< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles

SonicWall SMA1000 SSRF flaw signals broader security pattern

🔒 SonicWall disclosed CVE-2026-102255, a pre-authentication SSRF vulnerability in the SMA1000 Appliance Workplace interface rated CVSS 10.0, allowing attackers to make the appliance issue requests and reach internal functions without credentials. The company also reported three additional, lower-severity flaws and strongly urges customers to upgrade to fixed releases. SonicWall says there's no evidence of active exploitation yet, but experts warn the attack is trivial to execute and could enable remote compromise.
read more →

Multiple Vendor Vulnerabilities and Vendor Patches

🔒 Cisco Talos disclosed multiple vulnerabilities affecting Adobe, Apple, Foxit Reader, and Microsoft. The vendors have issued patches in accordance with Cisco’s disclosure policy. Snort rule updates are available to detect exploitation, and Talos posts ongoing vulnerability advisories on its site. Affected components include Photoshop installer, macOS CoreWLAN, Foxit PDF JavaScript features, and several Windows kernel drivers.
read more →

SonicWall issues hotfix for critical SMA1000 SSRF

🔒 SonicWall released hotfixes addressing four vulnerabilities in SMA1000 appliances, including a CVSS 10.0 SSRF in the WorkPlace portal that can be reached before authentication. The vendor says there is no evidence the flaws are being exploited, and affected firmware builds are listed with fixed and vulnerable versions. The hotfix is available via MySonicWall and requires an appliance restart; no workaround is provided.
read more →

Critical LMCache flaw allows remote code execution

🛡️ A critical vulnerability in LMCache lets unauthenticated attackers execute code on the cache server when it is configured to listen on a routable address. The flaw resides in multiprocess mode where ZeroMQ messages are unpickled before type checks, enabling crafted messages to run with the LMCache process's privileges. JFrog disclosed the issue (CVE-2026-105192) on October 7 and rated it 9.8/10; no patched release is available, and operators are advised to keep the server bound to localhost or restrict network access.
read more →

Critical Atlassian Data Center Arbitrary File Access

🛡️ Atlassian has disclosed a critical arbitrary file access vulnerability (CVE-2026-21589, CVSS 9.3) affecting multiple Data Center products including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw allows unauthenticated attackers to retrieve specific files from the web application root if they know the exact path and filename. Atlassian released patches for impacted versions and recommends temporary mitigations such as removing instances from the public internet, deploying WAF rules, and applying Tomcat or urlrewrite.xml protections. Telemetry shows early exploitation attempts from a few IPs, and security researchers warn rapid scanning and mass exploitation are likely following public technical details.
read more →

SonicWall warns of max-severity SSRF in SMA1000

🔒 SonicWall issued hotfixes to address a maximum-severity server-side request forgery (SSRF) vulnerability in SMA1000 series appliances, including the 6210, 7210, and 8200v models. This flaw enables remote, unauthenticated attackers to abuse an unintended alternate access path to make the appliance issue requests on their behalf and reach internal functionality. SonicWall recommends applying the Tuesday hotfixes immediately; there is currently no evidence of active exploitation, though over 400 exposed appliances are tracked by Shadowserver.
read more →

Critical Atlassian flaw impacts eight enterprise products

🔒 A critical arbitrary file access vulnerability, CVE-2026-21589 (9.3), affects eight Atlassian Data Center products and allows unauthenticated attackers to read files in the web app root. Atlassian urges immediate patching to fixed releases and offers limited mitigations (WAF rules, Tomcat RewriteValve, urlrewrite.xml) for those that cannot upgrade. Customers should isolate internet-facing instances, search logs for traversal patterns, and rotate exposed credentials if compromise is suspected.
read more →

DNS Root KSK-2024 Rollover and Readiness Test

🔐 On October 11, 2026 the DNS root will replace its key-signing key (KSK) with KSK-2024 (key tag 38696). Most site operators need take no action, but operators of DNSSEC-validating resolvers must ensure their trust anchors include KSK-2024 before the switch to avoid service outages. Cloudflare’s resolvers already include the new key and offer a RFC 8509-based readiness test at dnstest.dev to check whether the resolver your browser uses trusts the new root key. The post explains KSK vs ZSK roles, RFC 5011 automatic updates, and why embedding the new anchor in resolver software helps avoid issues seen during the 2018 rollover.
read more →

Atlassian warns of critical arbitrary file-access flaw

⚠️ Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability affecting multiple self-hosted Data Center products including Confluence, Jira, and Bitbucket. An unauthenticated attacker can access specific files within an application's web root if they know the exact filename and path, though directory listing is not possible. Atlassian released fixed versions and urges immediate patching; cloud instances were auto-patched. Temporary mitigations and detailed configuration steps are provided for administrators unable to patch immediately.
read more →

LibreOffice and OpenOffice permit silent Java code execution

🛡️ A malicious spreadsheet can trigger remote Java code execution in LibreOffice and Apache OpenOffice via database ranges that auto-refresh from an external ODB source. The issue requires Java support to be enabled and bypasses the usual macro trust prompt, enabling execution without user consent. LibreOffice patched the flaw as CVE-2026-63277 in updates released October 5 (move to 26.2.5 or 26.8.0), while Apache OpenOffice's matching CVE-2026-59265 remains unpatched in releases up to 4.1.16. Users can mitigate the risk by disabling Java or avoiding untrusted spreadsheets until OpenOffice issues its fix.
read more →

