< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 19 of 125

Zimbra update fixes nine critical vulnerabilities

🔒 Zimbra Collaboration Suite 10.1.20 addresses nine vulnerabilities across commercial and open-source editions, including a permanent fix for an SNMP command injection flaw and four XSS issues in the Classic Web Client. The update also patches mailbox delegation and EWS access control problems, an SSRF in Nextcloud integration, and a bypass for email forwarding restrictions. Synacor urges administrators to upgrade promptly to prevent exploitation by threat actors.
read more →

Oracle July 2026 Critical Patch Update Overview

🛡️ Oracle’s July 2026 Critical Patch Update is its largest ever, delivering 1,449 fixes across 32 product families, including Database, Fusion Middleware, Java SE, and GoldenGate. Fusion Middleware saw 355 vulnerabilities, 219 exploitable remotely without authentication, and ten scored a CVSS 10.0. Database Server received critical fixes including CVE-2026-61211 (CVSS 9.9) in DBMS_CLOUD and an Oracle Net Services flaw, with additional OpenSSL-related patches. Experts urge rapid triage based on exposure and business impact as the sheer volume outpaces typical patching workflows.
read more →

Ubuntu snap-confine local root escalation advisory

🛡️ Cybersecurity researchers disclosed a high-severity local privilege escalation in snap-confine (CVE-2026-8933, CVSS 7.8) affecting default Ubuntu Desktop installs of 24.04, 25.10, and 26.04. The flaw arises from a race condition introduced during sandbox initialization that lets an unprivileged user exploit temporary /tmp artifacts and symlinks to gain root. Vendors advise applying the latest snapd updates immediately to mitigate the risk.
read more →

Adobe Acrobat Chrome Extension UXSS Flaw Exposes Data

🛡️ Researchers disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) affecting versions up to 26.5.2.2. Tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio Labs, the UXSS-class issue (CVSS 7.4) allowed cross-origin read access to session-bound data after simple user interaction. Exploitation required visiting a crafted page that triggers the extension's vulnerable code path, enabling attackers to extract WhatsApp Web content without credentials or malware.
read more →

Critical Check Point SmartConsole Authentication Bypass

🔒 Check Point released a jumbo hotfix (July 22, 2026) addressing multiple security hardening issues across firewall and management products. The advisory details several CVEs, including CVE-2026-16232, an authentication bypass affecting Management when exposed to the internet without IP restrictions, which was observed in the wild. The update provides mitigation guidance, IoCs, and installation instructions for the hotfix; customers are urged to apply it and follow best practices.
read more →

Adobe Chrome extension flaw exposed WhatsApp data

🔒 The Adobe Acrobat extension for Chrome contained a chain of vulnerabilities (CVE-2026-48294, dubbed HermeticReader) that let attacker-controlled websites access conversations and other data rendered in WhatsApp Web without authentication. Guardio researchers showed the flaw allowed web pages to write into the extension's storage, activate its WhatsApp integration (Hermes), and issue DOM-manipulating commands to a WhatsApp tab. Adobe patched the issue in version 26.5.2.3; users should ensure they have the update.
read more →

Active exploitation of Windmill path traversal bug

🛡️ A high-severity path traversal flaw in open-source developer platform Windmill (CVE-2026-29059, CVSS 7.5) has been observed exploited in the wild to read arbitrary files via the get_log_file endpoint. The issue allowed attackers to access sensitive files such as /etc/passwd and, where configured, the SUPERADMIN_SECRET value, enabling superadmin access. Windmill patched the vulnerability in version 1.603.3 by adding filename sanitization; about 170 vulnerable systems across 24 countries were identified.
read more →

CISA orders urgent patch for Langflow critical RCE

🔒 The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. federal agencies to prioritize patching a critical remote code execution vulnerability in the Langflow visual AI agent framework, tracked as CVE-2026-0770. Researchers at Trend Micro reported that the flaw is in the handling of the exec_globals parameter at the validation endpoint and allows unauthenticated attackers to execute code as root. KEVIntel observed in-the-wild exploitation starting June 27 with over 220 attempts; malicious actors tried to deploy malware and access cloud credentials. Agencies must remediate by Friday under BOD 26-04, and organizations are advised to review requests to /api/v1/validate/code, restrict validation access, and rotate exposed credentials.
read more →

Ubuntu snap-confine local root escalation CVE

🔒 A high-severity vulnerability in Ubuntu's snap-confine component (CVE-2026-8933) lets any local user gain full root on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Qualys TRU published research on July 21 showing two race conditions introduced after a hardening change to set-capabilities; attackers can exploit a brief ownership window via FUSE mounts and symlinks, then bypass AppArmor to execute commands as root. Canonical has issued patches and admins are urged to update snapd immediately.
read more →

Invisible PR comment lets Azure DevOps AI abuse access

🛡️ A hidden HTML comment in an Azure DevOps pull request can instruct a reviewer's AI coding agent to act beyond an attacker's privileges, leaking sensitive data. The flaw exists because the MCP server returns PR descriptions without the spotlighting guardrail applied elsewhere, so the agent receives hidden instructions the human reviewer cannot see. Manifold Security demonstrated a proof-of-concept that chains permitted agent calls to read cross-project resources and exfiltrate content using reviewer credentials. Microsoft acknowledged the report and recommended limiting project access and reviewing changes before running AI tools.
read more →

