< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch

2273 articles · page 2 of 114

CoSnitch flaws let Copilot execute prompts and exfiltrate

🛡️ Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to run prompts and pull data from connected apps within a victim's authenticated session. The issues — collectively named CoSnitch and tracked as CVE-2026-24301 — rely on an undocumented URL parameter pairing (autorun=1 and q) to trigger automatic prompt execution and data exfiltration. Microsoft received the report in December 2025 and shipped patches on August 18, 2026.
read more →

Hunting MacSync Stealer via behavioral pivots

🔍 Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
read more →

Critical AIT‑GUI Flaw Allows Remote Command Execution

🔒 A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more →

CISA Adds Actively Exploited Critical Ray Flaw

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more →

Critical GitLab GraphQL Flaw Allows Remote Project Changes

🔒 GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more →

Critical Forminator flaw lets attackers execute code

🛡️ A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin — used on 600,000+ sites — allows unauthenticated attackers to upload arbitrary files, including executable PHP, and achieve remote code execution. The flaw, present in versions up to 1.56.1, stems from improper file type validation in the handle_file_upload() function and misuse of MIME key matching combined with a public submission handler. Patch 1.56.2, released on July 31, 2026, fixes the issue; site owners should update immediately.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Critical WordPress plugin flaw exposes admin accounts

🔒 More than 40,000 WordPress sites were exposed by an authentication bypass in the User Profile Builder plugin. Tracked as CVE-2026-15826 with a 9.8 CVSS score, versions up to 3.16.4 are affected. Wordfence identified a type confusion in the registration/auto-login flow that can convert a failed registration into user ID 1, enabling generation of an admin authentication token. The vendor released version 3.16.5 on July 16; site owners should update immediately.
read more →

Unisoc modem exploit chain risks Android kernel

🔒 SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more →

Microsoft works on patch for Defender ShieldBreak zero-day

🛡️ Microsoft confirmed it is developing a security update to address a new Microsoft Defender zero-day called "ShieldBreak," disclosed by researcher "Nightmare Eclipse" after the August 2026 Patch Tuesday. The PoC reportedly allows local attackers with limited permissions to escalate to SYSTEM on patched Windows 10, Windows 11, and Windows Server, and has been tracked as CVE-2026-69414. Microsoft stated it is investigating and will provide a quality security update, while the researcher publicly disclosed the exploit amid a dispute over disclosure and bounties.
read more →

Critical SAP Commerce Cloud RCE Vulnerability Alert

🔔 SAP Commerce Cloud is affected by a maximum-severity vulnerability, CVE-2026-58231, rated 10.0 for insufficient authorization and input validation. An unauthenticated attacker can abuse a default authentication client to send crafted input and trigger arbitrary code execution, risking confidentiality, integrity, and availability. Vendors urge immediate patching and recommend IP filter sets as a temporary mitigation.
read more →

Critical SAP Commerce Cloud RCE Now Being Exploited

🛡️ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more →

Critical GeoServer SQL Injection Now Patched

🛡️ A critical SQL injection zero-day in GeoServer was disclosed on August 12, 2026, and saw active exploitation attempts within hours, according to watchTowr. The flaw, tied to the jsonArrayContains function in PostGIS DataStore, could lead to remote code execution under certain configurations and remained initially unpatched. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to remediate the issue, which carries a CVSS score of 9.8.
read more →

Microsoft patches LegacyHive Windows zero‑day

🛡️ Microsoft released patches addressing the Windows zero-day dubbed LegacyHive, disclosed after July 2026 Patch Tuesday. The flaw was revealed by a researcher using the "Nightmare Eclipse" handle, who published a proof-of-concept after the updates; the exploit requires additional credentials, limiting easy weaponization. Microsoft tracked the issue as CVE-2026-62832 and describes the bug as improper link resolution in the Windows User Profile Service that can allow local privilege escalation. ACROS Security also issued unofficial mitigations prior to Microsoft's August fixes.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Researcher posts Defender patch bypass PoC

🛡️ A researcher known as Nightmare Eclipse published a proof-of-concept called ShieldBreak that appears to bypass Microsoft’s recent patch for CVE-2026-50656, enabling attackers with any initial access to escalate to system-level privileges. Security experts warn the PoC could erode trust in patches and stress defense-in-depth measures such as application allowlisting, tightened admin rights, and hunting for MsMpEng.exe spawning system shells. Independent confirmations and community detections are emerging, though Microsoft has not yet provided a formal response.
read more →

Adobe Commerce flaw exploited to hijack customer accounts

🔒 Adobe patched a critical incorrect-authorization vulnerability (CVE-2026-71362) in its Commerce and Magento platforms after researchers observed exploitation attempts that can let attackers switch customer sessions and access private data. Sansec's Shield WAF reportedly blocked attacks and found the flaw required no account, admin rights, or user interaction. Administrators are urged to apply the August 2026 isolated patches after ensuring the correct -p release is installed.
read more →

PoC for SharePoint JWT Bypass Now Used in Attacks

🔒 A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more →

Researchers disclose cross‑session AI reasoning leak

🔒 A new research paper shows a flaw in how OpenAI, Anthropic, and Google carry encrypted reasoning between API calls, enabling recovery of hidden internal reasoning and secrets from session logs. The team demonstrated replay and decoding attacks that recovered API keys, passwords, and other private artifacts from publicly available agent traces. Vendors implemented mitigations and the authors say the main extraction no longer reproduces as of August 2026, but developers are urged to strip opaque reasoning blocks from shared logs.
read more →

Adobe issues urgent patches for critical ColdFusion flaws

🔒 Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more →