< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 2 of 125

Critical Dell CSM Flaws Allow Full Administrative Access

🔒 Dell released updates to fix multiple critical flaws in Container Storage Modules (CSM) that allow unauthenticated attackers to gain administrative control, escalate privileges, or forge tokens. Affected versions are all prior to 1.17.0, and the fixes are included in 1.18.0. Dell urges immediate updating and rotation of JWT signing secrets, as no effective mitigations exist aside from upgrading.
read more →

GitLab warns of critical RCE in AI Gateway

🔔 GitLab warned customers to immediately patch a critical AI Gateway vulnerability that could allow attackers to execute arbitrary commands on vulnerable instances. The flaw, tracked as CVE-2026-90970, affects self-hosted AI Gateway deployments and stems from improper neutralization allowing sandbox escape by authenticated users with Duo Agent Platform access. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue and said hosted AI Gateway users are already protected.
read more →

Google Pixel September 2026 Security Update Details

🔒 On September 15, Google released a Pixel-specific security bulletin addressing 110 vulnerabilities in its smartphones, highlighting CVE-2026-58704 as a zero-day exploited in targeted attacks. The bulletin complements the monthly Android Security Bulletin by fixing issues tied to Pixel hardware components such as the modem, bootloader, GPU, and fingerprint scanner. Owners should install the update via Settings → Security & privacy → System & updates → Security update → Install, and follow recommended hardening steps to reduce risk.
read more →

Dell CSM vulnerabilities give attackers admin control

🔒 Dell patched multiple maximum-severity flaws in its Container Storage Modules (CSM) that link enterprise storage arrays to Kubernetes. The issues, rooted in the CSM Authorization module, allow unauthenticated attackers to obtain administrator credentials and bypass authorization. Dell recommends updating CSM to version 1.18.0 or later to remediate the critical vulnerabilities.
read more →

Critical FortiMail Path Traversal Zero‑Day Alert

🔒 The U.S. CISA has added a critical Fortinet FortiMail flaw (CVE-2026-104286, CVSS 9.8) to its KEV catalog after reports of active exploitation. The vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests due to path traversal and NULL byte handling issues. Fortinet has identified affected FortiMail versions and provided upgrade guidance and temporary workarounds, including disabling IBE and restricting management access.
read more →

Critical FortiMail Zero-Day Allows Remote Code Execution

🚨 Fortinet warns of a critical FortiMail vulnerability (CVE-2026-104286) actively exploited in zero-day attacks that can allow unauthenticated attackers to write arbitrary files and execute code via crafted HTTP/HTTPS requests. The flaw affects multiple FortiMail 7.x and 8.0 releases; Fortinet identified the issue internally and provided temporary workarounds while patches are prepared. Admins are urged to disable IBE support or block management access from the Internet and to check published IOCs and logs for signs of compromise.
read more →

Critical Zero-Day in Cisco Catalyst SD‑WAN Manager

🔒 Cisco has released an urgent advisory for CVE-2026-76504, a critical (CVSS 9.8) authentication bypass in Cisco Catalyst SD-WAN Manager that is being actively exploited. The flaw stems from improper URI encoding handling in API session authentication, allowing unauthenticated remote attackers to gain admin-level access. Cisco and CISA urge immediate upgrades to fixed releases; no practical workaround exists, and cloud-hosted mitigations have been deployed but require customer validation.
read more →

Amazon Corretto 8 September 2026 Patch Release

🛡️ Amazon announced the Corretto 8u504 LTS update on September 30, 2026, a no-cost, production-ready OpenJDK distribution. This patch delivers tzdata 2026d timezone updates and is available for download alongside other Corretto LTS builds. Users can obtain updates via Corretto Apt, Yum, or Apk repositories on Linux systems. Feedback is invited.
read more →

Kiteworks fixes max-severity EPG code-injection flaw

🔒 Kiteworks released security updates addressing 126 vulnerabilities across its platform, including a max-severity code-injection flaw in the Email Protection Gateway (EPG). The issue, tracked as CVE-2026-54154, was reported via the YesWeHack bug bounty program and allowed unauthenticated remote code execution through a chain of path traversal, code injection, and missing authentication. The EPG flaw affects versions prior to 9.4.1 and is patched in 9.4.1 or later, while additional critical issues in Core and EPG were also fixed.
read more →

Cisco SD‑WAN Manager zero‑day allows admin access

🔒 Cisco fixed a critical flaw in Cisco Catalyst SD‑WAN Manager that let attackers bypass authentication via improperly handled URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504 with a 9.8 CVSS score, could grant administrative API privileges without credentials. Cisco has patched cloud-managed systems and released fixes for affected on‑prem releases; there is no workaround, so restricting access until upgrades are applied is advised.
read more →

