaw, CVE-2026-20245, is a command-injection vulnerability in the command-line interface that lets an authenticated local attacker with netadmin privileges execute arbitrary commands as root by uploading a crafted file. Cisco said exploitation has been limited but observed cases where attackers pushed configuration changes to edge devices, and published indicators of compromise. — Organizations running Cisco Catalyst SD-WAN Manager face an actively exploited flaw that can give attackers full control of the system, with no fix available yet. Defenders should urgently check Cisco's indicators of compromise, restrict and review privileged access, hunt for abuse of related SD-WAN flaws, and prepare to patch as soon as Cisco releases updates.
Sources: Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026, Cisco warns of unpatched SD-WAN zero-day exploited in attacks, Yet another Cisco SD-WAN 0-day under attack, and no patch in sight (+6 more)
Chained UniFi OS Server flaws CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 can give attackers root access without logging in
Researchers say attackers can take over vulnerable UniFi OS Server systems without a password and gain full root control. Bishop Fox showed that three patched bugs in UniFi OS Server 5.0.6 and earlier—CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910—can be chained from the network to bypass authentication, read files, and trigger command injection, leading to remote code execution and trivial privilege escalation via passwordless sudo. — UniFi OS Server can manage core business systems such as networking, cameras, and door access, so compromise can hand attackers broad control of an organization’s environment. Organizations using affected versions should patch immediately and check for suspicious requests to the noted endpoints, because the attack leaves little or no login evidence.
Sources: Critical UniFi OS bug lets hackers gain root without authentication, Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs, CISA warns of max severity Ubiquiti flaws exploited in attacks
Kandji patches CVE-2026-39118 after researchers show macOS trust-cache and XPC chain can disable EDR and MDM agents
Researchers showed that a normal non-admin macOS user can silently turn off some enterprise security tools, including endpoint detection and response (EDR) and mobile device management (MDM) agents. XM Cyber said the attack chains weakly validated XPC service connections, malicious changes to Interface Builder NIB files, and persistence in macOS's code-signing trust cache after a signed app runs; it demonstrated the technique against CrowdStrike Falcon Sensor and Kandji, and Kandji assigned CVE-2026-39118 and patched its product. — Organizations using macOS fleets could lose key security monitoring and management controls without obvious alerts, even from a standard user account. Defenders should review Kandji fixes, validate CrowdStrike detections, and assess exposed XPC privilege paths on managed Macs now.
Sources: macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
Dify patches four CVEs that could expose private chats and files across tenants in its AI app platform
Dify fixed four security flaws that could let attackers on shared cloud instances read other customers’ AI chats, preview uploaded documents, and reach internal APIs. The issues are CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950, affecting multi-tenant Dify deployments; Zafran said a low-bar console account could abuse tracing and plugin-daemon features for cross-tenant access, and Dify released fixes in version 1.14.2. The report also notes Dify used a PDFium build vulnerable to CVE-2024-5846 until December 21, 2025. — Organizations using Dify, especially in shared cloud setups, may have exposed private prompts, responses, and uploaded files to other users. Admins should update to Dify 1.14.2 immediately and apply any recommended web application firewall rules for CVE-2026-41948.
Sources: Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Samsung fixed Galaxy KNOX kernel flaw CVE-2026-20971 that exposed devices from the S9 through S25 to local kernel attacks
Samsung patched a high-severity flaw in its KNOX security framework that affected a wide range of Galaxy phones and tablets, including models from the Galaxy S9 through S25. The bug, CVE-2026-20971, was an eight-year-old use-after-free vulnerability in the interaction between the PROCA process authenticator and FIVE kernel integrity system. Researchers said an untrusted app could trigger kernel memory corruption on Android 13, 14, 15, and 16; Samsung fixed it in the January 2026 security release. — This matters because the flaw sat in Samsung’s device-security layer for years across many generations of phones, creating a potential path to deeper device compromise if attackers could get code onto a target device. Samsung users and enterprise mobile admins should make sure affected Galaxy devices have the January 2026 update or later installed.
Sources: Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks
FFmpeg fixes PixelSmash flaw CVE-2026-8461 that can crash apps and enable code execution in Jellyfin under some conditions
FFmpeg fixed a newly disclosed bug that can crash or potentially compromise apps and servers that process malicious video files. The flaw, CVE-2026-8461, is a heap out-of-bounds write in FFmpeg's MagicYUV decoder affecting libavcodec users; JFrog showed remote code execution on Jellyfin 10.11.9 and Nextcloud setups with movie previews enabled, while other apps including Kodi, Emby, PhotoPrism, OBS Studio, and desktop thumbnailers may be vulnerable to denial of service. FFmpeg 8.1.2 contains the fix. — Organizations and self-hosting users that automatically scan or preview uploaded media should treat this as urgent because a booby-trapped video can trigger processing without being played. Update FFmpeg and any bundled copies in products like Jellyfin, and review whether automated media preview or ingestion workflows expose internet-facing systems.
Sources: FFmpeg fixes PixelSmash flaw in widely used video decoder, FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
Microsoft fixes AutoGen Studio flaw that could let a malicious webpage run commands on a developer’s machine
Microsoft fixed a vulnerability chain in AutoGen Studio that could let a malicious webpage trick an AI agent into running commands on the computer hosting the tool. The issue, dubbed AutoJack, affected AutoGen Studio builds made directly from the GitHub main branch before hardening commit b047730; Microsoft said it never shipped in a PyPI release. The chain involved unauthenticated MCP WebSocket access, localhost trust bypass, and attacker-controlled server_params that could launch PowerShell, Bash, or other executables. — Developers experimenting with AI agents could have exposed their own workstation to remote command execution just by having a browsing-capable agent visit hostile content. Anyone who built AutoGen Studio from GitHub during the affected window should update and run it only in an isolated, low-privilege environment.
Sources: Microsoft fixes AutoGen Studio flaw that enabled code execution
phpBB fixes decade-old authentication bypass that can let attackers log in as any forum user
phpBB has fixed a long-hidden security flaw that can let an attacker sign in as any user on affected forums, including administrators. The bug has no CVE yet and affects phpBB 3.3.16 and earlier plus 4.0.0-a2; phpBB says version 3.3.17 fixes the 3.x branch, while no safe 4.x release is available yet. Researchers said the issue is trivial to exploit with a single HTTP request in default configurations, though separate checks reportedly prevent direct remote code execution through the admin panel. — Forum operators should treat this as urgent because an attacker could impersonate staff, read private messages, and alter or delete content without needing special setup. Update phpBB 3.x to 3.3.17 immediately, and admins on 4.0.0-a2 should move to the patched master branch or apply vendor guidance as soon as possible.
