< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 7 of 125

Critical WSO2 JWT Flaw Under Active Exploitation

⚠️ WSO2 users face active exploitation of CVE-2026-5430, a critical JWT signature verification flaw that enables account takeover. Affected products include API Manager, API Control Plane, Traffic Manager, and Universal Gateway across several 4.x releases; fixes and update levels have been published. WatchTowr reports in-the-wild attempts capturing forged admin JWTs on September 13, 2026, and urges immediate patching to prevent unauthorized access and lateral movement.
read more →

Acronis warns of exploited cPanel backup flaw

🔒 Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. The flaw, designated CVE-2026-87886 with a 7.8 severity score, allows a low-privileged attacker to elevate permissions on affected Linux servers. Acronis reports limited, targeted exploitation and urges administrators to apply patches that fix affected builds of the plugin and extension.
read more →

Critical Cisco Secure Email Gateway zero-day patch

🔒 Cisco issued emergency fixes for a critical Secure Email Gateway vulnerability, CVE-2026-76461, that was being actively exploited. The flaw is an SQL injection in the product’s email parsing code and can lead to arbitrary SQL execution and root command execution. Patches are included in AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780, and CISA has added the issue to its KEV catalog.
read more →

Exposed Vite servers probed for cloud credentials

🔎 Attackers have begun probing exposed Vite development servers for sensitive data, including AWS and Azure credentials, environment files, and infrastructure state. F5 Labs observed over 32,000 scan attempts in August exploiting a file-access bypass (CVE-2026-39364) that defeats Vite's deny-list protections when specific query parameters are used. F5 urges patching Vite, rotating secrets, and ensuring development servers are not bound to external interfaces.
read more →

Mass scanning targets Vite dev servers and secrets

🔒 Cybersecurity researchers disclosed a widespread scanning campaign that targeted internet-exposed Vite development servers to harvest cloud credentials, configurations, and infrastructure state files. The activity, observed in August 2026, exploited CVE-2026-39364, a high-severity Vite flaw that allows unauthenticated attackers to bypass server.fs.deny protections via crafted query parameters. Successful exploitation requires the dev server to be exposed with --host or server.host, the sensitive file to reside within server.fs.allow, and a matching deny pattern. Attackers used forged headers and crawler-like User-Agents while operating from varied global IP ranges to evade detection.
read more →

Microsoft September Patch Breaks Excel Copy/Paste

🛠️ Microsoft confirmed that the September 2026 KB5002914 security update can cause copy-and-paste, autofill, and formula dragging to silently fail in Excel. Affected versions include Microsoft Excel 2016, 2019, 2021, and 2024, and users receive no error when the paste operation does not complete. Microsoft is investigating and will update its support document; some users report uninstalling KB5002914 restores functionality. The article also notes related recent Office and Windows fixes and emergency out-of-band updates.
read more →

Microsoft issues emergency out-of-band security patch

🛠️ Microsoft released an out-of-band update (KB5129195) on September 14 to address stability and functionality problems introduced by the September 8 Patch Tuesday. Affected services included Remote Desktop Services (RDS), MMC tools, File Explorer and the Windows Update page, which could become unresponsive or cause RDP connections to fail. The update also resolves Hyper-V issues impacting Plan9 shared folders, WSL integrations, and USB Audio Class 1.0 device failures. Administrators who applied temporary Group Policy mitigations do not need additional steps before installing this cumulative update.
read more →

Critical Cisco Secure Email Gateway zero-day exploited

📣 Cisco warned customers of an actively exploited zero-day in Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The flaw stems from insufficient validation in email parsing and malicious SQL in crafted messages. Cisco released patches and IOC guidance, while CISA added CVE-2026-76461 to its KEV Catalog, ordering federal fixes within three days.
read more →

LiteSpeed Enterprise flaw risks root on shared hosts

⚠️ cPanel warned on September 14 of a critical vulnerability in LiteSpeed Web Server Enterprise affecting versions before 6.3.7 that could allow a low-privilege hosting account to escalate to root on shared servers. Administrators are urged to install 6.3.7, released by LiteSpeed on September 11, using the provided manual update command. The advisory notes the flaw can bypass account isolation controls such as CageFS, but neither vendor has published technical details, a CVE, or evidence of exploitation.
read more →

Microsoft issues emergency Windows updates for RDS failures

🔧 Microsoft released out-of-band Windows updates on September 14 to address Remote Desktop Services (RDS) failures and related component crashes introduced by the September security updates. The fixes include updates for Windows 11 (KB5129194, KB5129195), Windows 10 (KB5129236), and Windows Server (KB5129235, KB5129237), and are available via Windows Update, WSUS, and the Microsoft Update Catalog. The Windows 11 updates also resolve a Hyper-V Plan9 share issue and some USB Audio Class 1.0 multichannel problems, though Microsoft is still working on remaining audio bugs.
read more →

