< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 11 of 125

Critical cPanel flaw allows root code execution

🛡️ cPanel released patches for a critical vulnerability (CVE-2026-65643) affecting domain parking and addon domain handling in cPanel & WHM that could let authenticated users create arbitrary files and achieve root code execution. The company published fixed builds across multiple release branches on August 27, 2026, and advised administrators to update immediately or enable automatic updates. The advisory names patched builds including a WP Squared release, omits DNSOnly, and provides no interim mitigation or CVSS score. Servers on end-of-life versions must upgrade to receive the fix.
read more →

Windows 11 preview update KB5120998: 35 fixes

🛈 Microsoft released the KB5120998 preview cumulative update for Windows 11 25H2 and 24H2, bringing 35 non-security changes and improvements to the Start menu, taskbar, search, and system behaviors. This optional update lets administrators test bug fixes and new features before they're broadly deployed in the next Patch Tuesday release. It also begins rolling out an administrator protection feature that supplies just-in-time privileges and profile separation, disabled by default and configurable via Intune or Group Policy.
read more →

Next.js fixes critical RCE via AVIF and Windows path

🔒 Vercel released urgent patches for two critical remote code execution flaws in Next.js: one triggered by specially crafted AVIF images and another by a Windows-specific path traversal. Fixes are available in Next.js 15.5.24 and 16.3.3 published August 25, 2026; Vercel-hosted apps are already protected. Users on affected versions should upgrade immediately, especially Windows-hosted servers which have no workaround.
read more →

Amazon Kiro prompt injection enables data exfiltration

🛡️ Researchers disclosed a vulnerability in Amazon Kiro IDE (version 0.7.45 on Windows) that enables data exfiltration via prompt injection and manipulated Kiro Powers. Mindguard reported that attacker-controlled repository content and steering files can influence the agent to read and transmit sensitive local data when a malicious workspace file is opened and any message is sent to the agent. Amazon issued a remediation in Kiro IDE 0.8.140; the latest release is 1.0.337.
read more →

Microsoft issues fix for Windows 11 gaming crashes

🎮 Microsoft has begun rolling out a permanent fix for an issue that caused system crashes and games to fail with EXCEPTION_ACCESS_VIOLATION on Windows 11 devices. The problem was traced to the inpoutx64.sys driver used by peripherals or internal components with RGB lighting. The company is deploying a block that disables the driver on affected consumer and unmanaged business devices and has provided a registry workaround for enterprise administrators.
read more →

CISA Adds Six Exploited Flaws, Urges Immediate Patching

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, urging prompt patching by government agencies and critical infrastructure. Two high-severity flaws—CVE-2026-8452 in Citrix NetScaler and CVE-2019-1068 in Microsoft SQL Server—carry CVSS scores of 8.8 and require immediate attention. Citrix has published updates to address the NetScaler memory overflow, while the SQL Server RCE remains actively exploited despite a seven-year-old patch. CISA set accelerated patch deadlines for the critical and other listed flaws.
read more →

CISA directs urgent patching for Citrix NetScaler RCE

🔒 CISA has ordered federal agencies to patch Citrix NetScaler appliances by Saturday due to an actively exploited vulnerability, CVE-2026-8452. The flaw is a memory overflow affecting NetScaler ADC and Gateway appliances configured with Gateway VPN or AAA virtual servers and can lead to unpredictable behavior, DoS, or remote code execution. Researchers have observed active exploitation in attacks deploying web shells, and Citrix's advisory has not yet acknowledged in-the-wild targeting. Shadowserver currently tracks thousands of exposed NetScaler instances online.
read more →

CISA Adds Six Actively Exploited Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity issue in Citrix NetScaler ADC and NetScaler Gateway with evidence of active exploitation. The list includes flaws affecting Microsoft SQL Server, the Linux Kernel, Red Hat components, Ajax.NET Professional, and Citrix, with CISA issuing remediation deadlines for federal agencies. Security firms reported web shells and discovery activity tied to attempts exploiting the Citrix flaw, and telemetry has identified multiple attacker IPs worldwide. CISA also published a vulnerability review highlighting injection and memory-safety weaknesses as frequent root causes of exploitation.
read more →

Critical Avada WordPress Theme Zero-Click RCE

🛡️A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows an unauthenticated attacker to execute arbitrary PHP code via a zero-click exploit. Tracked as CVE-2026-18431 with a 9.8 score, the attack requires a precise sequence of authorization, input-validation, trust-boundary, and file-handling failures. ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 after disclosure by Wordfence, which withheld full details to allow administrators time to update.
read more →