Critical Atlassian Data Center Path Traversal Fixes

🔒 Atlassian disclosed CVE-2026-21589, a critical path traversal vulnerability in eight Data Center products that allows unauthenticated attackers who know a file's exact path to read files from the web application root. The flaw, rated 9.3 CVSS v4.0, affects on-premises deployments and has fixed versions listed for each product; cloud offerings have been patched. Atlassian advises offlineing or restricting internet access for instances that cannot be upgraded and provides temporary WAF or server-level blocking rules as mitigations.
read more →

Dell patches 18 critical storage and Kubernetes flaws

🔒 Dell disclosed 18 CVEs affecting its Container Storage Modules (CSM) and Dell System Update (DSU), including two CVEs rated 10 and five rated 9+. The flaws could let unauthenticated or low-privilege attackers bypass auth, gain root, forge admin tokens, and execute remote code. Affected CSM versions prior to 1.17.0 and DSU versions prior to 2.3.0.0 must be updated; Dell reports no active exploitation so far. Vendors and customers are urged to apply fixes and rotate credentials.
read more →

Microsoft Exchange privilege escalation advisory

🔒 Microsoft issued out-of-band updates for a high-severity flaw in Microsoft Exchange Server that can allow an authenticated attacker to elevate privileges and access other users' mailboxes within the same organization. Tracked as CVE-2026-96940 with a CVSS score of 8.8, Microsoft applied a service-side fix for Exchange Online, while on-premises customers must install provided updates for specified Exchange Server builds. The company named researcher Jan Mitchell as the reporter and rated exploitability as "Exploitation More Likely."
read more →

Critical Dell DSU Flaw Lets Attackers Gain Root

🛡️ Dell warned customers to update the System Update (DSU) CLI after a critical path traversal vulnerability (CVE-2026-86360) was disclosed that can allow unauthenticated attackers to execute code with root privileges. The company released DSU 2.3.0.0 to patch this and four other high-severity issues, and urged immediate upgrades. U.S. agencies previously warned vendors to eliminate path traversal weaknesses, and organizations should patch promptly to reduce risk.
read more →

Citrix NetScaler zero-day prompts emergency guidance

🔒 Citrix has disclosed a high-severity zero-day, CVE-2026-88779, affecting NetScaler ADC and NetScaler Gateway that can lead to denial of service when specific SAML-related configurations are present. The vendor urged customers on affected versions to review SAML authentication entries and install updates; temporary signatures and NetScaler Global Deny List rules are available to reduce exposure. Citrix stated customer data integrity was not impacted and is monitoring the situation while CISA added the flaw to its KEV catalog.
read more →

Citrix NetScaler memory-overflow DoS vulnerability alert

⚠️ Citrix has warned of a new high-severity memory-overflow vulnerability (CVE-2026-88779) affecting NetScaler ADC and NetScaler Gateway appliances, rating it 8.7 under CVSS 4.0 and reporting observed targeted exploitation. The flaw can cause repeated denial-of-service conditions when SAML authentication is configured and used with Gateway or AAA virtual servers. Citrix provided fixed build numbers and a temporary virtual-patching mitigation via Global Deny List signatures, and warned that affected customers who already patched earlier in the week may need to upgrade again. CISA added the vulnerability to its KEV catalog with an October 7 remediation deadline for US federal agencies.
read more →

Windows KB5124010 causes crashes in AC-3 apps

🎧 Microsoft confirmed that the September 2026 preview update KB5124010 can cause some games and applications using AC-3 (Dolby Digital) audio decoding to crash or close unexpectedly. The update is optional unless devices run Windows 11 24H2 with automatic preview updates enabled. Microsoft noted many modern apps are unaffected because they use alternative decoding, and said it is investigating the issue and will provide further updates when available.
read more →

Citrix NetScaler zero-day patched after active exploitation

🔒 Citrix released security updates for a high-severity NetScaler ADC and NetScaler Gateway vulnerability, tracked as CVE-2026-88779, with a CVSS score of 8.7. The memory overflow bug can cause denial-of-service when NetScaler is configured as a SAML service provider or identity provider; customers should check for add authentication samlAction or add authentication samlIdPProfile entries. Patches are available in specified 13.1 and 14.1 releases, and CISA added the flaw to its KEV catalog with a federal remediation deadline of October 7, 2026.
read more →

Citrix issues emergency NetScaler SAML patch

🔒 Citrix has released emergency updates for a NetScaler SAML vulnerability, CVE-2026-88779, which has been exploited in active attacks and causes denial-of-service conditions. The flaw affects NetScaler ADC and Gateway appliances using SAML authentication and carries a CVSS score of 8.7. Citrix published fixes for 14.1 and 13.1 branches and supplied Global Deny Lists while urging immediate upgrades. Administrators are urged to verify SAML configuration to determine exposure and apply the new releases promptly.
read more →

GitLab patches critical AI Gateway remote command flaw

🔒 GitLab disclosed a critical vulnerability (CVE-2026-90970) in its AI Gateway that could let a logged-in user with Duo Agent Platform access escape a prompt template sandbox and run commands on self-hosted gateways. The flaw, rated 9.9 CVSS, affects gateway releases from 18.1.6 through the 19.1 line and is fixed in 19.2.4, 19.3.2, and 19.4.1. GitLab has already remediated gateways it hosts; self-managed customers are urged to update immediately.
read more →