< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 6 of 125

Securing AWS AgentCore Harness Credentials

🔒 Unit 42 researchers found that default AWS AgentCore Harness configurations can enable prompt-injection attacks that cause the harness to exfiltrate plaintext credentials from AgentCore Identity. The harness ships built-in tools, including a root-running shell enabled by default, which can access credentials when they are resolved to memory. AWS closed the report as informative under the shared responsibility model; operators should scope allowedTools, apply least privilege to identity vault accounts, and monitor egress from harness containers. Unit 42 offers cloud assessments and incident response support.
read more →

Critical Check Point flaw allows root code execution

🔒 Check Point Software released updates for a critical stack-based buffer overflow (CVE-2026-91843) in Security Management Server and Log Server login flows that can enable remote root code execution without user interaction. The vendor offered temporary mitigations, including system hardening and restricting trusted client IPs in SmartConsole, and advised teams to watch for "Administrator failed to log in: Username too long" alerts. The issue is part of a series of recent critical patches affecting Check Point firewalls and management systems.
read more →

Cisco issues emergency patches for critical ISE zero-day

🔒 Cisco released emergency patches for an actively exploited authentication bypass in Cisco Identity Services Engine (ISE) and ISE-PIC, tracked as CVE-2026-76460 with a CVSS score of 10.0. The flaw allows unauthenticated, root-level access via a management API endpoint; fixes are included in specific 3.1–3.5 patch releases. CISA has added the flaw to its Known Exploited Vulnerabilities list and Cisco urges log checks, iACLs, and re-imaging if compromise is suspected.
read more →

Critical Check Point Management Server Flaw Alert

🔒 A critical stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers can allow unauthenticated attackers to execute code as root over the network. Check Point issued a LivePatch fix and says it has no evidence of exploitation; customers with automatic updates enabled may already be protected. Administrators should apply sk1000155, confirm LivePatch installation, and limit Trusted Clients to known hosts while avoiding direct Internet exposure.
read more →

Critical Docker Sandboxes Escape Flaw Fixed in 0.42.0

🛡️ Docker warned on September 15 that a critical flaw, CVE-2026-77179, in Docker Sandboxes for macOS allowed code running inside a VM to escape the shared project directory and read or modify files on the host as the VMM user; the issue was fixed in 0.42.0 released September 7. A second high-severity issue, CVE-2026-79994, let guests trick a relay into connecting to AF_UNIX sockets outside the workspace. Docker recommends upgrading to 0.42.0+ or using clone mode and avoiding read-write host mounts until patched.
read more →

Critical Unbound DNSSEC Validator Heap Overflow Fix

🛡️ NLnet Labs released Unbound 1.26.1 to address a critical heap overflow in the DNSSEC validator affecting every release prior to 1.26.1. The overflow (CVE-2026-81642) can be triggered by an attacker controlling a malicious zone and may allow denial of service or remote code execution; eight additional flaws were also patched. Source, binaries, and Windows installers are available, and the advisory provides standalone and combined patches for those unable to upgrade.
read more →

Cisco warns of active exploit for ISE API flaw

🔒 Cisco has warned of active exploitation of a critical vulnerability, CVE-2026-76460, in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw, rated 10.0 CVSS, stems from insufficient control on an API endpoint and can allow attackers to bypass the web-based management interface. Cisco released software updates and recommends using iACLs and log reviews while urging customers to upgrade immediately.
read more →

Microsoft issues workaround for Windows domain login bug

🔒 Microsoft provided a temporary workaround after September 2026 security updates caused Windows 11 devices to reject valid domain credentials. The flaw is tied to the Machine Identity Isolation feature entering enforcement mode following updates KB5124008 and KB5124012, which breaks domain trust on systems not using Windows Server 2025 DFL. Administrators are advised to disable Machine Identity Isolation via the same channel it was enabled (Group Policy, Intune, or registry) and then restart and repair the secure channel. Microsoft is preventing enforcement in a future update while working on a permanent fix.
read more →

ISC issues BIND 9.20.29 and 9.21.26 fixes

🛡️ The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to remediate fourteen vulnerabilities disclosed on 16 September, including a DoH-related crash triggered by an invalid SIG(0) when the client closes a connection early. ISC reports no known active exploitation of these flaws and provides no workarounds; twelve of the issues also affect the unsupported 9.18 branch. The advisories detail affected versions, CVSS scores, conditions to exploit each flaw, and that public test reproductions exist to confirm fixes.
read more →

Cisco warns of critical ISE authentication zero-day

🛡️ Cisco has disclosed a maximum-severity zero-day, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE-PIC that allows unauthenticated remote attackers to bypass authentication by exploiting an API endpoint. Cisco reports active exploitation and urges customers to upgrade to fixed patches for supported versions. There are no workarounds; recommended mitigations include iACLs and log review for suspicious usernames using the provided detection command.
read more →