Sources: phpBB forum fixes auth bypass bug lurking for a decade, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Apple patches Beats Studio Buds Bluetooth flaw CVE-2025-20701 that could let nearby attackers eavesdrop
Apple released a firmware update for Beats Studio Buds to fix a flaw that could let someone nearby listen through the earbuds' microphone before they are paired. The issue, CVE-2025-20701, affects Airoha Bluetooth system-on-chip code used in the earbuds and was fixed in Beats Firmware Update 1B211. Apple says an attacker within Bluetooth range could exploit the unpaired device while it is seeking pair requests; researchers previously showed related Airoha flaws CVE-2025-20700 and CVE-2025-20702 could also help attackers hijack headphone functions and issue call commands. — People using affected Beats earbuds could be exposed to nearby spying even without pairing the device first. Users should ensure their Beats Studio Buds receive firmware 1B211 by pairing them with an iPhone, iPad, or Mac and confirming the update in Bluetooth settings.
Sources: Apple fixes Beats Studio Buds flaw that let hackers spy on conversations, Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Splunk patches critical Splunk Enterprise flaw CVE-2026-20253 that lets unauthenticated attackers create or overwrite files
Splunk released security updates for a critical flaw in Splunk Enterprise that could let attackers on the network create or modify files without logging in. The bug, CVE-2026-20253, has a CVSS score of 9.8 and affects a PostgreSQL sidecar service endpoint that lacks authentication; Splunk also fixed three high-severity Splunk Enterprise bugs tied to remote code execution, server-side request forgery (making the server send attacker-chosen requests), and cross-site scripting, plus additional issues in Splunk SOAR and third-party components. — Organizations running Splunk Enterprise or Splunk SOAR should treat this as a high-priority update because the most severe issue is remotely reachable without authentication. Admins should patch quickly and review exposure of Splunk services to internal and external networks.
Sources: Splunk, Palo Alto Networks Patch Severe Vulnerabilities, Atlassian, Splunk Patch Critical Vulnerabilities, Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure (+1 more)
F5 patches critical NGINX vulnerabilities CVE-2026-42530 and CVE-2026-42055 that can crash servers and potentially allow code execution
F5 released emergency updates for NGINX products to fix critical security flaws that can let an unauthenticated attacker crash internet-facing servers and, in some cases, potentially run malicious code. The main issues are CVE-2026-42530 and CVE-2026-42055, both rated 9.2, affecting HTTP modules in NGINX Plus, NGINX Open Source, and NGINX Gateway Fabric; exploitation can trigger worker-process restarts, and arbitrary code execution may be possible if Address Space Layout Randomization (a memory-protection feature) is disabled or bypassed. F5 also patched NGINX Gateway Fabric flaws CVE-2026-11311 and CVE-2026-50107 that let authenticated attackers inject NGINX configuration directives. — Organizations using NGINX to run websites, APIs, or application gateways may be exposed to denial-of-service and possible remote compromise, especially on internet-facing systems. Administrators should identify affected NGINX deployments and apply F5's out-of-band updates promptly.
Sources: F5 Patches Critical, High-Severity NGINX Vulnerabilities, F5 issues out-of-band patches for critical NGINX vulnerabilities, F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
Atlassian issues broad security updates for Jira, Confluence, Bitbucket, Bamboo, Crowd, and other products over critical dependency flaws
Atlassian released a large set of security updates for many of its self-hosted products, including Jira, Confluence, Bitbucket, Bamboo, Crowd, Fisheye/Crucible, and Jira Service Management. The fixes cover dozens of third-party dependency vulnerabilities across about 100 bulletins, including critical flaws in Axios (CVE-2026-42043, CVE-2026-40175, CVE-2026-42264), Apache Tomcat (including CVE-2026-41293, CVE-2026-43512, CVE-2026-43515), and Netty (CVE-2026-42584). — Organizations running Atlassian server and data center products may be exposed through bundled components they do not directly track, so administrators should apply the relevant product updates promptly. The story matters because these tools are widely used for code hosting, ticketing, documentation, and internal collaboration.
Sources: Atlassian, Splunk Patch Critical Vulnerabilities
Cisco patches critical Cisco ISE and ISE-PIC command-execution flaw CVE-2026-20181
Cisco released security fixes for a critical flaw in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could let an attacker run commands on affected systems. The bug, CVE-2026-20181, is a 9.1-severity input-validation issue that can be exploited over HTTP by a remote attacker with valid administrative credentials to gain OS-level access and then escalate to root; in single-node deployments it can also cause a denial-of-service. Fixes are in ISE/ISE-PIC 3.3 Patch 11 and 3.4 Patch 6, with a hotfix for 3.5 and inclusion planned for 3.5 Patch 4; Cisco also fixed CVE-2026-20190, an unauthenticated information-disclosure flaw. — Organizations using Cisco ISE or ISE-PIC should patch quickly because these systems help control who and what can join the network, making compromise especially sensitive. Even though Cisco says it has no evidence of active exploitation, the combination of root-level impact and possible credential exposure makes this an update-now issue for administrators.
Sources: Critical Command Execution Vulnerability Patched in Cisco ISE
Cisco adds Catalyst SD-WAN Validator to the list of products affected by exploited flaw CVE-2026-20127
Cisco has updated its February advisory to say another SD-WAN product, Catalyst SD-WAN Validator, is vulnerable to a maximum-severity flaw that attackers have already used. The issue, CVE-2026-20127, is an improper authentication bug that can let an attacker become an administrator; Cisco previously said it could then be chained with CVE-2022-20775, a path traversal flaw, to gain persistent root access on vulnerable SD-WAN systems. — Organizations using Cisco SD-WAN need to confirm Validator was included in their remediation and review logs for signs of compromise. This matters because affected systems can be fully taken over and used to alter core network settings.
Sources: Cisco adds another SD-WAN box to max-severity bug advisory
Researcher releases RoguePlanet Windows zero-day that can give SYSTEM access on patched Windows 10 and 11
A security researcher published a new Windows zero-day exploit that can give an attacker full SYSTEM privileges on fully patched consumer PCs. The proof-of-concept, dubbed RoguePlanet, abuses a race condition in Microsoft Defender to achieve local privilege escalation on Windows 10 and Windows 11 systems with June 2026 updates installed; the researcher says earlier versions also enabled remote code execution through malicious .vhd(x) files on remote SMB shares and BitLocker bypass paths, but the currently released exploit is validated primarily as local escalation and reportedly does not yet work on Windows Server. — This matters because a public exploit can help malware or intruders turn limited access on a Windows machine into full control even after current patches are installed. Organizations should watch for Microsoft guidance, restrict untrusted SMB and disk-image handling where possible, and prioritize detection for SYSTEM-level escalation from Defender-related activity.
