< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 18 of 125

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →

AI-assisted exploit yields local Linux root escalation

🔒 STAR Labs published a local privilege-escalation exploit for CentOS Stream 9 that abuses a use-after-free race in the kernel traffic-control subsystem (CVE-2026-53264, CVSS 7.8). Researcher Lee Jia Jie says AI aided discovery and exploit development; the exploit requires specific kernel options, unprivileged user namespaces, and a kernel-specific ROP chain. Upstream fixes landed June 1, 2026 and have been backported to multiple stable branches, but distribution coverage remains uneven.
read more →

Arista VeloCloud Orchestrator Exploited in Wild

🔒 Arista has confirmed a maximum-severity OS command injection flaw, CVE-2026-16812 (CVSS 10.0), affecting on-premises VeloCloud Orchestrator (VCO) that is under active exploitation. The issue can enable remote attackers to execute arbitrary code and access privileged internal functionality, potentially compromising confidentiality, integrity, and availability. Affected on-prem VCO releases include versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1; hosted and dedicated deployments were already fixed. Arista shared three malicious IPs as IoCs and urged operators to preserve logs, restrict access, and update promptly.
read more →

FastJson zero-day RCE targeting US firms

📣 Researchers report active exploitation of a critical remote code execution flaw in the FastJson Java library (versions 1.2.68–1.2.83). Observed attacks primarily target US organizations across finance, healthcare, retail and other sectors, and exploit Spring Boot fat-JAR deployments. Alibaba confirmed the issue but no patch is available; users are urged to enable SafeMode or migrate to non-affected builds.
read more →

Arista patches VeloCloud Orchestrator zero-day exploit

🔒 Arista released fixes for a maximum-severity unauthenticated command injection in on-premises VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited. The flaw allows remote attackers network access to the VCO web interface to execute privileged commands without credentials, potentially impacting confidentiality, integrity, and availability. Affected on-premises versions include 5.2.x, 6.1.x, 6.4.x and early 7.0.x releases; hosted and dedicated deployments are already patched. Administrators are urged to apply the provided updates, restrict VCO web access, block listed malicious IPs, and review logs for signs of compromise.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →

Public exploit targets vBulletin template engine

🔒 SSD Secure Disclosure published a proof-of-concept on July 27 showing an unauthenticated request can reach PHP's eval() in vBulletin templates and execute code on unpatched forums. vBulletin released fixes (6.2.2 and patches for branches) on July 1, and Cloud instances are reported patched, but self-hosted sites running affected versions remain at risk. The disclosed exploit contained a trivial one-character typo that prevents it running unchanged; the underlying vulnerability, identified as CVE-2026-61511 by SSD, enables pre-auth remote code execution via ajax/render/pagenav template rendering.
read more →

n8n fixes high‑severity sandbox escape allowing server command execution

🔒 n8n patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute OS commands on the server hosting the automation platform. The flaw, tracked as GHSA-gv7g-jm28-cr3m and rated High (CVSS 8.7), affects versions <2.31.5 and >=2.32.0,<2.32.1; fixes were released in 2.31.5 and 2.32.1. Administrators are urged to update rather than rely on interim access-restriction mitigations.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

Critical Fastjson 1.x RCE Exploitation in Spring Boot

🛡️ Security firms ThreatBook and Imperva report active exploitation attempts targeting a critical remote code execution flaw in Fastjson 1.x, affecting Spring Boot executable fat-JAR deployments. Tracked as CVE-2026-16723 with an Alibaba CVSS of 9.0, the chain impacts Fastjson 1.2.68–1.2.83 when SafeMode is disabled and can execute code without AutoType or classpath gadgets. Alibaba has not yet released a 1.x patch; recommended mitigations include enabling SafeMode or using the 1.2.83_noneautotype build and migrating to Fastjson2 long-term.
read more →

Certighost AD CS exploit lets low-privileged users

🔒 Researchers published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. Codenamed Certighost, the flaw enables a Kerberos credential capable of DCSync to retrieve the krbtgt secret. Microsoft patched AD CS as CVE-2026-54121 on July 14 and rated it a CVSS 8.8; the full proof-of-concept was released publicly.
read more →

NodeBB fixes eight AI-discovered security flaws

🔒 Aikido Security's AI pentest agents found eight high-severity vulnerabilities in NodeBB, affecting every version before 4.14.0; NodeBB has issued patches and administrators should upgrade to 4.14.2. The issues ranged from a settings-based elevation that opened the admin dashboard to ordinary members, to unauthenticated access to private messages and categories, to a page-rendering flaw enabling injected links that execute code. Five flaws lived in federation code connecting forums to the fediverse, and several fixes were deployed piecemeal between May and July, with 4.14.0 rebuilding page text handling.
read more →

