< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 4 of 125

Unpatched OnePlus flaws let installed apps gain root

🔒 A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app that requests no special permissions. Researcher Rasmus Moorats chained two vendor services to gain root: one that accepts arbitrary calls and injects text into system commands, and another that executes shell instructions when invoked as root. OnePlus confirmed the flaws in May, claimed exclusive control over disclosure, and had not released a patch when Moorats published on September 24.
read more →

Cloudflare: Containers cross‑tenant storage vulnerability fixed

🔒 On September 4, 2026, researcher Oren Yomtov of Accomplish reported a vulnerability affecting Cloudflare Containers and Sandboxes. Cloudflare validated the report, found no evidence of customer data compromise, and applied a fleetwide fix with no customer action required. The issue involved dm-thin thin-provisioning and the skip_block_zeroing option, which could allow residual data disclosure when partially overwriting reassigned 64 KiB blocks. Cloudflare removed the option, retired affected disks and caches, and found no signs of malicious exploitation.
read more →

Critical VeloCloud Orchestrator vulnerability impacts on-prem

🔒 Arista warned of a critical flaw in on-premises VeloCloud Orchestrator that allows remote attackers to access privileged internal functionality and potentially compromise the VSO host. The issue, tracked as CVE-2026-93952 with a CVSS score of 10.0, is actively exploited and affects multiple VCO release trains, though fixes are available only for some versions. Arista recommends immediate upgrades where patches exist and, for those that cannot upgrade, restricting web interface access and monitoring for suspicious indicators of compromise.
read more →

Critical Roundcube flaw now actively exploited

🔒 A high-severity vulnerability in Roundcube Webmail patched in May (CVE-2026-48842) is now being actively exploited, the Canadian Centre for Cyber Security warns. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that can allow unauthenticated attackers to execute database commands and steal data. Administrators are urged to update to versions 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately.
read more →

CISA outlines a Quality Era for global CVE program

🔍 CISA has published a framework to improve CVE data quality as disclosure volumes and AI‑driven discovery accelerate. The paper, released on September 22, shifts the CVE Program from growth to a focus on reliability, responsiveness and record accuracy amid surging submissions. It defines quality across governance, ecosystem participation, data infrastructure and CVE record content and proposes potential measures without setting targets. CISA plans continued engagement with CNAs, researchers and vendors alongside technical modernization.
read more →

Windows 11 preview KB5124010 adds 46 fixes

🛠️ Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, delivering 46 changes including Bluetooth fixes and the ability to remap the Copilot key. This optional update focuses on quality improvements and new features—such as Emoji 17.0 support, an Open apps maximized accessibility option, and a WinRE remote management plug-in—without including security patches. Administrators can install it via Settings > Windows Update or manually from the Microsoft Update Catalog, and it upgrades affected systems to builds 26200.9550 and 26100.9550.
read more →

F5 patches critical BIG-IP APM zero‑day flaw

🔒 F5 released fixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that was actively exploited in the wild. The heap-based buffer overflow, tracked as CVE-2026-94127 and rated 9.8, affects deployments configured as OAuth authorization servers and can also impact appliance-mode systems when both APM and an OAuth authorization server profile are enabled. F5 published hotfixes for the 21.x, 17.5.x and 17.1.x branches and provided an iRule mitigation while patches are applied.
read more →

Leaked GitLab email token enables commits and CI

📧 GitLab issues each user a persistent incoming-email address for filing work items; that address contains a token tied to the account and does not expire. Researchers at Aikido Security found the token is shared across a user's project addresses and allows anyone who holds the address to create issues, open merge requests by email, commit patches to branches (including main) and trigger CI/CD jobs that run as the account holder. GitLab currently does not verify the sender address, and incoming email bypasses IP allowlists and two-factor requirements.
read more →

Arista issues patch for actively exploited VCO zero‑day

🔒 Arista Networks has released patches for a critical zero-day (CVE-2026-93952) actively exploited in VeloCloud Orchestrator (VCO) On‑Prem deployments. The flaw, caused by improper input validation when certificate-based Edge-to‑VCO authentication is configured, allows remote attackers to access privileged host functionality without credentials or user interaction. Arista and CISA have both flagged the issue and recommended immediate mitigation and log review.
read more →

Critical cPanel flaws enable root and cross-account access

🔒 cPanel disclosed three vulnerabilities affecting its CalDAV/CardDAV service and the WP Toolkit plugin on September 22. One flaw (CVE-2026-87899) allows any logged-in hosting account to execute code as root, while another (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. A third issue (CVE-2026-68490) permits local users to read other accounts' calendars and contacts without altering them. Fixed versions for cPanel & WHM and WP Toolkit have been published, and cPanel provides update instructions but no temporary mitigations.
read more →