Sources: New Windows Zero-Day Exploit ‘RoguePlanet’ Released, Angry bug hunter with Microsoft beef drops new Windows 0-day, ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker (+2 more)
Google Chrome 149 security update fixes 429 vulnerabilities, including critical ANGLE and Network bugs
Google released Chrome 149 with fixes for 429 security vulnerabilities, a record-sized browser security update that affects users on Windows, macOS, and Linux. The most severe issue is CVE-2026-10881, a CVSS 9.6 out-of-bounds read/write flaw in the ANGLE graphics engine that could let a remote attacker use a crafted HTML page to escape Chrome’s sandbox and potentially run code on the operating system. Google also fixed critical flaws CVE-2026-10882 in Network and CVE-2026-10883 in ANGLE in versions 149.0.7827.53 for Linux and 149.0.7827.53/54 for Windows and macOS. — Chrome is widely used, so a large set of browser bugs with multiple critical issues can put many users and organizations at risk from malicious websites. Users and administrators should update Chrome promptly across all devices and managed fleets.
Sources: Chrome 149 Patches 429 Vulnerabilities, Chrome 149 Update Patches 28 Vulnerabilities, Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities
CISA adds actively exploited LiteSpeed cPanel plugin flaw CVE-2026-54420 to KEV and orders agencies to patch within 3 days
CISA warned that attackers are actively exploiting another flaw in LiteSpeed’s cPanel user-end plugin and told U.S. federal agencies to secure affected servers within three days. The bug, CVE-2026-54420, affects LiteSpeed cPanel user-end plugin versions before 2.4.8 and can let an attacker who already has FTP access or a web shell (a malicious script that gives remote server control) escalate privileges to root on shared hosting servers running CloudLinux/CageFS; LiteSpeed said exploitation has been seen in the wild and provided log-based detection guidance. — Organizations using affected LiteSpeed cPanel hosting plugins should treat this as urgent because active attackers can turn limited server access into full root control. Update to version 2.4.8 or later immediately and check logs for signs of exploitation.
Sources: CISA warns of another cPanel plugin flaw exploited in attacks, Joomla, LiteSpeed Vulnerabilities Exploited in Attacks
Attackers use FortiClient EMS zero-day CVE-2026-35616 to push infostealer malware to managed devices
Attackers are using a critical Fortinet server flaw to send malware to computers managed by FortiClient Endpoint Management Server (EMS). The issue, CVE-2026-35616, is a remote code execution bug in FortiClient EMS that can be exploited without authentication via crafted requests; Fortinet patched it in April after warning it had already been used as a zero-day, and Arctic Wolf now says fresh attacks are abusing EMS scripting workflows to deploy EKZ Infostealer disguised as a Fortinet patch. — This can turn a central management server into a way to infect every device it manages, putting passwords, browser cookies, and other sensitive data at risk. Organizations running FortiClient EMS should patch immediately, check for suspicious PowerShell/script activity, and investigate whether fake update jobs were pushed to endpoints.
Sources: Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks, Hackers exploit FortiClient EMS flaw to push infostealer malware, FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch (+2 more)
Cisco patches exploited Catalyst SD-WAN Manager zero-day CVE-2026-20262 that can lead to root access
Cisco released fixes for a zero-day in Catalyst SD-WAN Manager that attackers were already using to gain deeper control of vulnerable systems. The flaw, CVE-2026-20262, affects SD-WAN vManage deployments including on-prem, Cloud, Cloud-Pro, and FedRAMP environments. Cisco says an authenticated remote attacker can abuse insufficient input validation in a file-upload API to create or overwrite files, then escalate privileges to root. Fixed releases include 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. — Organizations using Cisco SD-WAN management systems should treat this as urgent because it was exploited before patches were available and can lead to full system compromise. Update immediately and review Cisco's indicators of compromise, especially file-upload attempts involving index.jsp and .war files in vmanage logs.
Sources: Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks, Cisco SD-WAN make-me-root bug under attack, Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks
CISA adds exploited LiteSpeed cPanel plugin zero-day CVE-2026-48172 to KEV and urges immediate removal or patching
CISA says a critical bug in the LiteSpeed user-end plugin for cPanel is being actively exploited and can give attackers root-level control of affected servers. The flaw, CVE-2026-48172, is a 9.8-severity privilege-escalation vulnerability affecting user-end plugin versions 2.3 through 2.4.4; LiteSpeed fixed it in version 2.4.5, later bundled in WHM Plugin 5.3.1.0 with user-end plugin 2.4.7, while cPanel also removed the vulnerable plugin via a nightly update on May 19. — Organizations running cPanel with the LiteSpeed user-end plugin could be exposed to full server compromise, so this is an update-now or remove-now situation. Admins should upgrade immediately, remove the plugin if they cannot patch, and review logs and suspicious IP activity for signs of exploitation.
Sources: CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day, CISA gives feds 4 days to patch actively exploited cPanel plugin flaw, CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
Microsoft fixed critical Microsoft 365 Copilot flaw CVE-2026-42824 that let one click steal mailbox and SharePoint data
Microsoft patched a critical flaw in Microsoft 365 Copilot Enterprise that could let an attacker steal sensitive data from a user's email, OneDrive, SharePoint, and calendar after the user clicked a crafted link. The issue, CVE-2026-42824, was demonstrated as a three-part attack chain dubbed SearchLeak that combined parameter-to-prompt injection, an HTML rendering race condition, and a Bing server-side request forgery (SSRF) path to bypass content security protections and exfiltrate Copilot search results. — Organizations using Microsoft 365 Copilot Enterprise could have had internal data quietly siphoned out through normal-looking links, with little visible sign to the victim. The fix is already available, so defenders should verify Microsoft 365 Copilot protections are current and review for suspicious link-based abuse involving Copilot, Bing, OneDrive, SharePoint, and Exchange data.
Sources: New attack turned Microsoft 365 Copilot into 1-click data theft tool, One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Palo Alto says attackers are exploiting GlobalProtect VPN auth bypass flaw CVE-2026-0257
Palo Alto Networks says attackers are now using a GlobalProtect VPN flaw to try to get into corporate networks without valid credentials. The issue, CVE-2026-0257, affects PAN-OS GlobalProtect portal and gateway configurations that use authentication override cookies with specific certificate reuse; attackers can forge those cookies and establish unauthorized VPN access on unpatched devices. Rapid7 says it saw exploitation from at least May 17, 2026, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog. — Organizations that use Palo Alto GlobalProtect could be exposed to unauthorized remote access into internal networks, so this is an urgent patch-now issue. Defenders should update PAN-OS immediately and, if needed, disable authentication override cookies or use a separate certificate for that feature.