Redis fixes multiple authenticated RCE paths via RESTORE

🔒 Redis issued seven security releases on July 23 after published PoCs demonstrated authenticated remote code execution chains against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All exploit chains require RESTORE; Streams chains also need EVAL and XGROUP, while the 8.8.0 chain needs EVAL plus the bundled RedisBloom module. Users should upgrade to the fixed branch and, until then, revoke RESTORE from unnecessary accounts and block untrusted network access.
read more →

Critical Check Point SmartConsole vulnerability exploited

🔒 Check Point confirmed a critical SmartConsole vulnerability (CVE-2026-16232, CVSS 9.3) is being exploited in the wild, allowing unauthenticated attackers to obtain login tokens and assume full admin privileges. The company released a patch and urged limiting Trusted Clients to trusted IPs/subnets while noting practical challenges with dynamic addressing. Check Point found ten impacted customers and recommends applying the hotfix rather than relying solely on mitigations.
read more →

XFS reflink race lets local unprivileged users gain root

🔒 Qualys TRU disclosed a decade-old race condition in the Linux XFS filesystem that allows an unprivileged local user to gain full root access on kernels 4.11+ when XFS reflink is enabled. The flaw, tracked as CVE-2026-64600 and dubbed RefluXFS, lets a race between concurrent writes corrupt the copy-on-write mechanism so the original file is modified directly on disk without kernel logs. Vendors merged a patch into upstream in July; affected organizations should apply vendor kernel updates and reboot to mitigate.
read more →

Sandbox escape in Claude Cowork threatens macOS users

🔒 Researchers disclosed a sandbox escape in Anthropic's Claude Cowork that allowed an agent running in a Linux VM on macOS to read and write files across the host. Accomplish AI reported the flaw, codenamed SharedRoot, and said roughly 500,000 local Cowork users were affected before mitigation. Anthropic marked the report informative; newer Cowork defaults to cloud execution, but local sessions remain vulnerable. Accomplish AI outlined mitigation steps including restricting shared mounts and disabling unprivileged namespaces.
read more →

RefluXFS: Critical XFS Race Condition Allows Root

🛡️ A nine-year-old race condition in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600 and dubbed RefluXFS by Qualys TRU, enables local attackers to overwrite protected files and gain root privileges. The flaw affects systems with reflink-enabled XFS on kernel v4.11+ and requires a directory writable by an unprivileged user plus a high-value target file. Exploitation is reliable, leaves no kernel logs, survives reboots, and bypasses common defenses because it operates at the filesystem allocation layer. Vendor-fixed kernels are available and immediate patching and rebooting are recommended.
read more →

Check Point patches SmartConsole zero-day exploit

🔒 Check Point has released a patch for an actively exploited SmartConsole zero-day (CVE-2026-16232) that permits unauthenticated attackers to obtain an application login token and authenticate with administrator privileges. Successful exploitation requires the Management Server to be reachable from the Internet and Trusted Clients not being restricted, allowing attackers to alter security configurations and policies. The vendor urged affected customers to apply updates and recommended mitigations, while CISA has added the flaw to its known exploited vulnerabilities catalog and ordered federal agencies to patch by July 25.
read more →

RefluXFS Linux flaw allows local persistent root

🛡️Qualys disclosed RefluXFS (CVE-2026-64600), a Linux kernel race in XFS reflink handling that lets an unprivileged local user overwrite root-owned files and achieve persistent root access. The bug dates to Linux 4.11 (2017) and affects systems with reflink-enabled XFS filesystems; default installs of several RHEL-derived distributions, Fedora Server, and Amazon Linux can be vulnerable. A patch was merged July 16 and vendors began shipping backports; apply updates and reboot to ensure protection.
read more →

Check Point issues fixes for actively exploited flaw

🛡️ Check Point released security updates for Security Management and Multi-Domain Management products to address multiple vulnerabilities, including a critical authentication bypass (CVE-2026-16232) actively exploited in the wild. The flaw enables unauthenticated attackers to obtain a SmartConsole login token and gain full administrative privileges if Management is exposed to the internet without Trusted Client or firewall restrictions. Additional patches cover two other high-severity issues (CVE-2026-62144 and CVE-2026-62145). Customers are urged to apply the July 22 Jumbo hotfix, restrict Trusted Clients to trusted IPs, and secure Management access with firewall protections.
read more →