< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 3 of 125

New Spectre‑v2 BTR Variant Targets JIT Engines

🔒 A team from VUSec and Scuola Superiore Sant'Anna has disclosed a new Spectre‑v2 variant called Branch Target Reuse (BTR) that impacts JIT engines in browsers, language runtimes, and the Linux kernel across multiple CPU vendors. Researchers demonstrated exploitation against SpiderMonkey, GraalVM, and cBPF JIT, producing kernel exploits that can recover root password hashes on patched Intel systems. Mitigations have been merged into the Linux kernel under CVE‑2026‑64507 and CVE‑2026‑64508, while vendors pursue code‑cache randomization and site isolation approaches.
read more →

AgentCore SDK flaws allowed sandbox command execution

🔒 Two vulnerabilities in Amazon Bedrock AgentCore's Python SDK could let attackers execute commands inside Code Interpreter sandboxes and access AWS credentials. BeyondTrust detailed that crafted package names and pip extras syntax could bypass validation, tracked as CVE-2026-12530 and CVE-2026-16796. AWS patched the issues in versions 1.6.1 and 1.18.1, and urged upgrades and stricter handling of untrusted package names.
read more →

Apple patches CoreGraphics zero-day exploited in attacks

🛡️ Apple released updates to address a zero-day vulnerability in CoreGraphics tracked as CVE-2026-20700, discovered by Meta Product Security. The flaw is an out-of-bounds write that could allow crashes, data corruption, or arbitrary code execution when processing malicious files. Affected platforms include multiple iPhone, iPad, and Mac models, and fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
read more →

MCP Python SDK flaw risks leaking OAuth credentials

🔒 The official MCP Python SDK had a vulnerability that allowed a malicious MCP server to trick clients into sending OAuth credentials to an attacker-controlled token endpoint. Affected releases exposed the client secret, authorization code, and PKCE proof key; fixes were released in versions 1.30.0 and 2.2.0. The issue impacts clients using specific OAuth providers over HTTP and requires upgrades plus configuration changes to fully mitigate.
read more →

Active exploitation of Citrix NetScaler ADC and Gateway

🛡️ Mandiant and Google Threat Intelligence Group identified active exploitation of a zero-day (CVE-2026-88772) affecting Citrix NetScaler ADC and Gateway appliances starting in early September 2026, with evidence of impact across government, finance, education and professional services in North America and Europe. The campaign bypasses authentication by corrupting the NetScaler Packet Processing Engine (NSPPE) during DTLS handshake parsing, leading to root execution and installation of PHP web shells and a Python tunneler. Observed tooling includes WHIPSHOT (PHP web shell) and SLAPSHOT (Python proxy) that facilitate persistence, internal reconnaissance, and credential theft. Citrix has published updates and guidance; defenders are urged to review vendor guidance and apply patches and containment steps.
read more →

Apple patches CoreGraphics out‑of‑bounds flaw

🔒 Apple released security updates fixing CVE-2026-86950, an out-of-bounds write in the CoreGraphics component that could allow arbitrary code execution when processing a crafted file. The issue was fixed with improved bounds checking and was reported by Meta Product Security. Apple said the flaw may have been exploited in targeted, sophisticated attacks against iOS versions before iOS 27. Updates are available for iOS, iPadOS, and macOS builds listed by device.
read more →

NetScaler zero-days exploited: urgent patch guidance

🔒 Unit 42 alerts that Citrix has reported active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on CVSS v4.0. The flaws enable unauthenticated remote code execution and a DTLS memory overflow that may cause RCE or DoS on NetScaler ADC and Gateway devices. Unit 42 urges immediate patching, system isolation, evidence preservation, and threat hunting while offering Incident Response assistance.
read more →

NeedyMantis: Modular post‑compromise malware analysis

🛡️ Microsoft Threat Intelligence describes NeedyMantis, a modular post‑compromise malware family observed since October 2025 in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is typically deployed after initial access to maintain persistent access and support follow‑on operations. NeedyMantis uses multiple loaders, a custom encrypted archive format, a bespoke executable layout, and modular components to evade analysis and extend capability. Microsoft links observed activity to Storm‑3069 and activity consistent with Chinese‑aligned threat actors, and provides IOCs, Defender detections, and mitigations.
read more →

Amazon Corretto September 2026 Patch Updates

🛡️ Amazon released September 25, 2026 patch updates for Corretto LTS and Feature Release builds, including Corretto 25.0.4.10.1, 21.0.12.11.1, 17.0.20.12.1, and 11.0.32.12.1. These Corretto distributions are no-cost, production-ready builds of OpenJDK. The update incorporates the tzdata 2026d timezone data refresh. Users can download releases or configure Apt, Yum, or Apk repositories to receive the updates and provide feedback.
read more →

