< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 10 of 125

Active SQL injection in Sangoma Switchvox exploited

🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
read more →

SQL Injection Flaw in WP Backup Plugin Risks Site Takeover

🛡️ A high-severity SQL injection in the All-in-One WP Migration and Backup plugin (CVE-2026-19949) can let unauthenticated attackers achieve remote code execution and site takeover. Discovered by Jack Taylor and reported via Wordfence, the flaw stems from incorrect parsing of escaped backslashes and quotes during archive restoration. Exploitation requires an admin to perform an export/import action, and despite a patch in version 7.110, roughly 3.25 million sites remain vulnerable.
read more →

Malicious Git configs enable code execution in agents

🔒 Manifold Security disclosed eight vulnerabilities across seven CLI AI coding agents where a repository's .git config can name commands the agent runs locally as the user, bypassing sandboxes and prompts. Some vendors have released fixes (goose, Claude Code core.fsmonitor path, Cursor), while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained unpatched at Manifold's retest on September 1. OpenAI published related CVEs for Codex the same day.
read more →

GeoNetwork fixes chained unauthenticated RCE vulnerabilities

🛡️ GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution by combining a missing authorization check on the formatter upload endpoint with an unsafe Saxon XSLT configuration. The fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with advisory details published August 31. Vendor-sourced scans found 121 internet-exposed instances across 39 countries, many tied to government or national agencies, and administrators are urged to upgrade or block write methods to the formatter endpoint as an interim mitigation.
read more →

Critical SonicWall SMA1000 Zero-Day Flaws Exposed

🛡️ SonicWall has disclosed two zero-day vulnerabilities affecting SMA1000 appliances (models 6210, 7210 and 8200v), with impacted firmware versions 12.4.3-03453 and 12.5.0-02835 (platform-hotfix) and older. The more severe issue, CVE-2026-83548, is a pre-authentication SSRF in the Appliance Work Place interface with a CVSS score of 10.0, while CVE-2026-83549 is a post-authentication RCE in the Management Console (CVSS 7.8). SonicWall advises upgrading to the latest hotfix, contacting Technical Support to hunt for IoCs, and re-imaging or redeploying appliances and resetting credentials if compromises are found.
read more →

SonicWall warns of exploited SMA1000 zero-days

🛡️ SonicWall warned customers that attackers are chaining two newly discovered SMA1000 zero-day vulnerabilities to achieve remote code execution. The first is a critical command injection flaw (CVE-2026-83548) tied to an SSRF issue in the Appliance WorkPlace, while the second (CVE-2026-83549) affects the Management Console and requires admin privileges. Affected models include SMA1000 6210, 7210, and 8200v; SonicWall urges immediate hotfix upgrades and recommends re-imaging and credential resets if compromise is suspected.
read more →

Nearly 22,000 Exchange Servers Exposed to Hijack Bug

🔒 Tracked as CVE-2026-62911, a high-severity authentication bypass in Microsoft Exchange Server 2016, 2019, and SE allows attackers with basic privileges to hijack all user mailboxes via low-complexity, user-interaction attacks. Microsoft patched the flaw in August 2026 Patch Tuesday, but Shadowserver found 21,899 exposed IPs still unpatched, predominantly in the US and Germany. Authorities including NCSC-NL and Germany's BSI warn that exploit code is public and urge immediate updates or isolation of affected servers, especially as ESU updates for older Exchange versions end in October 2026.
read more →

Amazon RDS Custom adds latest SQL Server CU and GDR

🛡️ Amazon RDS Custom for SQL Server now supports the latest Cumulative Update (CU) and General Distribution Release (GDR) packages. This update includes SQL Server 2019 CU32+GDR (RDS 15.00.4480.2.v1) and SQL Server 2022 CU25+GDR (RDS 16.00.4262.2.v1). The GDRs address vulnerabilities such as CVE-2026-47295, CVE-2026-47296, CVE-2026-54118, and CVE-2026-55002. You can apply these updates via the Amazon RDS console, AWS SDK, or CLI.
read more →

Windows Defender false-off notifications raise risk

🛡️ Microsoft acknowledged a bug causing Windows to display “Microsoft Defender Antivirus is turned off” notifications even though the product is functioning correctly. The vendor says it will issue a fix in a future Defender update and listed affected Windows client and server versions spanning recent and legacy releases. Security experts warn the advisory may train users and SOCs to ignore critical alerts, enabling attacker tradecraft and increasing risk.
read more →