Sources: Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks, Recent Palo Alto Networks Vulnerability Exploited for Weeks, Palo Alto VPN bug graduates from advisory to active exploitation (+2 more)
CISA adds actively exploited LiteLLM command-injection flaw CVE-2026-42271 to KEV catalog
CISA says attackers are actively exploiting a critical flaw in BerriAI's LiteLLM, an artificial intelligence gateway used to connect apps to multiple model providers. The bug, CVE-2026-42271, is a command-injection vulnerability, meaning crafted input can make a server run attacker-chosen system commands. CISA added it to the Known Exploited Vulnerabilities catalog, but public details on the attacks remain limited. — Organizations running internet-facing or internally exposed LiteLLM instances should treat this as urgent and patch or isolate affected systems immediately. An actively exploited command-injection flaw can quickly lead to full server compromise and follow-on data theft.
Sources: In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
Microsoft patches Surface firmware flaw that could permanently brick devices when Secure Boot protections are disabled
Microsoft has been quietly patching a Surface firmware flaw that could make some devices permanently unbootable after a single crafted command sequence. The issue affects Surface hardware using the Surface System Aggregator Module (SSAM or SAM) embedded controller when Secure Core and Secure Boot are disabled; a researcher said arbitrary write commands sent through a driver interface could overwrite controller or boot-related firmware and leave the device unable to complete startup after reboot. No CVE is cited in the report. — This matters for Surface owners and enterprise IT teams because the impact is physical loss of the device until motherboard-level repair or replacement. Organizations managing Surface fleets should review Microsoft's firmware updates, keep Secure Boot and Secure Core enabled where possible, and restrict administrator-level access that could reach the hardware interface.
Sources: Microsoft has mostly repaired a flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet, Microsoft has mostly repaired flaw in Surface hardware that allowed unprotected devices to be bricked by a single packet
Ivanti patches two critical Sentry flaws, including root remote-code-execution bug CVE-2026-10520
Ivanti released emergency security updates for its Sentry mobile gateway after finding two critical flaws that could let attackers take over affected systems. The bugs are CVE-2026-10520, a maximum-severity OS command injection issue that can enable remote code execution as root, and CVE-2026-10523, an authentication bypass that can let unauthenticated attackers create rogue admin accounts. Fixes are in Sentry versions R10.5.2, R10.6.2, and R10.7.1; Ivanti said it has no evidence of active exploitation at disclosure. — Organizations using Ivanti Sentry should update immediately because these bugs could hand an attacker full control of a gateway that sits between mobile devices and internal corporate systems. Even without confirmed in-the-wild abuse yet, Ivanti edge and management products have a strong history of rapid post-disclosure exploitation.
Sources: Ivanti: Max severity Sentry flaw allows code execution as root, Critical Vulnerabilities Patched in Fortinet, Ivanti Products, Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 (+3 more)
Microsoft issues mitigations for YellowKey Windows BitLocker bypass zero-day tracked as CVE-2026-45585
Microsoft said it is tracking the publicly disclosed YellowKey Windows BitLocker security feature bypass as CVE-2026-45585 and published mitigations pending a security update. The flaw can allow access to BitLocker-protected drives by abusing specially crafted FsTx files and WinRE behavior; Microsoft recommends disabling autofstx.exe auto-start in WinRE and requiring BitLocker TPM+PIN startup authentication. — Organizations and users relying on BitLocker for device-at-rest protection may need to apply mitigations immediately because PoC details are public and a fix is not yet available. Defenders should review BitLocker startup settings and WinRE configuration now.
Sources: Microsoft shares mitigation for YellowKey Windows zero-day, Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit, Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass (+9 more)
CISA adds actively exploited Microsoft Exchange Server XSS flaw CVE-2026-42897 to KEV catalog
CISA on May 15, 2026 added CVE-2026-42897, a Microsoft Exchange Server cross-site scripting vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under BOD 22-01, federal civilian agencies must remediate by CISA's due date, and CISA urged all organizations to prioritize patching KEV-listed flaws. — Active exploitation of an Exchange Server flaw raises immediate risk for organizations running the product, especially federal agencies subject to KEV deadlines. Defenders should identify exposed Exchange instances and prioritize remediation or mitigation quickly.
Sources: CISA Adds One Known Exploited Vulnerability to Catalog, Microsoft patches Exchange Server zero-day exploited in attacks, Microsoft Patches Exploited Exchange Server Vulnerability (+1 more)
CISA says new directive will change how federal agencies prioritize and patch cyber vulnerabilities
CISA says it is about to change how U.S. federal agencies handle software flaws, telling them to focus first on the vulnerabilities and systems that pose the highest real-world risk. Acting Director Nick Andersen said a binding operational directive due Wednesday will shift agencies away from treating every patch the same and toward prioritizing internet-exposed assets, Known Exploited Vulnerabilities, exploit automation, and critical functions; CISA also plans closer risk reviews with critical infrastructure operators. — This could change patching deadlines and vulnerability-management practices across the federal government and influence how critical infrastructure owners prioritize fixes. Agencies and defenders should watch for the directive’s release because it may require faster action on the most dangerous exposed systems while de-emphasizing lower-risk issues.
Sources: CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says, CISA to require federal agencies to patch some cyber vulnerabilities within 3 days, CISA tells govt agencies to patch critical exploited flaws in 3 days (+1 more)
Palo Alto Networks patches Cortex XSOAR and XSIAM flaw CVE-2026-0274 that can expose restricted resources
Palo Alto Networks released fixes for a serious vulnerability in Cortex XSOAR and Cortex XSIAM that could let attackers access and change protected resources. The flaw, CVE-2026-0274, is a high-severity improper credential-validation issue in the CommvaultSecurityIQ integration and does not require special configuration to be triggered; Palo Alto also patched eight additional medium- and low-severity bugs in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App. — Teams using affected Palo Alto platforms should install updates because the flaw could undermine access controls in tools used for security operations and response. Even without known active exploitation, these are widely deployed enterprise products and should be patched before attackers can weaponize the bugs.
Sources: Splunk, Palo Alto Networks Patch Severe Vulnerabilities
Google patches exploited Chrome zero-day CVE-2026-11645 in Chrome 149
Google released a Chrome 149 security update that fixes an actively exploited browser flaw, putting Chrome users at risk until they update. The zero-day, CVE-2026-11645, is a high-severity out-of-bounds read/write bug in the V8 JavaScript engine that can let a remote attacker run code inside Chrome’s sandbox via a specially crafted HTML page; exploitation likely requires chaining with a separate sandbox-escape flaw for full compromise. Google said the bug was reported in late April by an anonymous researcher. — Anyone using Chrome should update promptly because this flaw is already being used in real attacks. Even though the code runs inside Chrome’s sandbox, browser zero-days are high-priority because attackers often combine them with other bugs to fully compromise devices.