GPUThor Rowhammer Bypasses NVIDIA ECC Protections

🛡️ Researchers from the University of Toronto disclosed GPUThor, a Rowhammer variant that defeats SECDED ECC on Ampere-class NVIDIA GPUs, enabling DoS and root privilege escalation. The attack achieves far higher bit-flip rates than prior GPU Rowhammer concepts by exploiting undocumented memory request coalescing and TRR behavior. Tested on RTX A4000–A6000 cards, GPUThor produced thousands of flips per GB and demonstrated both device resets and corrupted page tables leading to host root access. NVIDIA issued guidance recommending SYS-ECC, IOMMU/DMA isolation, telemetry monitoring, and restrictions on untrusted workloads.
read more →

Securing AI Gateways and Control Plane Targets

🔒 Microsoft describes attacks targeting AI infrastructure components such as gateways, retrieval platforms, orchestration services, and container runtimes that centralize credentials and execution privileges. Observed intrusions against LiteLLM, RAGFlow, and Kestra aimed to harvest secrets, persist on hosts, and monetize compute. The advisory emphasizes inventorying exposed AI surfaces, restricting administrative access, and monitoring gateway-originated execution and secret access to mitigate risk.
read more →

Ubiquiti fixes three maximum-severity vulnerabilities

🔒 Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more →

Unpatched Kaltura mwEmbed flaws enable file read and RCE

🛡️ CERT/CC disclosed two unpatched vulnerabilities in Kaltura's mwEmbed/html5lib player that allow unauthenticated remote file reads and remote code execution via unsafe PHP deserialization. The flaws (CVE-2026-19913 & CVE-2026-19912) stem from mwEmbedLoader.php accepting an attacker-controlled ServiceUrl and using PHP's unserialize() without validation. No patch is available and CERT/CC was unable to reach Kaltura; administrators are advised to restrict endpoint access, allow-list ServiceUrl, and take mitigation steps including rotating credentials in local.ini.
read more →

NemoClaw vulnerability lets local AI be poisoned

🛡️ A vulnerability in Nvidia's NemoClaw can let a malicious website trick a browser into reaching a locally running Ollama model server via DNS rebinding, giving unauthenticated API access. Cyera researchers showed an attacker could modify a model's chat template to inject persistent, hidden instructions that survive future sessions. Nvidia has patched macOS and Linux builds in NemoClaw 0.0.35, while Windows/WSL remains unpatched.
read more →

NVIDIA NemoClaw exposure lets webpage hijack Ollama

🛡️ Oasis Security disclosed a flaw in NVIDIA NemoClaw that can allow an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and implant hidden instructions inside a model's chat template. The issue stems from NemoClaw setting OLLAMA_HOST to 0.0.0.0 on some Windows/WSL paths, exposing an unauthenticated API on port 11434 that skips Host/Origin checks and can be exploited via DNS rebinding. No CVE or patch is yet linked and no exploitation was reported as of August 25, 2026.
read more →

Marimo notebook MCP command injection patched

🛡️ Marimo fixed a high-severity code injection that let a crafted notebook supply a malicious Model Context Protocol (MCP) command executed as a local subprocess when opened in edit mode. Tracked as CVE-2026-75149 and scored ~8.7–8.8, the flaw affected versions prior to 0.23.15 and required user interaction but no attacker authentication. Marimo released version 0.23.15 and later versions to remediate the issue.
read more →

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

Critical Keycloak password reset vulnerability patched

🔒 Red Hat and the Keycloak project released patches to fix a critical flaw (CVE-2026-18963) that allows an unauthenticated remote attacker to take over user accounts by forcing a password reset. Upstream Keycloak users should update to 26.7.2 (released Aug 19, 2026); Red Hat build customers must apply fixes for 26.4.15 and 26.6.6. Red Hat rates the issue 9.1 CVSS and recommends disabling the "Forgot password" feature as a temporary mitigation while upgrading.
read more →

Windows Defender driver can be repurposed for abuse

🛡️ Check Point Research found that Microsoft-signed Boot-Time Removal driver BTR.sys can be abused to perform kernel-level file and registry operations, potentially neutralizing security controls. The technique uses an undocumented encrypted transaction format rather than a conventional IOCTL interface and affects Windows versions from Windows 7 through Windows 11 25H2. CPR released a proof-of-concept tool, BTR_CLI, demonstrating extraction, transaction construction, and driver loading using the system's own copy of BTR.sys. Microsoft indicated the issue did not meet criteria for immediate servicing and noted the attack requires pre-existing privileges.
read more →

CISA orders urgent Zimbra patching for active exploit

🔔 The Cybersecurity and Infrastructure Security Agency (CISA) directed U.S. federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite flaw (CVE-2026-73570) within three days after CERT Polska reported in-the-wild attacks. The flaw, fixed in Zimbra 10.1.20 released July 20, permits unauthenticated remote code execution via a command injection in the SNMP notification component when enabled. Administrators are urged to review recent logs for indicators such as unexpected service restarts and newly created files under zimbra-owned webapps and /tmp directories.
read more →