Windows 11 KB5120998 update reverts mouse settings

🐭 Microsoft confirmed that the KB5120998 August 2026 non-security preview update can change or reset mouse cursor personalization on affected Windows 11 systems. Reports indicate high‑DPI cursors may be replaced with larger white cursors and custom animations revert to defaults, with users unable to restore previous settings. Microsoft is investigating and asks affected customers to report the issue via the Feedback Hub.
read more →

Five critical WordPress plugin and theme flaws

🔒 Multiple critical vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Reports from Wordfence and Patchstack describe issues ranging from authentication bypass and privilege escalation to arbitrary file writes and remote code execution. Affected versions span multiple releases and require immediate patching or mitigation to prevent complete site takeover.
read more →

TerminalFix campaign uses reverse-tunnel to pivot

🛡️ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
read more →

ServiceNow patches three maximum severity platform flaws

🔒 ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more →

PaperCut issues second emergency patch for exploited flaws

🛡️ PaperCut released a second emergency security update after researchers found multiple bypasses of the initial fix for actively exploited vulnerabilities in PaperCut NG/MF. The company disclosed two CVEs—CVE-2026-81578 (auth bypass, 8.8) and CVE-2026-82078 (unsafe dynamic class-loading, 9.4)—that can be chained for remote code execution. The updated Emergency Patch Release 2 provides additional hardening and is available for versions 24–26 on Windows, Linux, and macOS; administrators are urged to install it and restrict web interface access.
read more →

GiveWP plugin flaw allows remote command execution

🛡️ GiveWP, a WordPress donation plugin with over 100,000 installs, contained a critical vulnerability (CVE-2026-82222) that allowed attackers to execute arbitrary server commands. Patchstack researchers reported the issue on July 28, showing exploitation required chaining unsafe unserialization, attacker-controlled serialized donations, and a bundled gadget chain. The vendor released a patch in version 4.16.7.2 on August 27 that blocks serialized payloads and cleans affected databases.
read more →

Attackers Chain Two PaperCut Flaws to Achieve RCE

🛡️ Huntress and watchTowr reported attackers chaining two recently patched PaperCut vulnerabilities to bypass authentication and achieve remote code execution. PaperCut released a second emergency patch with additional hardening after disclosure of CVE-2026-81578 and CVE-2026-82078. Observed activity includes execution of Base64-encoded commands and deployment of a cross-platform Java .class file used for reconnaissance and cleanup.
read more →

Thousands of Gitea Servers Remain Vulnerable to RCE

🔒 Shadowserver reports over 8,300 Internet-exposed Gitea instances remain unpatched against a critical code injection flaw (CVE-2026-60004) exploited in active remote code execution attacks. The vulnerability, disclosed by a Salesforce researcher, lets authenticated users execute shell commands via the diffpatch API, and default open registration enables easy exploitation. Gitea issued version 1.27.1 on July 27 to fix the issue and urged immediate upgrades, while CISA added the flaw to its actively exploited catalog and ordered federal agencies to patch swiftly.
read more →

Two root RCE chains found in Unitree G1 EDU

🔒 Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) chains impacting the Unitree G1 EDU, tracked as CVE-2026-76639 and CVE-2026-76640. One path is network-adjacent via chat_go and bashrunner, the other begins from an unauthenticated BLE bootstrap write leading to Wi‑Fi provisioning and a buffer overflow. Unitree's cloud account-to-robot ownership check was reportedly patched in July 2026, but no fixed firmware release has been publicly confirmed for the G1 EDU.
read more →

ServiceNow issues high‑severity AI Platform security fixes

🔒 ServiceNow released patches on August 27, 2026, for four vulnerabilities affecting the ServiceNow AI Platform, three rated CVSS 10.0 and exploitable by unauthenticated attackers in certain conditions. The company deployed updates to hosted instances and provided fixes to partners and self‑hosted customers, who must apply them manually. ServiceNow stated it has no current evidence of exploitation and continues to support customers applying the patches.
read more →

ServiceNow patches three critical AI Platform flaws

🔒 ServiceNow issued emergency patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) can be exploited by unauthenticated attackers with low complexity and no user interaction. The company also patched a high-severity sandbox escape (CVE-2026-6876) and urged customers to update self-hosted instances promptly.
read more →