CISA Adds Critical Cisco SD‑WAN Manager Flaw to KEV

🔒 CISA has added a critical authentication bypass vulnerability in Cisco Catalyst SD‑WAN Manager (CVE-2026-76504, CVSS 9.8) to its Known Exploited Vulnerabilities list after reports of active exploitation. The flaw allows an unauthenticated, remote attacker to gain admin privileges by abusing improper URI handling in HTTP requests. Cisco provided IoCs and log entries to audit, and FCEB agencies must apply fixes by October 3, 2026. Organizations are urged to upgrade to fixed releases and hunt for POST requests to URL-encoded variants of "/j_security_check".
read more →

Proof‑of‑Concept for Apple CoreGraphics Flaw Published

🛡️ Researchers published a public proof‑of‑concept for CVE‑2026‑86950, an Apple CoreGraphics vulnerability Apple says may have been used in targeted attacks. The trigger is a malicious PDF with a crafted embedded font that causes a crash on unpatched iPhones and Macs, though the published code demonstrates a crash, not full code execution. Apple patched the flaw on September 28 after crediting Meta Product Security, and CISA added it to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 2.
read more →

CISA warns of critical pre-auth RCE in RouterOS

🔒 CISA has issued an alert about a critical pre-authentication vulnerability (CVE-2026-84411) in MikroTik RouterOS that can lead to remote code execution or denial of service. The flaw is an integer underflow in the web-management HTTP request handling and can be triggered by a single crafted request to achieve root-level code execution. Affected RouterOS releases are reported to be below 7.24, and MikroTik recommends updating to 7.23 or later; the vendor has not yet published its own advisory.
read more →

Critical Cisco SD‑WAN Manager Zero‑Day Alert

🛡️ Cisco warned on September 30 that attackers are actively exploiting a critical zero‑day, CVE‑2026‑76504, in Catalyst SD‑WAN Manager that allows unauthenticated API access as the admin user. The flaw, tied to mishandled URI encoding in session login requests, scored 9.8/10 and has fixed releases available across affected release trains. Cisco confirmed active exploitation and advised upgrades; no workaround exists and internet‑exposed Managers are at highest risk.
read more →

Cisco warns of SD‑WAN authentication bypass zero‑day

🔒 Cisco released updates to address a critical zero-day in the Catalyst SD-WAN Manager (CVE-2026-76504) that is being actively exploited to gain admin privileges. The flaw affects API session-based authentication and allows unauthenticated remote access by bypassing an authentication rule via improper URI encoding. Cisco published IOCs and log locations for detection and urged customers to upgrade to fixed releases or open TAC cases for investigation. Multiple fixed releases are listed for affected versions.
read more →

Unsloth Studio model loader allowed remote code execution

🛡️ Pillar Security found that selecting a model in Unsloth Studio caused the application to download and execute Python code from model repositories. The issue arose because Unsloth enabled Hugging Face's trust_remote_code automatically during routine model checks, running code just by reading a model's config.json. Unsloth patched the behavior in version 2026.6.9 and users are urged to upgrade and audit uses of trust_remote_code.
read more →

TeamViewer urges immediate patch for severe flaws

🔒 TeamViewer has issued an urgent advisory urging customers to update immediately after disclosing multiple high-severity vulnerabilities in its Full Client and Host software for Windows, macOS, and Linux. The most critical issue is a remote session access control bypass (CVE-2026-92370) that could allow unauthorized remote actions leading to remote code execution. Four other flaws include path traversal, heap overflow, TOCTOU race condition, and improper path validation, which can enable local or remote code execution and privilege escalation. TeamViewer recommends upgrading to version 15.82, noting no evidence of public exploits or active in-the-wild abuse so far.
read more →

Apple issues CoreGraphics zero-day patch

🔒 Apple has released a security update addressing CVE-2026-86950, a zero-day in the CoreGraphics rendering framework that Meta Product Security reported. The company said processing a maliciously crafted file could allow arbitrary code execution and that the flaw may have been exploited in an “extremely sophisticated” attack targeting specific individuals. Affected devices include recent iPhones, various iPad models and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple fixed the issue in iOS 26.7.1, iPadOS 26.7.1 and the noted macOS builds.
read more →

OpenSSL fixes high-severity DTLS memory leak bug

🔒 OpenSSL released fixes on September 29 for a High-severity DTLS vulnerability (CVE-2026-84782) that can leak heap memory or crash applications when a DTLS handshake resend occurs while a larger message is partially sent. The bug affects multiple branches and is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while fixes for older branches are available only to premium support customers. Vendors including Ubuntu and Debian have issued package updates; Ubuntu users must reboot after updating.
read more →

New Spectre v2 Variant Leaks Linux Root Hash

🛡️ Researchers disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that can recover root password hashes from Intel-based Linux systems within minutes by exploiting stale branch predictor information after just-in-time (JIT) code reuse. The attack manipulates leftover predictions to trigger transient execution of attacker-controlled instructions, producing cache traces that reveal memory contents. VUSec and Scuola Superiore Sant'Anna reported practical exploits against Linux cBPF and evaluated exposure in SpiderMonkey and GraalVM, leading to CVE-2026-64507 and CVE-2026-64508 and kernel fixes.
read more →