Oracle September patches put Fusion Middleware at risk

🛡️ Oracle’s September 2026 Critical Security Patch Update delivers 673 fixes across 17 product families, led by Oracle E-Business Suite (159 patches) and Fusion Middleware (153). Several vulnerabilities in these products are remotely exploitable without authentication, including five Fusion Middleware flaws rated CVSS 10.0 and an additional CVSS 10.0 issue in Hyperion Financial Management. Oracle urges immediate patching and notes that mitigations such as blocking protocols or removing privileges may break functionality and are not substitutes for updates.
read more →

Critical Issabel Framework JWT RCE Under Active Exploitation

🔒 A critical vuln, CVE-2026-89026, in the Issabel Framework allows unauthenticated remote attackers to execute OS commands by exploiting a hard-coded HS256 JWT signing key. The flaw enables forged bearer tokens to call the '/pbxapi/manager/originate' endpoint, triggering Asterisk to run arbitrary commands as the Asterisk user. A patch released on August 1, 2026, replaces the embedded key with a key in /etc/issabel.conf. Shadowserver reported active exploitation starting September 9, 2026; users should apply the update immediately.
read more →

Critical RCE in WooCommerce Wholesale Lead Capture

🛡️ Wordfence reports attackers uploading PHP webshells via a critical flaw in the premium WooCommerce Wholesale Lead Capture plugin. The vulnerability (CVE-2026-27540) was patched in version 2.0.3.2 on February 20, but exploitation attempts—over 100,000 blocked—continued months later. Site owners should update immediately, scan uploads directories, and check access logs for the vulnerable AJAX action.
read more →

Browser extension can hijack built‑in AI agents

🔒 Security researchers at Forever Security demonstrated that a single ordinary browser extension can commandeer built‑in AI assistants in five Chromium‑based products: Chrome (Gemini Live), Perplexity Comet, Microsoft Edge, Opera Neon and Claude in Chrome. The exploit required only two common permissions and let the extension inject code into the trusted AI page to send commands to the agent. Google and Microsoft have issued patches for Chrome and Edge; Perplexity, Opera and Anthropic paid bounties but have not publicly fixed the exact methods described. Forever Security emphasized the attacks are proof‑of‑concepts requiring the malicious extension to be already installed.
read more →

Parallels Desktop local privilege escalation flaw

🔒 JFrog disclosed a local privilege escalation in Parallels Desktop for Mac that allows a non‑admin local account to execute code as root by abusing the prl_disp_service socket and an unsafe InstallAppliance extract template. The issue, tracked as CVE-2026-90894 and rated 7.8 by JFrog, was demonstrated on Parallels Desktop 26.4.0 on Apple silicon. JFrog says the fix appears in the 27.x line, which is only installable on Apple silicon Macs, leaving Intel users on the 26.x line without the described repair.
read more →

Google patches Pixel modem flaw amid active exploitation

🔐 Google disclosed a high-severity privilege escalation flaw in its Pixel Cellular Modem, tracked as CVE-2026-58704 (CVSS 8.0), which may be under limited targeted exploitation. The NIST description notes a logic error enabling permission bypass and remote (proximal/adjacent) escalation without user interaction. September Pixel updates include fixes for this issue plus 109 other vulnerabilities; users should apply security patches dated 2026-09-05 or later via Settings > Security & privacy.
read more →

Acronis Patch Urged After cPanel Plugin Exploit

🔒 Acronis has disclosed a high-severity local privilege escalation flaw in its Backup plugin for cPanel and WHM, tracked as CVE-2026-87886 (CVSS 7.8), and confirmed it has been exploited in the wild. The issue stems from insecure file permissions and affects older builds of the cPanel & WHM (Linux) plugin and the Plesk extension; fixes are included in 1.9.3 HF3 for cPanel and in updated Plesk builds. Acronis urges immediate installation of the update; limited targeted attacks have been observed, though attribution and detailed attack objectives remain unknown.
read more →

Zero-day Flaws Found in TP-Link Home Security Cameras

🔒 Security researchers disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras used for home and SOHO monitoring. Vendor firmware V5_1.4.6, released 18 August, addresses CVE-2026-15315 (auth bypass via replay) and CVE-2026-15316 (onboarding DoS). OPSWAT warns the auth bypass can expose live video and recordings, while the DoS crashes the HTTPS service. A third, still-unpatched bug is considered critical and may allow full device compromise.
read more →

Google issues September 2026 Pixel security updates

🔒 Google released September 2026 security patches for Pixel devices addressing 110 vulnerabilities, including one zero-day actively exploited in targeted attacks. The high-severity issue, CVE-2026-58704, is a modem component authorization flaw that can allow adjacent-network attackers with basic privileges to escalate privileges without user interaction. Pixel users should install the update via Settings and restart devices to complete the patch.
read more →

Critical RCE Flaw Exploited in WooCommerce Plugin

🔒 Wordfence has observed active exploitation of a critical vulnerability (CVE-2026-27540) in the premium WordPress plugin WooCommerce Wholesale Lead Capture, enabling unauthenticated attackers to upload arbitrary files and achieve remote code execution. The flaw affects versions up to 2.0.3.1 and has prompted over 100,000 blocked exploit attempts since June 2026. Site owners should inspect for unexpected .php files and suspicious admin-ajax requests referencing the "wwlc_file_upload_handler" action.
read more →