< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch

2273 articles · page 3 of 114

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

Cisco ASA and FTD HTTP DoS Flaw Exploited

🛡️ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

Zoom patches zero-click RCE and VDI disclosure flaws

🛡️ Zoom has patched four vulnerabilities across its applications, including two zero-click remote code execution issues that allow a meeting participant to execute malicious code on other attendees' systems without any interaction. Three client vulnerabilities affect Zoom versions before 7.1.5 and 7.0.6 and stem from memory corruption in the text annotation feature; a fourth path traversal flaw impacts Zoom Workplace VDI Client and plugins before 7.0.11 and 6.6.15. The annotation bugs were found by A Security using an AI agent, which built a working exploit in under 24 hours, and Zoom has provided mitigations including server-side filtering and guidance to restrict optional features and enforce client version minimums.
read more →

Microsoft Patch Tuesday — August 2026 Update Summary

🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →

Microsoft patches 398 vulnerabilities, including active zero-day

🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
read more →

Cisco warns of ASA and FTD VPN flaw causing DoS

🔒 Cisco warns of a high-severity DoS vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and Threat Defense (FTD) devices when certain remote access services are enabled. The flaw stems from insufficient error checking in HTTP request processing and can be exploited remotely without authentication to crash affected devices. Cisco has released hotfixes for multiple ASA and FTD releases and urges customers to upgrade, noting no available workarounds. The company reports active exploitation since August 2026 but has not shared exploit details or indicators of compromise.
read more →

Zoom annotation flaws allowed zero-click takeover

🛡️ Researchers found that Zoom's annotation feature could enable zero-click remote code execution between meeting participants. The flaws affected multiple Zoom clients and SDKs and were patched in June and July, before public disclosure, with no reported exploitation at publication. The bugs involve improper parsing of structured drawing objects, leading to buffer overflows, over-reads, and a use-after-free. Patches and CVE references are included in Zoom advisories.
read more →

Windows 10 KB5120249 August 2026 Patch Update

🛡️ Microsoft released the Windows 10 KB5120249 Extended Security Updates (ESU) for 22H2 and 21H2, delivering the August 2026 Patch Tuesday fixes. The update is mandatory and raises OS Builds to 19045.7663 and 19044.7663. Install via Start > Settings > Update & Security > Windows Update or download from the Microsoft Update Catalog. The patch resolves a File History SMB backup failure and expands rollout of new Secure Boot certificates.
read more →

Windows 11 August 2026 cumulative updates released

🔔 Microsoft released Windows 11 cumulative updates KB512103 and KB5120240 for 25H2/24H2 and 23H2 to address security flaws, fix bugs, and add features. These August 2026 Patch Tuesday updates include fixes for roughly 400 vulnerabilities and are delivered via Windows Update or the Microsoft Update Catalog. Notable additions include improved Windows Search typo handling, Voice Access enhancements, touchpad gestures, and extended Windows Hello ESS support for peripheral fingerprint sensors.
read more →

AI-assisted exploit lets attackers assume SharePoint users

🔒 Security researchers discovered an unauthenticated bypass in Microsoft SharePoint allowing an attacker to impersonate any user, including administrators. The flaw, CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not listed. Rapid7 chained the bypass to an RCE, CVE-2026-63520, to run code as the Windows service account, and published analysis and a proof-of-concept. Organizations should ensure the July update is applied and watch for August patches.
read more →

Cursor command-line agent pre-trust command execution

🔒 A flaw in Cursor's command-line coding agent allowed cloned repositories to run arbitrary commands on a developer's machine before the user was prompted to trust the repo, and could execute outside the sandbox even when sandboxing was enabled. Manifold Security reported the issue on July 20 and published findings on August 10; Cursor shipped a fix for the pre-trust behavior three days after the report but closed the submission as informative and issued no advisory. The vulnerability involved the agent's worktree setup reading a tracked config file and piping it directly to a shell without parsing or allowlisting, and the sandbox policy was hardcoded off on that path. Developers should update to build 2026.07.23-e383d2b or later or skip worktree setup to close the pre-trust window, though Manifold says the sandbox gap remains.
read more →

Mozilla rotates GPG signing key after accidental exposure

🔐 Mozilla updated the GPG subkey used to sign Firefox and Thunderbird artifacts after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. The organization says the exposure risk is low because repository access was limited and its audit found no evidence of unauthorized access. Mozilla revoked the old key, published the new public key and revocation, and provided instructions for users who manually verify signatures or use RPM-based Linux distributions.
read more →

CISA: SharePoint RCE Flaw Now Used in Ransomware

🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
read more →

Malicious SIMs can remotely commandeer cellular modules

🔒 Researchers from the University of Birmingham and Fuzzware demonstrate that a hostile SIM card can use the SIM's standard proactive commands (RUN AT) to instruct modems to execute AT commands, enabling code execution on affected devices. They tested 26 devices and found nine accepted the command, including several Quectel modules in EV chargers, industrial routers, and car telematics units. Vendors including Qualcomm and Quectel have responses in progress, but no public advisories have been broadly published.
read more →

Mozilla revokes Linux signing subkey after exposure

🔐 Mozilla revoked the OpenPGP subkey used to sign Firefox and Thunderbird Linux downloads after an unencrypted copy was mistakenly committed to a private repository. The revocation means files signed by the old subkey will stop verifying once users import the revocation; most users are unaffected, but manual verifiers and some RPM-based installs must update keys. A new replacement subkey was published with a 2028 expiry, and Mozilla says audit logs show no evidence of external access despite the revocation reason code indicating compromise.
read more →

Cisco warns of high-severity ClamAV flaws with PoC exploits

🔒 Cisco alerted customers to two high-severity vulnerabilities in the ClamAV ZIP archive parser used by its Secure Endpoint Connector, tracked as CVE-2026-20337 and CVE-2026-20338. The flaws, caused by improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, resulting in denial-of-service (DoS). Proof-of-concept exploit code is publicly available, and Cisco plans updates later this month to address the issues across Windows, Linux, and macOS.
read more →

Researchers Weaponize Windows PnP Auto-Install Flaw

🔒 Security researchers demonstrated that Windows Plug and Play auto-install can be abused to fetch signed vendor software for an emulated USB device and escalate to SYSTEM on an updated Windows 11 machine. The technique also works over Remote Desktop when low-level USB or PnP redirection is enabled, though Microsoft notes this is not enabled by default. The researchers presented their findings at DEF CON 34 and provided tooling to emulate devices and chain co-installer behavior to privileged execution.
read more →