< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2494 articles · page 22 of 125

Windows 11 July 2026 Cumulative Updates Released

🛈 Microsoft released Windows 11 cumulative updates KB5101650 and KB5099414 for 25H2/24H2 and 23H2 to deliver July 2026 Patch Tuesday fixes addressing security vulnerabilities, bug fixes, and feature refinements. The rollouts update build numbers and include notable Bluetooth pairing improvements, a quieter Widgets experience, enhanced accessibility controls, File Explorer and networking fixes, and Point-in-Time restore availability. Install via Settings > Windows Update or the Microsoft Update Catalog.
read more →

Claude for Chrome click flaw lets other extensions act

🔒 Manifold Security found that Claude for Chrome still accepts synthetic clicks and can read permission mode from its URL, enabling other extensions with DOM access on claude.ai to trigger nine allowlisted tasks (including Gmail, Google Docs, and Calendar). Anthropic constrained arbitrary prompts after ClaudeBleed, but the click handler lacks an event.isTrusted check and the side panel honors ?skipPermissions=true, creating high-risk scenarios especially if "Act without asking" is enabled. Manifold reported this in May against v1.0.72; the issues remained in v1.0.80 as of July 7 and no patch or public advisory was available by July 14.
read more →

Progress confirms ShareFile zero‑day behind shutdown

🛡️ Progress Software confirmed a high‑severity zero‑day in ShareFile Storage Zone Controller that prompted an emergency shutdown of customer Windows servers. The flaw is a path traversal impacting all 5.x and 6.x releases, allowing an authenticated admin to read arbitrary files, write attacker‑controlled content, or enumerate the filesystem. Progress released patches (5.12.5 and 6.0.2), reserved a CVE to be published in two weeks, and currently reports no evidence of customer data breaches.
read more →

RabbitMQ flaws risk OAuth secret exposure

🔒 Cybersecurity researchers disclosed two access-control flaws in RabbitMQ that could leak OAuth client secrets and allow cross-tenant data access. Miggo's team reported one issue exposes the broker's OAuth secret to unauthenticated requests, enabling full broker takeover, while the other permits authenticated users to read other tenants' queue metadata. Affected releases begin at 3.13.0; fixes are available in recent patch releases and administrators are urged to rotate secrets and restrict management access.
read more →

Cloudflare explains DNSSEC NTA and EDE 33

🛡️ On July 3, 2026, Albania's .AL TLD experienced a failed DNSSEC key rollover that caused widespread validation failures for validating resolvers, including Cloudflare's 1.1.1.1. Cloudflare applied a Negative Trust Anchor (NTA) to restore resolution and for the first time returned a new Extended DNS Error (EDE 33) to signal that DNSSEC validation had been bypassed. The change provides visibility into responses served under an NTA and complements EDE codes like EDE 9 to show the underlying DNSSEC failure.
read more →

Old Microsoft-signed UEFI shims expose Secure Boot

🔒 Researchers found 11 Microsoft-signed UEFI shim bootloaders that can be abused to bypass Secure Boot on many systems, enabling execution of untrusted code during early boot. ESET and CERT/CC detail how outdated shims (mostly v0.9 and earlier) remained trusted because they were not revoked, allowing attackers to deploy UEFI bootkits and persist below the OS. Microsoft revoked affected certificates in June 2026 following disclosures.
read more →

SAP patches critical NetWeaver, Commerce Cloud flaws

🔒 SAP released July 2026 security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The issues include a memory corruption bug in NetWeaver AS ABAP, an HTTP request smuggling flaw in Approuter, and default-credential exposure in Commerce Cloud. SAP also fixed several high- and medium-severity bugs such as RCE, XSS, SQLi, and DLL hijacking.
read more →

FIFA Applications Expose Authorization Flaw

🛡️ The Football Data Platform and Commentator Information System had server-side backends that failed to enforce user authorization, relying instead on client-side UI checks. This omission allowed unauthorized access paths that could be exploited without network-level intrusion. The flaw stems from improper access control design and highlights the risks of trusting client-side validation.
read more →

Old Microsoft‑signed UEFI shims undermine Secure Boot

🔒 ESET researchers found 11 outdated Microsoft-signed UEFI shim bootloaders (version 0.9 and below) that allow bypassing UEFI Secure Boot on systems trusting the Microsoft Corporation UEFI CA 2011 certificate. These shims can execute untrusted code during early boot and enable deployment of malicious UEFI bootkits even when Secure Boot is enabled. Microsoft revoked the affected binaries in the June 9, 2026 dbx update after coordinated disclosure through CERT/CC.
read more →