Telegram Desktop export flaw allowed hidden script

🛡️ Security researchers at ExPatch disclosed a Telegram Desktop flaw that let bot messages embed hidden JavaScript into HTML chat exports. The script executed when an exported HTML file was opened in a browser, allowing exfiltration or page modification, and persisted in previously exported files even after Telegram shipped a fix. Telegram patched the export escaping in July; users should update and re-export or treat old HTML exports as untrusted.
read more →

DDRop attack undermines cloud confidential computing

🔒Researchers disclosed DDRop, a cheap active interposer attack that silently drops writes to DDR5 memory, defeating freshness assumptions in Intel TDX, Scalable SGX, and AMD SEV‑SNP. The exploit requires brief physical access to insert a small board between CPU and DIMM and lets an attacker with existing software control read or manipulate protected VM memory. Vendors were notified and have acknowledged the findings; hardware redesign is needed for a full fix.
read more →

Microsoft September Patch Breaks Vulnerability Records

🔒 Microsoft’s September patch is unusually large, addressing a record ~972 vulnerabilities with 112 rated high critical. This follows consecutive months of escalating patch counts and coincides with industry concern over AI-accelerated discovery and exploitation of flaws. Vendors and organizations have warned the window for patching is narrowing, prompting a surge in rapid remediation efforts. Microsoft emphasizes immediate updates as attackers can quickly weaponize fixes through AI-assisted analysis.
read more →

Urgent Patch for GitLab Path Traversal Flaw

🛡️ GitLab has released a fix for a maximum-severity path traversal vulnerability (CVE-2026-85706) that allowed unauthenticated users to read arbitrary files via the repository commits API. The issue affects multiple versions and was remediated on September 10. Security vendors reported in-the-wild probes shortly after disclosure, and CISA added the flaw to its KEV Catalog, urging rapid remediation. Organizations are advised to patch immediately and hunt logs for suspicious POST requests to the commits endpoint.
read more →

Microsoft September updates cause RDS failures

🔔 Microsoft confirmed that its September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server and client systems. The issue affects Windows Server 2012 and later, as well as Windows 10 and Windows 11, producing RDP connection drops, sign-in problems, and unresponsive management tools. Microsoft published Group Policy mitigations for enterprise environments and noted temporary recovery by restarting affected VMs or uninstalling the updates, though removal also drops security fixes. The company is working on a permanent fix.
read more →

Microsoft September updates break USB audio on Windows

🔊 Microsoft confirmed that installing the KB5124008 and KB5124012 September 2026 security updates can cause some USB Audio Class 1.0 devices to fail on Windows 11 version 24H2 or later. Affected users report "This device cannot start (Code 10)" errors, no audio output, and unresponsive volume controls; some speakers fail only with multichannel or 3D audio. Microsoft has not provided an official workaround, though switching to 2-channel mode has restored audio for some users.
read more →

CISA Adds Five Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The issues include improper authorization and authentication flaws in Artifactory, a privilege management bypass in ScreenConnect, and two critical RouterOS bugs enabling kernel memory disclosure and privilege escalation. Federal agencies have specific patch deadlines in September 2026 to mitigate these risks.
read more →

Dutch NCSC Warns of Critical Check Point VPN Flaws

🔒 The Dutch Nationaal Cyber Security Centrum (NCSC) warns of imminent exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, urging immediate patching. Check Point issued fixes on September 9 (SK1000117, SK1000118) and provided LivePatch and hotfix releases for affected versions including R81.20, R82, and R82.10. Administrators are advised to apply updates promptly and restrict Site-to-Site VPN access to trusted IPs where possible.
read more →

Critical GitLab path traversal flaw draws rapid probes

🔒 GitLab released emergency patches to fix multiple vulnerabilities, including CVE-2026-85706, a CVSS 10.0 path traversal bug in the repository commits API that can let unauthenticated actors read arbitrary files under certain conditions. The flaw affects several CE and EE releases prior to the 19.3.2, 19.2.6 and 19.1.8 fixes, and was observed being probed in the wild from 06:00 UTC on September 11, 2026. GitLab also patched an insecure deserialization issue in EE (CVE-2026-87719, CVSS 9.9). Organizations running internet-exposed, self-managed instances are urged to apply patches immediately or restrict public access.
read more →

ConnectWise patches critical ScreenConnect flaw

🔒 ConnectWise issued an update for ScreenConnect five days after warning customers that active remote sessions could be used to transfer and execute files without authorization. Administrators were advised on Sept. 3 to remove the TransferFiles permission from any users with open sessions. The vulnerability, tracked as CVE-2026-84869, is fixed in ScreenConnect client version 26.6.5 and later. The update follows prior security incidents, including a 2025 nation-state attack and earlier 2024 exploitation reports.
read more →