Sources: Google Patches 5th Chrome Zero-Day Exploited in 2026, Google patches new Chrome zero-day flaw exploited in the wild, Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now (+2 more)
Arista says exploited EOS flaw CVE-2026-7473 will not be patched and affected switch owners must use mitigations
Arista says hackers have exploited a flaw in its EOS network operating system, and some affected switch platforms will not get a software fix. The issue, CVE-2026-7473, affects certain Arista devices configured as tunnel endpoints and can cause them to accept and decapsulate unconfigured tunnel traffic sent to the same IP address. Arista says impacted products include 7020R, 7280R/R2, and 7500R/R2 series, with some IPv6 decapsulation scenarios also affecting 7280R3, 7500R3, and 7800R3. CISA has added the bug to its Known Exploited Vulnerabilities list. — Organizations using affected Arista switches may be exposed right now, and there is no vendor patch planned, so this is a mitigation-or-replace situation rather than a routine update. Network defenders should identify affected tunnel configurations immediately, apply Arista's workarounds, and prioritize review because CISA says the flaw is being actively exploited.
Sources: No Patch Planned for Exploited Arista EOS Vulnerability, CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Claroty finds critical remote-attack flaws in Vertiv UPS cards and Trane Tracer SC+ HVAC controllers used in data centers
Researchers found critical vulnerabilities in Vertiv UPS network cards and Trane Tracer SC+ HVAC controllers that could let hackers remotely disrupt power protection and cooling systems in data centers and other facilities. Claroty reported authentication-bypass and remote-code-execution flaws in Vertiv cards, and authentication bypass, remote code execution, denial-of-service, and sensitive-information exposure issues in Trane Tracer SC+ building-management controllers; the vendors have issued patches, but the article does not list CVE IDs or affected versions. — These products help keep servers powered and cool, so successful attacks could cause outages, hardware damage, or forced shutdowns. Organizations using Vertiv UPS management cards or Trane Tracer SC+ should identify exposed systems and apply vendor patches and mitigations quickly.
Sources: Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers
Public zero-day in VS Code and github.dev can steal GitHub tokens and expose private repositories
A newly disclosed Visual Studio Code flaw can let attackers steal a victim’s GitHub sign-in token with a single click on a malicious link, potentially exposing all private repositories that account can access. Researcher Ammar Askar published proof-of-concept exploit code on June 3, 2026; no CVE has been assigned and no official patch is available. The bug abuses message passing between sandboxed webviews and the main editor in github.dev, allowing a malicious extension to be installed and extract a broad GitHub OAuth token. — Developers, maintainers, and employees who use github.dev or VS Code-linked GitHub workflows could have source code and other private repository data exposed before a fix is available. Until Microsoft and GitHub ship a patch, users should treat github.dev links cautiously and clear github.dev cookies/site data so unexpected extension sign-in prompts appear.
Sources: VS Code zero-day lets hackers steal GitHub tokens in one click, One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens, Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures (+3 more)
Check Point patches exploited VPN authentication-bypass zero-day CVE-2026-50751 tied to Qilin ransomware activity
Check Point says attackers used a zero-day flaw to break into some of its VPN systems, and at least one confirmed follow-on intrusion was linked to the Qilin ransomware operation. The main issue, CVE-2026-50751, is an unauthenticated authentication-bypass bug affecting Remote Access VPN, Mobile Access / SSL VPN, and Spark gateways when configured with deprecated IKEv1, legacy clients, and no mandatory machine certificate; Check Point also disclosed CVE-2026-50752, an IKEv1 certificate-validation flaw that could enable man-in-the-middle attacks on site-to-site VPNs. Exploitation began May 7 and has hit a few dozen organizations globally. — Organizations using affected Check Point VPN setups could be exposed to break-ins without valid credentials, with ransomware risk if attackers get in. This is urgent: apply Check Point's updates immediately or disable IKEv1, require machine certificates, and follow the vendor's mitigations.
Sources: Check Point links VPN zero-day attacks to Qilin ransomware gang, Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix, CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day (+2 more)
Adobe patches 123 security flaws across Experience Manager, ColdFusion, Acrobat, Campaign Classic and other products
Adobe released security updates fixing 123 vulnerabilities across 11 products, affecting organizations and users running Experience Manager, ColdFusion, Acrobat Reader and other Adobe software. The biggest group is 57 flaws in Adobe Experience Manager, while ColdFusion and Campaign Classic include the highest-priority issues, with two Campaign Classic remote-code-execution bugs rated CVSS 10. Adobe said it has no evidence of in-the-wild exploitation and did not list CVE IDs in this report, but marked the ColdFusion and Campaign Classic issues as priority 1, meaning exploitation is more likely. — Organizations using Adobe server products should review and apply these updates promptly, especially for ColdFusion and Campaign Classic, because remote-code-execution bugs can let attackers take over systems. End users should update Acrobat and Reader through normal patch channels.
Sources: Adobe Patches 123 Vulnerabilities
OpenSSL patches high-severity PKCS#7 verification flaw CVE-2026-45447 and 17 other vulnerabilities
OpenSSL released new versions to fix a high-severity bug that can crash applications and may allow remote code execution when they verify a specially crafted signed message. The main issue, CVE-2026-45447, is a heap use-after-free in PKCS7_verify() triggered by a malformed PKCS#7 or S/MIME SignedData digestAlgorithms field; OpenSSL also patched 17 other flaws ranging from low to moderate severity affecting certificate handling, encryption integrity, denial of service, and possible code execution paths. — OpenSSL is embedded in many servers, appliances, and applications, so this can affect far more systems than organizations realize. Teams should identify where OpenSSL is deployed and apply the new releases promptly, especially in products or services that process S/MIME or PKCS#7 signed content.
Sources: OpenSSL Patches High-Severity Vulnerability Found With AI
Veeam patches critical Backup & Replication flaw CVE-2026-44963 that lets domain users run code on backup servers
Veeam released fixes for a critical flaw in its Backup & Replication software that could let a low-privilege domain user take over a backup server. The issue, CVE-2026-44963, affects Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds when the backup server is joined to a Windows domain; it was fixed in version 12.3.2.4854, and Veeam says version 13.x is not affected due to architectural changes. — Backup servers are high-value targets because attackers and ransomware gangs use them to steal data and destroy recovery options. Organizations running affected Veeam versions should update immediately and review whether backup servers are unnecessarily joined to a domain.
