< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 20 of 125

Microsoft issues emergency fix for Dell shutdown bug

🛠️ Microsoft released out-of-band updates to address a compatibility issue that caused some Dell PCs to shut down or suffer performance and power problems after July 2026 Windows 11 updates. The bug stems from a June preview change to the Windows USB-C Connection Manager that conflicts with the Intel Innovation Platform Framework (IPF) Processor Participant driver, producing a yellow exclamation in Device Manager. Microsoft blocked the July update on affected systems and on Saturday shipped emergency updates KB5121767 and KB5121768 for Windows 11 25H2, 24H2 and Enterprise LTSC 2024 to resolve the issue. Managed devices with Autopatch will get the fix automatically, while Intune admins can accelerate deployment; affected users should restart after installation.
read more →

7‑Zip XZ Vulnerability Fixed in 26.02 Update

🛡️ 7‑Zip 26.02 fixes CVE-2026-14266, a heap-based buffer overflow in its XZ decoder that can lead to code execution when a crafted XZ archive is opened. ZDI disclosed the flaw on July 15 after it was reported June 5; the patch shipped June 25. Exploitation requires the victim to open a malicious file, and on Windows the code runs with 7‑Zip's process token, not elevated privileges. Users should manually update to 26.02 or later, and vendors bundling 7‑Zip must issue their own fixes.
read more →

Critical nginx heap overflow allows remote crashes

🛡️ F5 released patches for a critical nginx heap buffer overflow (CVE-2026-42533) that can crash or restart worker processes and, in some environments, enable remote code execution. Fixed versions are nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1; systems on earlier releases should upgrade. The flaw occurs in the nginx script engine when a regex-based map's output variable is used in a string expression after an earlier regex capture, causing a two-pass evaluation mismatch that leads to overruns. F5 scores the flaw 9.2 (CVSS v4) and notes exposure depends on configuration rather than version alone.
read more →

7‑Zip patch fixes XZ decompression RCE risk

🛡️ 7‑Zip 26.02 addresses a remote code execution vulnerability in XZ decompression that could allow attackers to run arbitrary code when users open specially crafted archives. The flaw, reported by researcher Landon Peng and noted by the Zero Day Initiative, appears to stem from insufficient checks on available output buffer space during XZ decompression. The update adds bounds checks to prevent heap-based buffer overflow. Users must update manually from 7-zip.org because the application lacks automatic updates.
read more →

Critical wp2shell RCE in WordPress core requires patch

🔒 Public proof-of-concept exploits have been released for the critical "wp2shell" pre-authentication remote code execution chain affecting WordPress Core. The attack combines two flaws, CVE-2026-63030 and CVE-2026-60137, impacting WordPress 6.9.x and 7.0.x, prompting forced auto-updates to versions 6.9.5 and 7.0.2. Administrators are urged to patch immediately or apply temporary WAF/REST API mitigations while updates are applied.
read more →

Gemini lock-screen flaw lets messages be sent

🔒 Google is fixing a vulnerability that lets an attacker with physical access to a locked Android 16 device use Gemini to send SMS and WhatsApp messages without entering a PIN. Reports since May show the bypass exploits Gemini's Deep Research and a specific multi-touch gesture to circumvent authentication. Google says a patch is imminent; meanwhile, users should restrict Gemini's lock-screen access to limit exposure.
read more →

Critical WordPress core flaw enables anonymous RCE

🔒 WordPress patches a critical pre-auth remote code execution (RCE) in core that an anonymous HTTP request could exploit on default installs. Researcher Adam Kues of Assetnote reported the issue as wp2shell, and WordPress released versions 6.9.5 and 7.0.2 on July 17, 2026, to remediate affected 6.9.x and 7.0.x releases. Owners should verify their exact version and apply updates; Searchlight offers a checker and temporary mitigations for the REST batch endpoint.
read more →

OpenSSL HollowByte memory-exhaustion flaw analysis

🛡️ OpenSSL received a silent June fix for a denial-of-service issue Okta branded "HollowByte," which causes servers to allocate up to 131 KB per TLS ClientHello before the body arrives. The bug lets attackers exhaust connections and, on glibc systems, fragment the heap so freed memory remains resident until process restart. Fixed releases are 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 dated June 9, but OpenSSL chose to treat the change as a "bug or hardening" without a CVE, advisory, or changelog note.
read more →

HollowByte DoS in OpenSSL bloats server memory

🛡️ Okta researchers disclosed a DoS flaw named HollowByte that lets unauthenticated attackers bloat OpenSSL server memory by sending an 11-byte payload with a forged header. Vulnerable OpenSSL versions allocate memory based on the claimed message length before receiving the payload, then block waiting for data that never arrives, causing heavy heap fragmentation and long-lived RSS growth. The OpenSSL team silently fixed the issue and backported the patch to multiple release lines; administrators are urged to upgrade to the patched versions immediately.
read more →

