< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 21 of 125

Zoom warns of critical Windows account takeover flaw

🛡️ Zoom has disclosed a critical vulnerability in its Windows desktop client and Meeting SDK that could allow an unauthenticated attacker to hijack accounts. Tracked as CVE-2026-53412 with a 9.8 severity score, the flaw affects several Windows releases including Zoom Workplace and VDI clients prior to the listed patched versions. The vendor described the issue as an improper input validation vulnerability and urged users to apply the latest updates to mitigate risk.
read more →

Microsoft July 2026 Patch Tuesday: 570+ Vulnerabilities

🔒 July’s Patch Tuesday from Microsoft addressed an unprecedented number of vulnerabilities, with reports of 570–622 CVEs (620 if platform-level fixes are counted), plus hundreds in Chromium. The release includes many high-severity flaws — notably elevation of privilege and remote code execution bugs — with only three zero-days and 59 critical issues. Microsoft’s new summary-style advisories and its AI-powered MDASH scanning explain the surge, forcing organizations to reassess patch management and prioritization.
read more →

Microsoft‑signed UEFI shims allow Secure Boot bypass

🛡️ ESET found 11 Microsoft-signed UEFI shim bootloaders (version 0.9 or earlier) contain vulnerabilities that enable Secure Boot bypass across many systems. These shims trust outdated second-stage loaders like older GRUB 2 builds, allowing unsigned kernels or bootkits to load even with Secure Boot enabled. Microsoft issued dbx revocations on June 9; Windows will update automatically and Linux users should fetch revocations via the Linux Vendor Firmware Service. ESET cautions defenders to follow protection guidance rather than rely on IoCs.
read more →

Mozilla, Google, Adobe and VMware issue critical patches

🛡️ Mozilla, Google, Adobe and VMware released updates addressing multiple critical vulnerabilities across Firefox, Chrome, Adobe products, and VMware Avi Load Balancer. Mozilla patched two critical Firefox bugs (CVE-2026-15718, CVE-2026-15719) with exploit code publicly disclosed and fixed in Firefox 152.0.6. Google fixed 15 Chrome vulnerabilities including two critical Ozone use-after-free flaws, and Adobe addressed 88 issues across ColdFusion, Commerce, Experience Manager, and Illustrator. Broadcom remediated a critical authentication bypass in VMware Avi Load Balancer (CVE-2026-47865). Organizations are advised to apply updates promptly to mitigate risk.
read more →

New Windows Bind Link techniques can evade EDR

🛡️ Bitdefender researchers disclosed three techniques abusing Windows Bind Links — File-Binding, Process-Binding, and Silo-Binding — that let attackers with admin rights redirect file paths in memory so security tools see benign files while malicious payloads run. The methods exploit the bindflt.sys driver and can blind EDRs and bypass defenses like AMSI and AppLocker, though Microsoft assessed the issues as low severity because admin privileges are required.
read more →

New Claude for Chrome bugs let extensions abuse privileges

🔒 Researchers at Manifold Security found two vulnerabilities in Anthropic’s Claude for Chrome extension that let a malicious extension trigger privileged AI actions, including reading Gmail, Google Docs, and Calendar data. The flaws are reproducible in version 1.0.80 and persist eight releases after initial reporting. One issue allows synthetic clicks to bypass user verification due to missing event.isTrusted checks; the other places the extension into an elevated mode via a URL parameter. Manifold urges fixes to validate genuine user interactions and to avoid URL-driven privilege transitions.
read more →

Progress restores ShareFile after security suspension

🔒 Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension following the detection of a credible external security threat on July 10. The incident involved exploitation of a high-severity path traversal vulnerability in Storage Zones Controller versions 5.x and 6.x, and patched releases 5.12.5 and 6.0.2 have been issued. Progress reported no evidence of unauthorized access and is withholding the CVE to allow customers time to patch.
read more →

Cursor flaw allows repo-root binaries to run

🛡️ Open a repository in Cursor on Windows and, if a file named git.exe is in the project root, Cursor runs it automatically without prompt. Whatever that binary does executes as the logged-in user and Cursor repeatedly spawns it while the project remains open. Mindgard reported the issue in December 2025, published full details seven months later, and no patch or Cursor advisory had been issued as of July 15, 2026.
read more →

CISA warns: patch actively exploited SharePoint flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) in Internet-exposed on-premises instances. The flaws enable authentication bypass, remote code execution, and post-exploitation activity including theft of IIS machine keys and persistence to deploy malware. CISA urged administrators to apply Microsoft's patches, verify installation, shorten patch cycles, enable AMSI integration for SharePoint, use Microsoft Defender Antivirus detections, and implement hardening and monitoring measures.
read more →

Microsoft issues unprecedented July Patch Tuesday updates

🛡️ Microsoft released updates for 570 CVEs on the July 14 Patch Tuesday, prompted by its use of agentic AI to discover flaws. The update batch includes three zero-days (two exploited in the wild) and a large number of elevation-of-privilege, remote code execution and information disclosure bugs. Experts warn this surge is becoming the new normal and urge organizations to adopt risk-based patching, attack-surface reduction and scalable processes.
read more →

Microsoft blocks update for Dell devices after shutdowns

🛠️ Microsoft is blocking the June Windows 11 update on some Dell systems after the KB5095093 preview update introduced an incompatibility with the Intel Innovation Platform Framework Processor Participant driver. Affected devices may show a yellow exclamation in Device Manager and experience unexpected shutdowns, poor performance, overheating, and battery drain. Microsoft is working with Dell and will pause KB5101650 distribution until a fix is released in the coming days.
read more →