Sources: New Veeam vulnerability exposes backup servers to RCE attacks, Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Zcash fixes critical Orchard privacy-pool flaw that could have let attackers create fake ZEC
Zcash fixed a critical vulnerability in its Orchard shielded transaction system that could have allowed attackers to generate counterfeit ZEC while transactions still appeared valid. Security researcher Taylor Hornby found the issue on May 29 while auditing Orchard; the bug was a failed transaction-input validation check in the zero-knowledge proof workflow, affecting the Orchard privacy pool introduced in 2022. No CVE is cited, and it is unclear whether the flaw was exploited before the fix. — This is the kind of bug that can undermine trust in a cryptocurrency by allowing undetectable fraudulent coin creation. Zcash users, exchanges, and infrastructure operators should confirm they are running the patched software and watch for any follow-up guidance on possible past exploitation.
Sources: Critical Zcash Vulnerability Found and Fixed
CISA says attackers are exploiting SolarWinds Serv-U denial-of-service flaw CVE-2026-28318
CISA says hackers are now actively exploiting a recently patched SolarWinds Serv-U bug to crash exposed file-transfer servers. The flaw, CVE-2026-28318, affects SolarWinds Serv-U MFT and FTP software on Windows and Linux and can be triggered without authentication using specially crafted POST requests with Content-Encoding: deflate; SolarWinds fixed it in Serv-U 15.5.4 Hotfix 1 and advised admins who cannot patch to restrict access and block such requests. — Organizations running internet-exposed Serv-U servers could face service outages right now, including federal agencies ordered to remediate by June 19. If you use Serv-U, patch immediately or apply SolarWinds' temporary filtering and access restrictions while checking for signs of attempted abuse.
Sources: CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers, CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog, SolarWinds Serv-U Vulnerability Exploited in the Wild
Suspected Iranian hackers accessed internet-exposed gas station tank monitors across multiple U.S. states
U.S. officials believe suspected Iranian hackers broke into fuel-tank monitoring systems at gas stations in several states. The attackers targeted automatic tank gauges, or ATG systems, that were exposed online without passwords and changed displayed readings but reportedly could not alter actual fuel volumes. No physical damage has been reported, but officials warned the access could potentially hide leaks or create other safety and critical-infrastructure risks. — Gas stations and operators using older internet-connected monitoring gear may be at risk right now, especially if devices are reachable online without authentication. Operators should immediately remove ATG systems from direct internet exposure, require passwords, and review logs and display anomalies.
Sources: In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking, CISA warns of cyberattacks targeting fuel tank monitoring systems, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA (+1 more)
Google fixes actively exploited Android zero-day CVE-2025-48595 in June 2026 security update
Google released Android security updates that fix an actively exploited flaw affecting devices running Android 14 and later. The zero-day, CVE-2025-48595, is a high-severity Android Framework vulnerability that Google says has seen limited targeted exploitation and can let a local attacker achieve code execution and privilege escalation. The June 2026 bulletins also patch 124 vulnerabilities in total, including 18 critical issues across Framework, System, Qualcomm components, and other closed-source and kernel-related parts. — People and organizations using Android devices may be exposed to a flaw already being used in real attacks, even if only in targeted cases. Apply the June 2026 Android security update as soon as your device vendor makes it available, with particular urgency for Pixel users and higher-risk targets.
Sources: Google fixes one actively exploited Android zero-day, 124 flaws, Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities, Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited (+1 more)
CISA warns Linux kernel container-escape flaw CVE-2022-0492 is being exploited in the wild
CISA says attackers are now exploiting a Linux kernel bug that can let someone break out of a container and gain root-level control on the host system. The flaw, CVE-2022-0492, is an improper authentication issue in Linux cgroups v1 that allows modification of the release_agent mechanism, enabling privilege escalation and container escape; CISA added it to the Known Exploited Vulnerabilities catalog after Kaspersky reported real-world exploitation, and federal agencies were told to patch by June 5. — Organizations running Linux containers could be at risk of full host compromise if affected systems are unpatched. This is urgent for cloud, server, and platform teams: identify systems using cgroups v1, apply available kernel fixes, and review container hardening and isolation settings immediately.
Sources: Organizations Warned of Exploited Linux Kernel Vulnerability, CISA warns of active attacks exploiting Android, Linux bugs
Attackers exploit Burst Statistics WordPress plugin flaw to create administrator accounts on vulnerable sites
Attackers are targeting a flaw in the Burst Statistics WordPress plugin that can let outsiders take over websites by creating administrator accounts. Defiant says versions 3.4.0 to 3.4.1.1 contain an authentication bypass in application-password validation for REST API requests, allowing unauthenticated attackers to impersonate an admin for a request and use admin-level functions. Users should update to version 3.4.2 or newer. — Sites using Burst Statistics may be vulnerable to full website takeover, so this is urgent for WordPress administrators and hosting providers. Check plugin versions now, update immediately, and review for unexpected administrator accounts or suspicious REST API activity.
Sources: Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
Acer warns of two maximum-severity zero-days in Wave 7 routers and says fixes are coming by end of June
Acer says two critical security holes in its Wave 7 mesh routers could let attackers break in remotely, and patches are not available yet. The flaws, CVE-2026-49200 and CVE-2026-49201, affect Wave 7 routers running firmware T7c_GBL_1.01.000055 or earlier. One bug exposes plaintext web and Telnet credentials through an unauthenticated web-accessible log file, while the other uses a hardcoded AES key in backup handling to let attackers alter backups and implant persistent backdoor access. — People and organizations using affected Acer Wave 7 routers could face account compromise and long-term unauthorized access if devices are exposed. This is urgent because there is no patch yet; users should disable remote management or restrict it to trusted IP addresses and apply Acer's firmware update as soon as it is released.
Sources: Acer working to patch max severity zero-days in Wave 7 routers
CISA says attackers are exploiting Oracle WebLogic server flaw CVE-2024-21182
A long-patched Oracle WebLogic Server vulnerability is now being exploited in real attacks, putting internet-facing servers at risk if they were not updated. CISA added CVE-2024-21182 to its Known Exploited Vulnerabilities catalog on June 1, 2026. Oracle patched the flaw in July 2024; it can be exploited remotely without authentication against affected WebLogic Server instances, and successful exploitation can expose sensitive data or allow broader server compromise. — Organizations running Oracle WebLogic should treat this as urgent because attackers no longer need valid logins to target exposed systems. Patch immediately, check whether any WebLogic servers are internet-accessible, and hunt for signs of compromise if updates were delayed.