September 2026 Windows update disrupts Always On VPN

🔒 Microsoft warned administrators that the September 2026 Windows 11 security updates can cause Always On VPN connections to stall or repeatedly fail. The issue appears when profiles use automatic protocol selection between IKEv2 and SSTP, leaving connections stuck in a "Connecting" state or returning "The specified port is already in use." A temporary mitigation is to set the VPN profile to use either SSTP-only or IKEv2-only while Microsoft develops a permanent fix.
read more →

F5 BIG‑IP APM critical OAuth RCE patched

🛡️ F5 has disclosed and patched a critical heap‑based buffer overflow, CVE-2026-94127, in BIG‑IP Access Policy Manager when it is configured as an OAuth authorization server. The vulnerability allows unauthenticated remote code execution via specially crafted traffic to a virtual server hosting an APM access policy and an OAuth authorization server profile. F5 released engineering hotfixes for affected 21.1, 17.5 and 17.1 branches and provided an iRule mitigation for cases where immediate patching is not possible.
read more →

F5 warns of BIG‑IP APM RCE zero‑day being exploited

🔒 F5 released updates to fix a critical BIG‑IP APM zero‑day that is being actively exploited for remote code execution. The flaw affects deployments with APM configured as an access policy and OAuth profile on virtual servers; pure OAuth Client/Resource Server setups without authorization server profiles are not impacted. F5 urged admins to search for indicators like multiple OAuth failures and TMM SIGABRT events and provided an iRule mitigation for those unable to patch immediately.
read more →

Critical Next.js ImageResponse remote code risk fixed

🛡️ Vercel disclosed a critical vulnerability in Next.js ImageResponse that could allow remote code execution when untrusted values are embedded in SVG content during image generation. The flaw affects Next.js 16.2.0 through 16.3.5 on the Node.js runtime and was patched in version 16.3.6 on September 22. The issue stems from Satori incorrectly allowing unescaped values into SVG output; users of Satori should update to 0.33.5. Workarounds include avoiding attacker-controlled values in SVG content.
read more →

Rogue external MFA providers can steal passwords

🔒 Security researchers at Varonis Threat Labs have demonstrated an attack, dubbed TrustSink, that lets an attacker with a highly privileged Microsoft Entra account register a rogue external MFA provider to capture users' passwords during legitimate logins. The malicious provider displays a convincing copy of Microsoft's password prompt during the MFA step, captures credentials in plaintext, then returns a valid signed token so the login completes normally. The technique requires post-compromise access to Global Administrator or Authentication Policy Administrator privileges and can persist across password resets until the rogue provider is removed.
read more →

Check Point warns of critical management server flaw

🔒 Check Point disclosed a critical management server vulnerability, CVE-2026-93616, exploited in targeted attacks on July 23 that allows unauthenticated web service access to run scripts. A patch was released on September 22 for affected Security Management Server versions; administrators should verify releases and install the fix in support article sk1000171. Separately, attempts to exploit a VPN certificate flaw, CVE-2026-85102, have targeted Spark firewalls since September 12 despite fixes issued on September 9. Check Point published mitigation and hunting guidance including indicators of compromise for both issues.
read more →

WordPress issues urgent patch for critical flaw

🛡️ WordPress released updates on September 22 to fix a critical template-handling vulnerability (CVE-2026-87902) that lets unauthenticated attackers cause a site to load PHP files from outside theme folders. The flaw affects versions 4.7.0 through 7.1.1 and was rated CVSS 9.2. Site owners are urged to update to the listed patch for their branch immediately; automatic updates will apply for sites with that setting enabled.
read more →

Critical Bifrost AI gateway flaw allows remote code

🛡️ A critical vulnerability in Bifrost, an open-source AI gateway, lets unauthenticated attackers execute arbitrary commands on the gateway server via a single HTTP request when management authentication is disabled. Tracked as CVE-2026-90898 (CVSS 9.8), the flaw affects HTTP transports before transports/v2.1.0 and is exploitable by registering a stdio-type MCP client through the management API; a fix is available in v2.1.0. Operators should upgrade, enable management auth, and rotate exposed keys if the management API was reachable.
read more →

Check Point issues hotfix for critical management server zero‑day

🛡️ Check Point Software issued emergency hotfixes for a critical Security Management Server vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts via a path traversal flaw tracked as CVE-2026-93616. The company confirmed active exploitation against a small number of customers and published indicators of compromise and temporary mitigations for those who cannot immediately patch. The fix is included in the R82.20 Security Hotfix and applies to Management, Log, Multi‑Domain, and SmartEvent products.
read more →

Proof-of-Concept Fills Disk to Block Defender Updates

🛡️ A proof-of-concept named BigDiskBuster was published on GitHub on September 19 and prevents Microsoft Defender from installing platform and signature updates by filling all available disk space. The tool's author, former Microsoft researcher Abdelhamid Naceri, previously disclosed other Defender exploits that were used in live attacks. No patch, CVE, or official Microsoft advisory exists for this technique; administrators should monitor update failures, free space, and hidden temporary files while restricting execution of unknown binaries.
read more →