Critical NetScaler zero-days demand immediate patch

🔒 Citrix has confirmed two critical unauthenticated remote code execution zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are under active exploitation and must be patched immediately. Citrix released fixes in versions 14.1-73.37 and later and 13.1-64.23 and later, and urged customers to install updates as soon as possible. The US CISA added both to its KEV catalog while Citrix published additional mitigations, IOCs and fixes for six other related vulnerabilities.
read more →

Citrix issues urgent patches for critical NetScaler flaws

🔐 Citrix has released updates addressing eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, including two critical zero-days that were actively exploited. The most severe issues — CVE-2026-88771 and CVE-2026-88772 — enable unauthenticated remote code execution in default deployments and in DTLS-enabled configurations respectively. Agencies including CISA and the ACSC have issued emergency patching guidance, and Citrix urges customers to install updates immediately.
read more →

CISA Adds Two Critical Citrix NetScaler Flaws to KEV

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Both issues carry CVSS scores of 9.5 and can lead to remote command execution or denial-of-service; one requires DTLS to be enabled. Citrix has released patched versions and provided IoCs through the NetScaler Console to help customers detect compromises.
read more →

Cloudflare fixes Containers flaw exposing customer data

🔒 Cloudflare patched a vulnerability in its Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other tenants on the same physical host. The issue, reported via HackerOne on September 4, stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks, enabling partial reads of leftover data. Cloudflare retired affected disks, cleared cached snapshots, and applied automatic fixes by September 19, 2026, finding no evidence of real-world data exposure.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A high-severity CSRF vulnerability in the Elementor Website Builder (versions 4.3.0 and 4.3.1) allows an unauthenticated attacker to coerce logged-in users into performing REST API actions, including creating rogue administrator accounts. Patchstack reported the issue, which affects over 2 million installations of those versions and has a CVSS score of 8.8. The flaw stems from the Editor Events module skipping CSRF checks when "elementor/v1/events/" appears in the request URI. Elementor addressed the bug in version 4.3.2 following disclosure by researcher "Saggre," and users are urged to update immediately.
read more →

Elementor CSRF Flaw Lets Attackers Create Admins

🔒 A CSRF vulnerability in the Elementor WordPress plugin could let an unauthenticated attacker create administrator accounts by tricking a logged-in admin into opening a crafted link. The flaw affects versions 4.3.0 and 4.3.1, which are active on up to 2 million sites. Patchstack reported the issue to Elementor on September 22 and a fix was issued in version 4.3.2 two days later. Users are advised to update immediately to prevent one-click admin account creation attacks.
read more →

CISA Alerts: Active Exploits in WSO2, Adobe, SharePoint

⚠️ CISA warns that multiple critical and high-severity vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS are being actively exploited. Two critical flaws—CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce—were added to the Known Exploited Vulnerabilities catalog with federal mitigation deadlines. Agencies must patch or mitigate by the specified dates, and organizations are urged to prioritize these fixes.
read more →

Critical WordPress RCE CVE-2026-87902 Patch Alert

⚠️ A critical Remote Code Execution vulnerability, CVE-2026-87902, affects WordPress versions 4.7.0 through 7.1.1 and allows arbitrary PHP file inclusion leading to potential code execution. WordPress released patches on September 22 (latest recommended version 7.1.2 or newer), but exploit attempts were observed within hours. Site owners should update immediately and follow recommended hardening measures to complement the patch.
read more →

GitLab issue-email token exposes account access

🛡️ A GitLab feature that supplies a project-scoped email address to create issues embeds a long-lived token in the address, which can be used to act as the linked user across projects. Aikido Security found the token (prefixed with glimt-) is identical across project addresses for an account and bypasses IP restrictions, enabling actions like creating issues and merge requests with the account's permissions. GitLab updated wording to acknowledge merge request capabilities; Aikido recommends treating the addresses as credentials and rotating tokens if exposed.
read more →

CISA Adds Critical WSO2 and Adobe Flaws to KEV

🔒 CISA has added two critical vulnerabilities—affecting WSO2 and Adobe Commerce/Magento—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws include a path traversal and unrestricted file upload in WSO2 leading to remote code execution, and an authorization bypass in Adobe Commerce that allows customer account takeover. Federal agencies are advised to patch by September 27, 2026.
read more →

WordPress critical RCE flaw patched; rapid attacks follow

🔒 WordPress released a security update fixing a critical remote code execution vulnerability (CVE-2026-87902) that allows unauthenticated attackers to include and execute readable local PHP files outside active theme directories. The flaw, reported by researcher Robert Ressl, has been backported to versions as far back as 4.7 and has already seen exploitation in the wild. Security firms observed reconnaissance within hours and active payload delivery within a day, prompting urgent calls for fast, verified patch rollouts and increased visibility of forgotten WordPress instances.
read more →