Sources: Oracle WebLogic Vulnerability Exploited in the Wild, CISA flags two-year-old Oracle flaw as actively exploited in attacks, Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
HP patches critical CVE-2026-0826 in Poly VoIP phones that can let attackers remotely take over devices
HP released fixes for a critical flaw in several Poly Voice VoIP phone models that could let an attacker remotely seize control of a phone and use it as a foothold inside a company network. Rapid7 said CVE-2026-0826 is a stack-based buffer overflow in Session Description Protocol parsing when Interactive Connectivity Establishment is enabled, affecting Poly VVX 150/250/350/450 and Trio 8300/8500/8800 devices; a malicious SIP INVITE can trigger root-level remote code execution, and HP has published patched firmware. — Organizations using these desk and conference phones should treat this as urgent because compromised voice devices often sit on trusted internal networks and typically lack security tooling. Update affected Poly firmware now and disable ICE where it is not needed.
Sources: Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
Attackers exploit WP Maps Pro WordPress plugin flaw CVE-2026-8732 to create administrator accounts
Attackers are trying to take over WordPress sites that use the WP Maps Pro plugin by secretly creating their own administrator accounts. The bug, CVE-2026-8732, affects WP Maps Pro 6.1.0 and earlier and stems from an unauthenticated AJAX endpoint tied to a temporary support-access feature; a crafted request can create an admin user and generate a passwordless login link. Wordfence says it blocked more than 3,600 exploitation attempts in 24 hours, and the vendor fixed the issue in version 6.1.1 on May 20, 2026. — Any site running the vulnerable plugin can be fully taken over, letting attackers plant backdoors, change content, or steal data. Users should update WP Maps Pro to 6.1.1 or later immediately and review WordPress admin accounts for unexpected new users.
Sources: WP Maps Pro bug exploited to create admin accounts on WordPress sites, Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts, WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
Attackers are now exploiting Windows Server Netlogon remote-code-execution flaw CVE-2026-41089
A critical Windows Server security flaw that can let outsiders run code on domain controllers is now being exploited in real attacks. Belgium's Centre for Cybersecurity said CVE-2026-41089, a stack-based buffer overflow in the Netlogon remote procedure call (RPC) service, is under active exploitation after Microsoft patched it in May 2026. The bug affects supported Windows Server versions including Windows Server 2025 and can be triggered by a specially crafted network request without prior authentication. — Domain controllers are the systems that authenticate users across many business networks, so compromise can put an entire organization at risk. Organizations running Windows Server should treat this as high priority and patch exposed and internal domain controllers immediately.
Sources: Critical Windows Netlogon RCE flaw now exploited in attacks, Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs
Google Chrome 148 update fixes 151 browser vulnerabilities, including 22 critical flaws
Google released a Chrome 148 security update that fixes 151 vulnerabilities, including 22 critical bugs that could help attackers run malicious code through the browser. The most severe issues named are CVE-2026-9872 (out-of-bounds write in GPU), CVE-2026-9873 (use-after-free in Network), CVE-2026-9874 (use-after-free in Dawn), CVE-2026-9875 (out-of-bounds read in WebGL), and CVE-2026-9876 (use-after-free in WebGL). The update is rolling out as 148.0.7778.216/217 for Windows, 148.0.7778.215/216 for macOS, and 148.0.7778.215 for Linux. — Chrome is widely used, so browser flaws with remote-code-execution potential can expose large numbers of people and organizations to drive-by compromise if left unpatched. Users and IT teams should update Chrome promptly across Windows, macOS, and Linux fleets.
Sources: Chrome 148 Update Patches 151 Vulnerabilities
Pretalx patched stored XSS flaw CVE-2026-41241 that could let conference organizers' accounts be hijacked
Pretalx, an open source platform used by many conferences to manage call-for-proposals and schedules, fixed a flaw that could let a malicious speaker submission run code in an organizer's browser. The issue, CVE-2026-41241, is a stored cross-site scripting (XSS) bug in searchable fields such as submission titles, speaker names, usernames, and email addresses; when an organizer searched for a matching record, attacker-supplied HTML or JavaScript could execute, steal a cross-site request forgery (CSRF) token, submit authenticated actions, or exfiltrate visible data. It was patched in April and fixed in pretalx 2026.1.0. — Conference teams using pretalx could have had proposal data changed or organizer sessions abused simply by viewing malicious submissions, so affected admins should update to pretalx 2026.1.0 or later and review organizer access and stored submissions. Because pretalx is reused across many events, one product bug can affect multiple independent conference systems at once.
Sources: How to guarantee a speaker gig: Hack the system. Literally, Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate
India CERT-In tells organizations to patch or isolate exploited internet-facing vulnerabilities within 12 hours
India's national cyber agency has told organizations to fix, mitigate, or disconnect exposed critical systems within 12 hours when a known-exploited vulnerability affects them. In new CERT-In guidance on defending against AI-assisted attacks, the agency says the half-day target applies where feasible to internet-facing or 'crown jewel' systems with exploited n-day flaws, while other cases such as internal systems generally get a 24-hour target; this is guidance rather than a single-CVE advisory. — This raises the urgency for Indian organizations and anyone tracking national cyber guidance as attackers use artificial intelligence to speed up exploitation. Defenders should review patching and mitigation playbooks now so internet-exposed high-value systems can be patched, shielded, or taken offline quickly when active exploitation is known.
Sources: India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat
Drupal announces critical core security update for high-risk vulnerability affecting versions 8 and later
Drupal announced a core security release for May 20, 2026, warning that exploits could appear within hours of disclosure. The issue affects Drupal core 8+ with patches planned for supported 11.x and 10.x branches, plus hotfixes for end-of-life 9.5 and 8.9 releases. No CVE or technical details were disclosed ahead of release. — Drupal is widely used by government, education, healthcare, and large organizations, so a high-risk core flaw has broad exposure. Defenders should monitor the advisory and be ready to apply updates immediately, especially because Drupal expects rapid exploit development.
Sources: Drupal critical update to fix bug with high exploitation risk, Clear your calendar, Drupal user: You have a critically urgent patch to install, Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks (+5 more)
TrendAI patches exploited Apex One zero-day CVE-2026-34926 in on-premises servers
TrendAI says attackers exploited a flaw in its Apex One security software before a patch was available, putting organizations that run the on-premises server at risk. The bug, CVE-2026-34926, is a directory traversal vulnerability in Apex One on-premise that can let an attacker alter a key server table and inject malicious code for deployment to agents; TrendAI says admin credentials to the server are required, and CISA has added the CVE to its Known Exploited Vulnerabilities catalog. — Organizations using Apex One on-premises should treat this as urgent because the flaw was exploited in real attacks and could let attackers push malicious code from the management server to protected endpoints. Apply TrendAI's update immediately and review who has administrative and remote access to the Apex One server.
