< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 17 of 125

Critical Cosmos DB flaw exposed master key risk

🛡️ A security researcher discovered a critical vulnerability in Azure Cosmos DB's Gremlin API that could have exposed the Cosmos Master Key, granting attackers read/write access to any Cosmos account and revealing database identifiers. Wiz, a Google subsidiary, disclosed the issue to Microsoft in November 2025; Microsoft pushed a hot fix within two days and later re-engineered the service to remove the master key and add guardrails. This follows a prior 2021 finding where Cosmos DB keys were exposed via a Jupyter Notebook flaw.
read more →

Google fixes over a thousand Chrome vulnerabilities

🔒 Google disclosed fixes for 1,072 security bugs across Chrome 149 and 150, and an additional 370 in Chrome 151, including seven critical issues. The company attributes a surge in discoveries to AI-assisted techniques and is shifting to faster release cadences and automated tooling to shorten disclosure and patch windows. Google is also piloting dynamic patching, session-preserving restarts, and moves toward memory-safe languages like Rust to reduce entire classes of C++-origin vulnerabilities.
read more →

Critical TeamCity RCE Patch Urged for On‑Prem Servers

🔒 JetBrains warned of a critical pre-authentication vulnerability in TeamCity On‑Premises that could allow unauthenticated HTTP(S) requests to bypass authentication and execute arbitrary OS commands. Tracked as CVE-2026-63077 and rated 9.8, the flaw affects all on‑prem deployments and has been fixed in versions 2025.11.7 and 2026.1.3. Customers unable to upgrade can apply a security patch plugin; TeamCity Cloud customers need take no action.
read more →

Critical TeamCity RCE Vulnerability Alert from JetBrains

🚨 JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises tracked as CVE-2026-63077 that allows remote code execution via the agent polling protocol when an attacker has HTTPS access to the server. All on‑premises TeamCity versions are affected, while TeamCity Cloud customers are already protected. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for 2017.1+ for those who cannot upgrade. Administrators are urged to apply patches immediately and follow recommended hardening practices such as limiting internet exposure and requiring VPN or other protective layers.
read more →

VMware patches critical auth bypass and VM escape flaws

🔒 Broadcom released emergency security updates for VMware vCenter, ESX, Workstation, and Fusion to address five vulnerabilities, including three critical flaws that allow authentication bypass, remote code execution, and VM escape. Affected products include VMware Cloud Foundation and various telco platform offerings; administrators should assume prepatched versions are vulnerable and apply fixes immediately. There are no effective workarounds, and some updates require service interruptions or host reboots.
read more →

Critical Ruflo MCP bridge flaw risks full AI agent takeover

🔒 A critical vulnerability in the open-source AI agent platform Ruflo (CVE-2026-59726, "RufRoot") allows unauthenticated attackers to exploit an exposed Model Context Protocol (MCP) bridge and gain full control of enterprise AI environments. Researchers at Noma Security showed a single HTTP request to the bridge’s /mcp endpoint can execute code, steal LLM API keys, access conversations, hijack agents, and poison persistent AI memory. Ruflo issued a rapid patch that binds the MCP bridge to loopback and enforces failure-closed behavior, while researchers urged immediate firewall and credential remediation.
read more →

Google Chrome fixes 370 vulnerabilities in update

🔒 Google’s Chrome team released version 151 (Windows, Mac and Linux) addressing 370 vulnerabilities, including seven critical flaws. The critical issues include several use after free bugs across Compositing, Views, Skia and Ozone, plus validation flaws in Dawn and ANGLE and a race condition in the Updater. These were reported between 18 May and 14 June 2026. The update also patches 71 high, 170 medium and 122 low severity issues, with researchers awarded $58,500 via the bug bounty.
read more →

Cisco FMC Zero‑Day Added to CISA KEV Catalog

🔒 CISA has added a newly disclosed zero‑day affecting Cisco Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated remote actor to log in using a static low‑privilege account and access sensitive data; Cisco warns the risk increases if the management interface is internet‑exposed. Hotfixes are available for multiple FMC versions and Cisco published an IoC check for "/var/tmp/license.tmp" to help detect compromise.
read more →

Cisco warns of FMC static credential zero-day exploit

🔒 Cisco warns that a high-severity static credential flaw in Secure Firewall Management Center (FMC)—tracked as CVE-2026-20316—has been actively exploited in zero-day attacks to gain unauthorized access. The flaw stems from built-in static credentials for a low-privilege account, enabling unauthenticated remote login and access to account data. Cisco released hot fixes for multiple FMC releases and advises installing them immediately, noting no effective workarounds and recommending credential rotation if compromise is detected.
read more →

Critical Active Storage flaw risks app secrets

🛡️ Ruby on Rails released patches for a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files via crafted image uploads. The issue affects applications using libvips for image processing and can expose secrets like secret_key_base, master keys, database credentials, and API tokens. Operators should upgrade Rails and libvips, and rotate any credentials potentially accessible to the Rails process.
read more →

Critical Ruflo MCP flaw allows unauthenticated RCE

🛡️ Researchers disclosed a critical vulnerability (CVE-2026-59726) in Ruflo, an open-source agent orchestration harness for Anthropic Claude Code and OpenAI Codex, that permitted unauthenticated remote code execution. The flaw, present in versions before 3.16.3, exposed an unauthenticated Model Context Protocol (MCP) bridge on port 3001 by default due to docker-compose binding to 0.0.0.0. Exploitation allowed attackers to run shell commands, steal LLM API keys, read conversations, poison AI memory, and persist backdoors. The maintainer released fixes after disclosure, changing the MCP binding to loopback, gating execution controls, and enabling MongoDB authentication.
read more →

