< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 5 of 125

Active exploitation of two high‑severity Check Point flaws

🔒 Check Point Research reports active exploitation of two critical vulnerabilities affecting Security Gateway and Security Management. CVE-2026-85102 (RCE during VPN certificate handling) had patches available since September 9 and is being actively probed; unpatched Spark customers are at risk. CVE-2026-93616 is a newly observed pre-authentication path traversal zero-day in Management; a fix is available now. Customers should install vendor fixes immediately and follow published mitigation and hunting guidance.
read more →

D-Link warns of critical zero-day in DIR-822A routers

🔒 D-Link disclosed a max-severity zero-day affecting DIR-822A routers that stems from a stack-based buffer overflow in the DHCP server component and can be exploited without authentication. Attackers on the same local network can send crafted DHCP packets to crash the DHCP daemon or achieve remote code execution. The vendor noted a public proof-of-concept exploit and is investigating a second public PoC for an L2TP parser out-of-bounds write.
read more →

Critical CVE-2026-93952 in VeloCloud Orchestrator

🛡️ Arista disclosed CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) that can allow a remote attacker with no login to privilege internal functions on orchestrators configured for certificate-based Edge authentication. Fixed releases are available for the 5.2 and 6.4 trains and for Hosted and Dedicated VCOs; 6.1 and 7.0 fixes are pending. Arista rated the flaw CVSS 3.1 10.0 and said it was discovered externally and is actively exploited.
read more →

New ARM64 KVM flaw exposes host memory

🔒 A vulnerability in the Linux kernel's KVM nested virtualization code for ARM64 (CVE-2026-89775) can leave freed host memory mapped and writable to a guest VM, enabling guest reads and writes and potential escape to the host. The bug is fixed upstream in Linux 6.18.51, 7.2.5, and 7.3-rc1, and affects systems only when nested virtualization is enabled. Vendors rate the impact high, and distributions are patching on differing schedules.
read more →

SharePoint flaw reclassified as remote code execution

🛡️ Microsoft initially labeled a SharePoint Server bug as a spoofing issue, but researcher Dinh Ho Anh Khoa's full disclosure shows it enables authenticated remote code execution. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition and was patched in August; the NVD assigns it an 8.8 score. Khoa's write-up details how unescaped quotes in Register directives allow arbitrary .NET class loading and execution via XamlServices.Parse().
read more →

New Microsoft Defender zero-day blocks updates

🛡️ A security researcher, Abdelhamid Naceri (aka Nightmare Eclipse), released a proof-of-concept named BigDiskBuster that prevents Microsoft Defender from applying definition and platform updates while it runs in the background. The researcher says the tool affects all supported Windows versions and resembles prior PoCs like UnDefend, though it is described as somewhat buggy. Microsoft did not immediately comment on the report and some earlier flaws disclosed by the researcher remain unpatched.
read more →

Hidden Muse setting lets local malware hijack assistant

🛡️ Security researcher Patrick Wardle demonstrated on September 21 that malware already running on a Mac can change a hidden Muse preference so dictation is sent to an attacker-controlled endpoint instead of Meta. The issue affects the Mac Muse app and requires code execution as the logged-in user; it is not a remote exploit. Wardle warned that this lets attackers leverage the app's granted permissions to access files, messages, and other resources Muse can reach.
read more →

WordPress Comment2Shell vulnerability patched

🛡️ WordPress fixed a critical flaw, CVE-2026-93485 dubbed Comment2Shell, on September 17 in version 7.1.1 after a researcher showed how a crafted comment could plant a hidden script that executes when a page is viewed. The bug allowed that script to act with the viewer's privileges and, if an administrator viewed the page, to leverage the admin session to upload a plugin web shell. Site owners are urged to update immediately or temporarily disable comments and consider WAF or security plugin mitigations.
read more →

Zyxel and Veeam Flaws Under Active Exploitation

🛡️ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more →

WordPress Click2Shell flaw enables remote PHP execution

🛡️ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.
read more →

Microsoft September update breaks File History backups

🔔 Microsoft warned that the built-in File History backup feature may stop working on some systems after installing the September 2026 security updates. Affected users may see FileHistory.exe crashes referencing KERNELBASE.dll, incorrect "Reconnect your drive" prompts, stale "Last Backup" timestamps, and "No previous version available" for prior backups. Impacted releases include Windows 10 21H2+, Enterprise LTSC 2016/2019, and Windows 11 23H2+.
read more →