Sources: TrendAI Patches Apex One Zero-Day Exploited in the Wild, Trend Micro warns of Apex One zero-day exploited in the wild
Ubiquiti patches five UniFi OS flaws, including three maximum-severity bugs that can be exploited remotely
Ubiquiti released security updates for UniFi OS after disclosing five vulnerabilities that could let attackers tamper with devices, read files, or run commands. The issues include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, all rated maximum severity, plus CVE-2026-33000 and CVE-2026-34911. They affect UniFi OS on UniFi Consoles that run UniFi Network, Protect, Access, Talk, and Connect; the flaws involve improper access control, path traversal, command injection, and information disclosure. Ubiquiti says the bugs can be exploited with low complexity and nearly 100,000 internet-exposed endpoints have been observed. — Organizations and home or small-business users running UniFi OS may be exposed to remote compromise if their management devices are reachable online. This is an update-now issue: apply Ubiquiti's patches promptly and reduce internet exposure of UniFi management interfaces where possible.
Sources: Ubiquiti patches three max severity UniFi OS vulnerabilities
Google accidentally exposed details of an unfixed Chromium flaw that can keep malicious code running after the browser is closed
Google briefly made public the technical details of an unfixed Chromium security flaw that affects Chrome and other Chromium-based browsers including Edge, Brave, Opera, Vivaldi, and Arc. Researcher Lyra Rebane says a malicious website can abuse a Service Worker to keep JavaScript running after the browser is closed, potentially enabling stealthy botnet-style abuse such as proxying traffic or launching distributed denial-of-service attacks; no CVE is listed in the report, and the bug was reportedly marked fixed in tracking systems even though current dev builds still appeared vulnerable. — This matters because simply visiting a malicious site once may be enough to leave a browser doing work in the background without the user's knowledge. Users and defenders should watch for an emergency browser update from Google and other Chromium-based vendors and apply it quickly once available.
Sources: Google accidentally exposed details of unfixed Chromium flaw
Cisco patches critical Cisco Secure Workload API flaw CVE-2026-20223 enabling Site Admin access
Cisco released fixes for CVE-2026-20223, a critical 10.0 vulnerability in Cisco Secure Workload Cluster Software caused by insufficient validation and authentication in internal REST API endpoints. The flaw affects SaaS and on-prem deployments and can let remote attackers read sensitive information and modify configurations across tenant boundaries with Site Admin privileges. Patched versions are 3.10.8.3 and 4.0.3.17. — Organizations using Cisco Secure Workload face high-impact administrative compromise and cross-tenant exposure if unpatched. Defenders should prioritize updates because exploitation requires only a crafted API request and no in-the-wild activity is needed for urgency at this severity.
Sources: Cisco Patches Critical Vulnerability in Secure Workload, Cisco serves up yet another perfect 10 bug with Secure Workload admin flaw, Max severity Cisco Secure Workload flaw gives Site Admin privileges
Attackers exploit SonicWall Gen6 SSL-VPN MFA bypass CVE-2024-12802 after incomplete remediation
ReliaQuest and SonicWall say attackers exploited CVE-2024-12802 on SonicWall Gen6 SSL-VPN appliances to bypass MFA when admins installed patched firmware but did not complete required LDAP reconfiguration steps. Intrusions observed from February to March involved brute-forced credentials, internal reconnaissance, RDP access, and attempted deployment of Cobalt Strike and a BYOVD tool across multiple sectors and geographies. — Organizations using SonicWall Gen6 SSL-VPN may still be exposed even if they believe they are patched, because firmware updates alone do not fully mitigate the flaw. Defenders should verify the manual remediation, hunt for listed indicators, and treat exposed Gen6 devices as potentially compromised.
Sources: Hackers bypass SonicWall VPN MFA due to incomplete patching
PoC exploit released for PinTheft Arch Linux local root escalation flaw in Linux RDS
Researchers disclosed a public proof-of-concept for PinTheft, a recently patched Linux local privilege-escalation flaw in the kernel's RDS zerocopy send path that can yield root on Arch Linux systems. The bug has not yet received a CVE ID. Exploitation requires the RDS module to be loaded, io_uring enabled, and other specific conditions; Arch is reportedly the only common distro tested with RDS enabled by default. — Public exploit code raises the risk of real-world abuse on exposed systems, especially where patching lags. Defenders should prioritize kernel updates or disable/unload the RDS modules as a mitigation.
Sources: Exploit released for new PinTheft Arch Linux root escalation flaw
ChromaDB CVE-2026-45829 exposes internet-facing Python API servers to unauthenticated RCE
Researchers disclosed CVE-2026-45829, a maximum-severity flaw in ChromaDB's Python FastAPI server that can let unauthenticated attackers force the server to fetch and execute a malicious Hugging Face model. The bug affects the Python API code introduced in ChromaDB 1.0.0 and was reportedly still present in 1.5.8; it was unclear at publication whether 1.5.9 fixed it. HiddenLayer said about 73% of internet-exposed instances were running vulnerable versions. — Organizations exposing ChromaDB's Python API over HTTP could face full server compromise without authentication. Defenders should immediately restrict exposure, prefer the Rust frontend where possible, and verify whether deployed versions are patched.
Sources: Max-severity flaw in ChromaDB for AI apps allows server hijacking
CISA warns ScadaBR 1.2.0 flaws can enable unauthenticated remote code execution in ICS environments
CISA published ICS advisory ICSA-26-139-03 for ScadaBR 1.2.0, detailing CVE-2026-8602, CVE-2026-8603, CVE-2026-8604, and CVE-2026-8605. The flaws include missing authentication, OS command injection, CSRF, and hard-coded credentials, and could allow unauthenticated attackers to inject sensor readings, gain admin access, or execute commands on the SCADA system. CISA said ScadaBR had not responded to mitigation requests. — ScadaBR is used in critical infrastructure sectors including energy, water, chemical, dams, and manufacturing, so these bugs present serious operational risk. Defenders should urgently identify exposed ScadaBR 1.2.0 systems and apply mitigations or isolate them, especially given the lack of a vendor response noted by CISA.
Sources: ScadaBR
Linux kernel CVE-2026-46333 lets local unprivileged users read root-only files
CVE-2026-46333 is a Linux kernel local information-disclosure flaw that can let unprivileged users read files normally restricted to root, including SSH keys and other sensitive credentials. The issue affects multiple LTS kernel lines from 5.10 upward, and a fix has landed upstream in commit 31e62c2 adjusting ptrace get_dumpable logic. — Multi-user Linux systems and servers running affected kernels may allow low-privilege users to access highly sensitive secrets and escalate further compromise. Defenders should identify affected kernel versions and apply the upstream fix or vendor updates promptly.
Sources: Linux kernel flaw opens root-only files to unprivileged users