New LegacyHive Windows zero-day enables privilege escalation

🔒 A researcher known as Nightmare Eclipse published a proof-of-concept named LegacyHive after Microsoft's July 2026 Patch Tuesday, claiming it exploits a vulnerability in the Windows User Profile Service. The PoC has been intentionally modified to require additional credentials, making exploitation harder than earlier releases. Analysts note successful exploitation allows non-admin users to modify the classes registry hive and achieve code execution on admin login. Detection queries for Microsoft Defender for Endpoint were published shortly after.
read more →

Chained Zero-Day Flaws in Siemens ROX II Switches

🛡️ This Unit 42 advisory, developed in partnership with Siemens, describes a chained exploit of three zero-day vulnerabilities in Siemens ROX II OT switches. The chain (CVE-2025-40948, CVE-2025-40947, CVE-2025-40949) enables arbitrary file disclosure, root privilege escalation and persistent root execution, risking full device compromise. Siemens has issued advisories and a firmware update V2.17.1; Palo Alto Networks provides virtual patching and OT device protections.
read more →

CISA urges immediate patching of Fortinet FortiSandbox

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by July 19. Both flaws are OS command injection bugs with CVSS scores of 9.1 and have documented in-the-wild exploitation. Fortinet released fixes in FortiSandbox versions 4.4.9 and 5.0.6; CISA advised discontinuing cloud services where mitigations are unavailable.
read more →

CISA orders urgent FortiSandbox patches for agencies

🔒 CISA has ordered U.S. federal agencies to urgently patch two actively exploited critical vulnerabilities in the Fortinet FortiSandbox platform. The flaws (CVE-2026-39808 and CVE-2026-25089) were fixed by Fortinet in April and June, and allow unauthenticated remote command injection with low complexity. Defused and CISA confirmed in-the-wild exploitation, and agencies must remediate by Sunday, July 19. Administrators are advised to upgrade affected deployments to the latest released versions to block attacks.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

Claude Chrome extension flaw lets malicious extensions act

🛡️ A vulnerability in Anthropic's Claude for Chrome extension can let a malicious extension simulate clicks to trigger nine predefined AI workflows. The issue, found by Ax Sharma of Manifold Security, stems from the extension failing to verify the browser's Event.isTrusted flag before executing tasks tied to page click handlers. A malicious extension with permissions on claude.ai could inject elements and fire synthetic clicks to abuse Claude's authenticated access to services like Gmail, Docs, Calendar, and Salesforce. Anthropic acknowledged the report and classified a related skipPermissions parameter as informational.
read more →

Zoom fixes critical account-takeover vulnerability

🔒 Zoom disclosed and patched a critical vulnerability that could allow an unauthenticated attacker to perform an account takeover via network access, affecting several Windows clients and VDI branches. The company also fixed three privilege-escalation bugs across Zoom Workplace, Zoom Rooms, and related VDI plugins. Security experts warned the flaw is highly dangerous due to low complexity and no user interaction required, while praising Zoom for discovering and patching the issues.
read more →

n8n token-exchange identity binding flaw fixed

🔒 n8n's Enterprise token-exchange feature matched incoming JWTs to local users using only the sub claim and ignored the iss value, allowing a valid token from one issuer to authenticate as a user belonging to another issuer. The bug (CVE-2026-59208) was fixed on June 24 and credited to GitHub user bearsyankees. It only affects Enterprise instances with token exchange enabled and trusting multiple issuers; the recommended mitigations are upgrade to 2.27.4/2.28.1+ or restrict trusted issuers.
read more →

CISA urges immediate SharePoint hardening now

🔒 CISA has warned that three Microsoft SharePoint vulnerabilities are being actively exploited and urged organizations to immediately patch on-premises SharePoint deployments. Administrators should follow Microsoft’s mitigation guidance, enable AMSI integration, hunt for indicators of compromise, and rotate machine keys where appropriate. The agency added CVE-2026-33201, CVE-2026-45659, and the newly listed CVE-2026-56164 to its Known Exploited Vulnerabilities catalog and required rapid remediation for federal agencies.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft announced that Windows 11 version 24H2 Home and Pro editions and Windows 10 Enterprise LTSB 2016 will stop receiving monthly updates after October 13, 2026. Enterprise and Education editions remain supported until October 12, 2027. Users are advised to upgrade to Windows 11 25H2, which is available via an enablement package and will be offered automatically to unmanaged Home and Pro devices. Devices can defer the update or choose restart timing through Settings > Windows Update.
read more →

Zoom issues urgent Windows security updates

🔒 Zoom released updates to patch a critical account-takeover vulnerability affecting several Windows clients and SDKs. The flaw, tracked as CVE-2026-53412 (CVSS 9.8), impacts Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows and could allow unauthenticated remote takeover. The advisory also fixes three high-severity escalation-of-privilege and TOCTOU bugs in various Workplace, VDI, plugin, Rooms, and Remote Control components; no active exploitation has been reported.
read more →