Detecting and Quarantining Exposed AWS IAM Keys

🔎 This article examines how AWS mitigates publicly exposed IAM access keys through the AWSCompromisedKeyQuarantine managed policy, tracing its evolution across versions and explaining its role in responding to leaked credentials. It details the GitHub secret scanning partnership with AWS, a real-world timeline from a public exposure test, and practical monitoring strategies security teams can use to detect quarantine events in their logging environments. The piece also outlines Palo Alto Networks services that can assist organizations in assessment and incident response.
read more →

Researchers Escape OpenAI Codex Sandbox to Run Commands

🛡️ Security researchers discovered two sandbox escapes in OpenAI's Codex that allowed untrusted agent code to execute commands on a developer's machine without prompts or visible output. Reported on August 12 and fixed within eight days, the vulnerabilities — dubbed Heapjack and Overpatch — exploit a shared memory token in a Node.js REPL and an overly permissive patch tool in the CLI. OpenAI released fixes in Codex Desktop build 26.818.21641 and Codex CLI 0.149.0; users should update immediately.
read more →

SolarWinds fixes high-severity ARM flaw

🔒 SolarWinds released updates to fix a high-severity vulnerability in Access Rights Manager (ARM) that could enable unauthenticated remote code execution. Tracked as CVE-2026-28326 and rated 8.8, the issue affects ARM 2026.2 and earlier and is addressed in ARM 2026.2.1. The flaw, attributed to a hard-coded static key, was reported by researcher Kai Huang from Armadin. No active exploitation has been reported.
read more →

CISA Adds Three Linux Kernel Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The flaws include high-severity issues in the TLS receive path, ebtables SNAT ARP rewrite, and an AF_ALG socket race condition, with CVSS scores of 9.8, 8.8, and 7.8 respectively. Red Hat updated advisories on September 19, 2026, urging immediate remediation, and FCEB agencies are recommended to patch by September 21, 2026 under BOD 26-04.
read more →

Public exploit code released for four Linux kernel flaws

🛡️ A researcher published working exploits for four Linux kernel local privilege-escalation flaws called DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Kernel maintainers have released fixes in recent stable kernels, so up-to-date systems are not vulnerable, but unpatched machines should be updated promptly. Three flaws require unprivileged user namespaces to reach, while DiagSpill needs only SCTP support. The exploits are tuned to specific builds, may crash systems, and so far show no evidence of in-the-wild use.
read more →

WordPress Click2Shell forced theme install patched

🔒 WordPress issued an urgent security patch (7.1.1) to address a vulnerability dubbed Click2Shell discovered by pwn.ai, which can cause a crafted link opened by a logged-in administrator to install an official WordPress.org theme without clicking Install. The core bug alone installs a legitimate theme, but chained with a separate theme flaw it can lead to remote code execution. Site operators should update immediately; affected branches back to 4.7 received fixes.
read more →

Plugin4Shell: Zero‑Click RCE in AI Coding Agents

🔒 Researchers discovered a zero-click vulnerability called Plugin4Shell affecting AI coding agents like Codex, Claude Code, Gemini CLI, and GitHub Copilot, allowing attackers to swap trusted plugins for malicious ones and execute code without developer interaction. The flaw stems from agents passing a Git commit SHA to Git but not verifying the checked-out commit, enabling repository owners or takeovers to resolve a malicious version under the expected identifier. Some vendors have patched the issue, while others have deprecated components or applied mitigations; enterprises are urged to inspect affected machines and audit logs.
read more →

Microsoft patches CVSS 10.0 flaw in Azure AI Foundry

🔒 Microsoft has released a fix for a maximum-severity privilege escalation flaw in Azure AI Foundry (CVE-2026-85889, CVSS 10.0). The company says the issue, discovered by Rémy Marot, allowed missing authentication for a critical function but has been fully mitigated and requires no customer action. Microsoft also patched several other high-severity Azure and Windows vulnerabilities in recent updates.
read more →

Plugin4Shell: Version-locked plugin swap risk

🔒 A flaw in four popular AI coding agents lets a repository owner swap a reviewed plugin for malicious code even when the agent locked it to a specific commit hash, Air Security reported. Anthropic and OpenAI have released fixes for Claude Code (2.1.179) and Codex (0.146.0) respectively; GitHub Copilot remains unpatched and Google will not fix the Gemini CLI. The issue arises when code hosts permit branch or tag names that look like commit hashes, allowing an attacker to point that name at different code while the agent reports the locked version.
read more →