SonicWall SMA 1000 Zero‑Days Prompt Urgent Patches

🛡️ SonicWall warned of active exploitation of two zero‑day vulnerabilities affecting Secure Mobile Access (SMA) 1000 series appliances, including an SSRF that scores 10.0 and a post‑auth code injection allowing command execution. Patches are available in platform hotfix builds 12.4.3‑03453, 12.5.0‑02835 and later; customers are urged to apply fixes and perform forensic checks for specific IoCs. CISA added both flaws to its KEV catalog and set a July 17, 2026 deadline for federal agencies.
read more →

Microsoft Patch Tuesday Hits Record Volume of Vulnerabilities

🔒 Microsoft’s July Patch Tuesday delivered an unprecedented volume of fixes, with 569 CVEs addressed and 59 rated critical, prompting vendors to urge accelerated patching. The release included three notable zero-days — two actively exploited elevation-of-privilege flaws in AD FS and SharePoint, plus a publicly disclosed BitLocker bypass — and several high-severity issues across Windows, Office, and Defender. SAP also issued 20 updates, including a 9.9 CVSS memory corruption bug in NetWeaver ABAP that can permit data access or system disruption.
read more →

SonicWall SMA1000 Zero-Day Flaws Prompt Urgent Patch

🛡️ SonicWall warns customers that two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited and urges immediate installation of hotfixes. CVE-2026-15409 is a critical SSRF (CVSS 10.0) in the Appliance Work Place interface allowing unauthenticated requests, while CVE-2026-15410 is a high-severity post-authentication code injection (CVSS 7.2) enabling OS command execution. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 and later; SonicWall provided IOCs and recommends re-imaging compromised devices.
read more →

Microsoft July 2026 Patch Tuesday: 622 Flaws Released

🛡️ Microsoft released its July 2026 security updates addressing 622 vulnerabilities across many products, including 57 marked critical. Two flaws have confirmed in-the-wild exploitation: an AD FS elevation of privilege (CVE-2026-56155) and a SharePoint spoofing/authentication issue (CVE-2026-56164). Talos highlights multiple critical remote-code-execution and elevation-of-privilege flaws affecting Windows components, Office, SharePoint, SQL Server, Defender, Copilot and cloud services. Cisco Talos also published Snort rules and urged customers to update intrusion-detection rule sets to detect exploitation attempts.
read more →

Microsoft ships record July Patch Tuesday fixes

🔒 Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs including two actively exploited elevation-of-privilege flaws in on‑premises SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint bug allows unauthenticated network privilege escalation and is tied to incident responders at Mandiant and Google's FLARE; admins should patch immediately and consider enabling AMSI Full Mode. The AD FS bug permits local privilege escalation for authenticated users and was credited to Microsoft DART. A third disclosed BitLocker bypass (CVE-2026-50661) requires physical access and is lower priority. The update also finalizes Kerberos RC4 hardening, risking authentication breaks for service accounts still using RC4 unless audited and rotated first. Microsoft says AI tooling increased bug discovery, and the scale of fixes means organizations should prioritize by exploitation status rather than CVSS score.
read more →

Microsoft issues record July security update batch

🔒 Microsoft released updates addressing a record 570 security vulnerabilities in July’s Patch Tuesday, attributing the surge to AI-assisted discovery. Nearly 60 of the flaws are rated critical, and three are confirmed zero-days already exploited in the wild. The fixes include numerous elevation-of-privilege bugs and a BitLocker security bypass; vendors warn that AI speeds both discovery and exploit development.
read more →

Microsoft issues Windows 10 KB5099539 security update

🔒 Microsoft released the Windows 10 KB5099539 extended security update, delivering the July 2026 Patch Tuesday fixes and additional security and reliability improvements for enrolled devices and LTSC editions. The update moves Windows 10 to build 19045.7548 (19044.7548 for Enterprise LTSC 2021) and addresses a record 570 vulnerabilities, including two exploited and one publicly disclosed zero-day. Administrators and eligible consumers can install it via Settings > Windows Update; several known issues and hardening changes are documented.
read more →

SAP July 2026 fixes critical NetWeaver ABAP flaw

🔒 SAP released its July 2026 security updates to remediate multiple serious vulnerabilities, including a critical NetWeaver Application Server ABAP out-of-bounds write (CVE-2026-44747). Vendors and customers are urged to apply the ABAP Kernel patch because the suggested workaround—disabling specific ICF nodes via SICF—may break SAP GUI for HTML. Other addressed issues include an HTTP request/response smuggling bug in Approuter (CVE-2026-27690) and a default-credential OAuth client issue in Commerce Cloud (CVE-2026-44761). SAP notes no evidence of active exploitation but recommends immediate patching and auditing of production instances for sample OAuth clients.
read more →

Windows 11 July 2026 Cumulative Updates Released

🛈 Microsoft released Windows 11 cumulative updates KB5101650 and KB5099414 for 25H2/24H2 and 23H2 to deliver July 2026 Patch Tuesday fixes addressing security vulnerabilities, bug fixes, and feature refinements. The rollouts update build numbers and include notable Bluetooth pairing improvements, a quieter Widgets experience, enhanced accessibility controls, File Explorer and networking fixes, and Point-in-Time restore availability. Install via Settings > Windows Update or the Microsoft Update Catalog.
read more →