Three critical VMware flaws permit authentication bypass

🔒 Broadcom issued security updates for multiple VMware products, including ESX, vCenter, Workstation, and Fusion, addressing three critical vulnerabilities. The highest-severity issues include an authentication bypass (CVE-2026-59309) and a directory traversal allowing code execution (CVE-2026-59310) in vCenter. Additional fixes cover VMXNET3 out-of-bounds write, out-of-bounds read, and insufficient logging flaws in ESX and related products. Broadcom reports no evidence of in-the-wild exploitation and has released patches across VMware Cloud Foundation, vSphere, Workstation, and Fusion versions.
read more →

Windows 11 KB5101684 preview brings 42 fixes

🔔 Microsoft released the optional KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, delivering 42 bug fixes and incremental feature rollouts. This non-security monthly preview updates systems to builds 26100.8973 and 26200.8973 and is installable via Settings > Windows Update or the Microsoft Update Catalog. Notable changes include File Explorer improvements, Voice Isolation for Voice Access, enhanced Windows Hello ESS support for external fingerprint readers, and fixes for File History and MDM enrollment issues. The update is optional and currently has no known issues.
read more →

Patched Firefox JIT Bug Enabled Remote Code Execution

🛡️ Nebula Security disclosed a high-severity Firefox JIT vulnerability, tracked as CVE-2026-10702, that could be triggered simply by visiting a malicious webpage and was used to compromise Tor Browser builds embedding affected Firefox versions. Mozilla fixed the flaw in Firefox 151.0.3 and rated it High; the bug allows arbitrary code execution in the browser renderer process and was exploited by Nebula as the initial stage of their IonStack browser-to-kernel chain on an ARM64 Android 17 build. Users are urged to update to the latest Firefox release.
read more →

Critical Gitea RCE in diffpatch fixed in 1.27.1

🔒 Gitea patched a critical remote code execution (RCE) vulnerability tracked as CVE-2026-60004 affecting versions 1.17 through 1.27.0. A user with repository write access could craft a malicious patch that becomes an active Git hook and executes shell commands as the Gitea service account. The flaw requires authentication and write permission, but default open registration allows outsiders to create accounts and exploit unpatched instances. Upgrading to 1.27.1 addresses the issue; Gitea Cloud upgrades were scheduled automatically.
read more →

Arista fixes critical VeloCloud Orchestrator flaw

🔒 Arista has released patches for a critical vulnerability in VeloCloud Orchestrator (VCO) that is actively being exploited in the wild. The vendor warned the flaw may allow remote attackers to access privileged internal functionality and impact VCO hosts, affecting confidentiality, integrity, and availability. Customers are urged to upgrade to fixed releases (VCO 5.2.3.14+, 6.1.3.4+, 6.4.2.4+) and to consider incident response actions such as credential rotation and device validation. Advisors stressed the severity—an unauthenticated command‑injection in an orchestration platform—and warned that on‑premises users often receive fixes more slowly than cloud deployments.
read more →

vBulletin fixes pre-auth RCE; public exploit published

🛡️ A critical pre-authenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x up to 5.7.5 and 6.2.1 allowed attackers to execute arbitrary PHP via template rendering. Researcher Egidio Romano reported the flaw via SSD Secure Disclosure and published a technical analysis and PoC showing the issue stems from improper input sanitization in runMaths(), which forwards data to PHP's eval(). vBulletin released patched 6.2.2 and backported fixes as Patch Level 1; users on older 5.x builds are advised to upgrade.
read more →

High-severity flaws bypass Hugging Face diffusers trust check

🔒 Three high-severity vulnerabilities in Hugging Face’s diffusers library allowed crafted model repositories to execute arbitrary code during model loading by bypassing the trust_remote_code safeguard. Zafran Security published findings showing the trust check ran separately from the code load, creating timing and path-based bypasses exploited by crafted files and configuration changes. Hugging Face patched the issues in diffusers 0.38.0 in May and acknowledged related concerns in transformers.
read more →

AI-assisted research reveals Linux net/sched race

🛡️ AI-assisted research uncovered a years-old use-after-free race in the Linux kernel's net/sched code that permits local privilege escalation to root (CVE-2026-53264). The bug arises from mismatched locking where an entry can be freed before an RCU grace period ends, creating a window for the kernel to access freed memory. The flaw was found by Lee Jia Jie of STAR Labs, who used AI to locate and reliably reproduce the race; a patch defers freeing until after the grace period. Distributions should apply upstream fixes via normal security channels.
read more →

OpenWrt critical DHCPv6 overflow and LuCI audit fixes

🛡️ OpenWrt released 24.10.8 (and 25.12.5 for 25.12 users) to fix a critical DHCPv6 stack overflow (CVE-2026-53921) and several remotely triggerable network-service flaws enabled by default. The DHCPv6 bug lets an unauthenticated attacker reachable to UDP/547 overwrite a stack buffer in odhcpd, potentially enabling code execution on devices lacking typical mitigations. The advisory includes public PoC code; other fixes include uhttpd request-smuggling, DHCPv6 hostname-injection XSS, and LuCI component hardening still under review.
read more →