Governments urge enterprises to improve router security

🔒 A multinational cybersecurity advisory warns that Russian government-sponsored actors are exploiting poorly configured routers and legacy protocols to steal device configurations and credentials. Attackers scan for devices using SNMPv1/v2, default community strings, and vulnerable Cisco features like Smart Install, then exfiltrate config files to attacker-controlled servers. Agencies recommend migrating to SNMPv3, disabling legacy protocols and Cisco Smart Install, enforcing strong passwords and MFA, blocking SNMP at firewalls, updating software, and retiring EOL devices.
read more →

CISA warns of exploited RCE in Joomla extensions

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting arbitrary file upload vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution. The agency designated these flaws as maximum priority and ordered federal agencies to apply updates or mitigations within three days. Vendors released fixes in iCagenda 4.0.8/3.9.15 and Balbooa Forms 2.4.1 after automated and zero-day exploitation was observed. Administrators should check installations and apply the available patches immediately.
read more →

RabbitMQ OAuth secret leak and authorization bypass patched

🔒 RabbitMQ has patched two critical access control flaws that could expose OAuth client secrets and leak queue/exchange metadata. Discovered by Miggo Security, CVE-2026-57219 allowed unauthenticated retrieval of OAuth configuration from an obsolete endpoint, risking full broker takeover; CVE-2026-57221 permitted authorization bypass for passive declarations, enabling reconnaissance. Users should upgrade immediately and rotate secrets.
read more →

Critical Zimbra XSS Flaw Targets Classic Web Client

🛡️ Zimbra has released an urgent update to fix a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could permit arbitrary code execution via specially crafted emails. The vendor says the flaw could expose mailbox data, session information, or account settings if exploited, though no CVE has yet been assigned. Zimbra recommends updating to Zimbra Collaboration Suite version 10.1.19 to mitigate the risk.
read more →

Six U-Boot Vulnerabilities Enable Stealthy Firmware Attacks

🔒 Binarly disclosed six vulnerabilities in the widely used U-Boot bootloader's FIT signature verification that can lead to crashes or arbitrary code execution during device boot. These flaws, present in code dating back to U-Boot 2013.07, potentially affect many releases and vendor forks across BMCs, networking gear, industrial systems, and IoT devices. While patches have been accepted upstream, vendor firmware updates are required to protect devices, and unsupported hardware may remain vulnerable.
read more →

Friday Squid Blogging: Squidbleed Vulnerability

🦑 A decades-old bug in the Squid proxy can leak HTTP request data, a flaw dubbed "Squidbleed." This post mixes a lighthearted squid image with serious security discussion, noting the vulnerability's age and potential impact on privacy. The author also invites readers to discuss other current security news not yet covered.
read more →

Six new U-Boot flaws risk pre-OS code execution

🔒 Researchers at Binarly disclosed six vulnerabilities in U-Boot, the bootloader used across routers, cameras, and server management controllers. Two flaws allow code execution during image parsing before signature verification, while four cause crashes. The bugs trace to unchecked returns from fdt_get_name and other parsing errors; patches were merged but not yet broadly distributed.
read more →

OpenClaw flaws enable host escape and credential theft

🔒 Three critical vulnerabilities in the OpenClaw personal AI assistant could allow credential theft, privilege escalation, and arbitrary host code execution if exploited. The flaws include two command injection bugs (GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm) and a path traversal/link-following issue (GHSA-575v-8hfq-m3mc). OpenClaw 2026.6.6 patches these issues; operators are advised to harden configurations and limit tool/channel allowlists.
read more →

AI agents can enable silent remote code execution

🔒 A new AI Now Institute report demonstrates a proof-of-concept exploit that coerces Anthropic’s Claude Code and OpenAI’s Codex into executing attacker-supplied binaries during automated code review. The attack uses multi-stage prompt injection hidden in repository files (documentation, comments) to trick agents in auto-mode or auto-review into running a seemingly benign script that launches a malicious payload. Researchers warn the architectural risk — agents’ inability to reliably attribute text sources — makes such platforms potential attack vectors when granted shell access and autonomous execution.
read more →

Unpatched XRING bug in XQUIC allows remote crash

🛡️ A single wrong variable in Alibaba's XQUIC library lets any remote client crash servers using default QPACK settings with ordinary HTTP/3 traffic. FoxIO researcher Sébastien Féry disclosed the XRING flaw on July 8 and showed a crash triggered by about 260 bytes of legal QPACK frames. All XQUIC releases through v1.9.4 are affected; no patch or CVE was available as of July 10. Operators can mitigate by setting SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0 or disabling HTTP/3 until a fix ships.
read more →

Zimbra urges urgent patch for Classic Web Client XSS

🔒 Zimbra released version 10.1.19 to address a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that can be triggered via specially crafted emails. The flaw, reported by Google's Threat Analysis Group, allows attackers to execute malicious code when messages are opened and potentially steal session data, account settings, or mailbox contents. Zimbra cautioned customers to upgrade immediately, noting the issue specifically affects Classic Web Client users, while attribution and active exploitation remain under investigation.
read more →