Critical SharePoint RCE Exploited to Steal Machine Keys

🔒 Microsoft SharePoint's critical CVE-2026-50522 vulnerability is being actively exploited in the wild to steal machine keys and preserve access post-patch. Researchers observed attackers leveraging a public proof-of-concept to trigger deserialization-based remote code execution against on-premises SharePoint, allowing creation of forged authentication tokens. Microsoft fixed the flaw in July, but security firms advise rotating exposed credentials and confirming patches.
read more →

Apple fixes Hide My Email unmasking vulnerability

🔒 Apple patched a vulnerability in its Hide My Email service that could reveal users' real email addresses when forwarded messages were rejected as spam. The fix was deployed on July 3, 2026, after the flaw was disclosed to Apple by Tyler Murphy of EasyOptOuts on June 13, 2025. The issue allowed real addresses to appear in mail transfer logs and affected addresses created before July 7, 2026. Apple now says the problem is resolved, even as a class action alleges misleading privacy claims.
read more →

AWS Kiro flaw let hidden web content trigger RCE

🛡️ Hidden text on a web page allowed Kiro, AWS's agentic coding IDE, to rewrite its mcp.json configuration and execute attacker-controlled commands on a developer's machine without a usable approval step. Researchers at Intezer and Kodem Security showed that asking Kiro to summarize or fetch a page could inject setup instructions in one-pixel white text, causing Kiro to register and launch a malicious Model Context Protocol server. AWS patched the vulnerability by protecting sensitive paths and adding platform-enforced approval checks.
read more →

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation

🛡️ Microsoft patched a critical SharePoint Server deserialization flaw, CVE-2026-50522 (CVSS 9.8), which is now being actively exploited. DEVCORE researcher splitline reported the issue; Microsoft warned authenticated attackers with Site Owner privileges could execute remote code. Security firms and CISA observed attackers stealing machine keys and urged credential rotation even after patching.
read more →

Zimbra issues patch for critical SNMP command flaw

🔧 Zimbra released version 10.1.20 to address nine vulnerabilities, led by a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The update also fixes four cross-site scripting (XSS) issues in the Classic Web Client and a mail forwarding restriction bypass (CVE-2026-50055) reported by Jonah Burgess. The vendor limited details per industry best practices and urged customers to apply the fixes promptly.
read more →

Microsoft issues WSUS sync fix and manual mitigation

🛠️ Microsoft published manual steps to remediate a WSUS synchronization problem that causes Windows Update scans to fail or time out on affected servers. The issue affects client (Windows 10, v1607+) and server (Windows Server 2012+) platforms and leads to prolonged sync times or operation timeouts due to accumulating publishing metadata. A service-side mitigation was rolled out for new or rebuilt WSUS installations, while administrators with existing servers are advised to back up SUSDB, run cleanup SQL queries, reset MaxXMLPerRequest, reindex SUSDB, run the WSUS Server Cleanup Wizard, and restart IIS or the WsusPool to restore normal sync behavior.
read more →

Unofficial patches available for LegacyHive zero-day

🛡️ Free unofficial micropatches are available for a recently disclosed Windows zero-day, dubbed LegacyHive, which enables non-admin users to escalate privileges by mounting other users' registry hives. The vulnerability was disclosed by researcher Nightmare Eclipse alongside a stripped proof-of-concept after Microsoft's July 2026 updates. ACROS Security (0Patch) offers free micropatches for affected Windows 10 2004+/Windows Server 2022+ systems; Microsoft says it is investigating the claims.
read more →

Amazon RDS adds latest CU and GDR for SQL Server

🔔 Amazon RDS now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for Microsoft SQL Server, including specific builds for SQL Server 2016 SP3, 2017, 2019, and 2022. The GDR updates address vulnerabilities detailed in CVE-2026-40370. AWS recommends upgrading RDS for SQL Server instances via the Amazon RDS Management Console, AWS SDK, or CLI to apply these security and stability updates. See the Amazon RDS SQL Server User Guide for upgrade instructions.
read more →

Critical WordPress REST Batch API RCE Patch Urged

⚠️ Security researchers disclosed a pre-authentication remote code execution flaw in WordPress’ built-in REST Batch API, tracked as wp2shell. The bug allows attackers to execute arbitrary code on default WordPress installs without plugins or authentication by exploiting an indexing mismatch in the batch/v1 endpoint. Affected versions include 6.9.0–6.9.4 and 7.0.0–7.0.1; fixes were released in 6.9.5, 7.0.2 and 6.8.6. Administrators are urged to patch immediately or block the REST Batch endpoints at the web server or WAF and inventory all WordPress instances.
read more →

Microsoft works to resolve WSUS sync delays

🛠️ Microsoft is addressing a known issue that has caused Windows Server Update Services (WSUS) servers to experience prolonged synchronization times and timeouts, impacting the delivery of updates. The problem, with heightened impact since July 13, 2026, affects client and server platforms and prevents admins from deploying updates through WSUS or Configuration Manager. Mitigations have been deployed for new or rebuilt WSUS installations, and Microsoft is developing additional steps to remediate previously affected servers.
read more →