< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 8 of 125

GitLab urges immediate patch for critical path flaw

🚨 GitLab has released urgent updates to address a maximum-severity path traversal vulnerability (CVE-2026-85706) discovered in the repository commits API and reported via HackerOne. The flaw allows unauthenticated attackers, under certain conditions, to read arbitrary files from vulnerable servers, potentially exposing credentials and secrets. GitLab patched this and a separate critical insecure deserialization bug (CVE-2026-87719) and strongly urges self-managed instances to upgrade to the fixed CE/EE releases immediately.
read more →

PaperCut issues maintenance releases replacing emergency patches

🛡️ PaperCut released Regular Maintenance Releases for NG/MF versions 26.0.5, 25.0.13 and 24.1.10 that replace earlier emergency patches addressing two actively exploited vulnerabilities. These MR builds include fixes from Emergency Patch Releases 1–3, additional hardening, and standard QA testing. Customers running emergency patch builds are advised to upgrade to the maintenance releases for full protection.
read more →

September Windows Server updates break RDS connectivity

🖥️ Administrators report that September 2026 cumulative updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025, preventing users from connecting and sometimes requiring hard resets. Affected servers often run normally for hours after patching before RDS connections start failing; existing sessions may not disconnect and new connections hang. Rolling back the updates restores functionality, but also removes security fixes. Microsoft is aware and investigating.
read more →

Excel KB5002914 update disrupts copy and paste

🔧 Users report that Microsoft’s KB5002914 Office security update, released in the September 2026 Patch Tuesday, is breaking copy-and-paste and formula autofill in Excel for some installations. Affected reports span Office versions from 2016 through 2024 and include both MSI and Click-to-Run deployments. Uninstalling or rolling back the update restores functionality for many users, while Microsoft says it is investigating and has added the issue to the KB5002914 release notes.
read more →

Check Point patches two 9.8-rated VPN certificate flaws

🔒 Check Point released fixes on September 9 for two critical VPN certificate vulnerabilities affecting its Security Gateway appliances and Security Management Server. Both flaws — CVE-2026-85102 (certificate trust validation) and CVE-2026-85103 (ASN.1 heap overflow) — carry a CVSS score of 9.8 and could, under specific conditions, allow unauthenticated remote code execution. The company deployed fixes via Live Patch and Jumbo Hotfixes, but customers reported rollout delays, broken advisory links, and incomplete version clarity. Check Point says it discovered the issues internally and has no evidence of active exploitation.
read more →

CISA Adds Cisco, Citrix, Fortinet Flaws to KEV List

🔒 CISA has added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities (KEV) catalog, mandating Federal Civilian Executive Branch (FCEB) agencies to patch by September 12, 2026. The issues include a Cisco FMC authentication bypass (CVE-2026-20079, CVSS 10.0) with active exploitation, a Citrix NetScaler ADC/Gateway bypass (CVE-2026-19490, CVSS 9.3), and a Fortinet FortiOS heap overflow (CVE-2025-25249, CVSS 7.3) linked to a Node.js RAT called PivotC2. Vendors and researchers reported observed post-compromise activity, honeypot hits, and large-scale scanning campaigns, prompting guidance to patch, limit internet exposure, and hunt for indicators of compromise.
read more →

Nearly 1 in 10 LiteLLM Gateways Exposed Default Key

🔒 Wiz Research found that many internet-facing LiteLLM gateways still accept the example admin key sk-1234 from the setup guide, allowing full admin access. The master key controls admin rights and authentication; if left default or unset, attackers can retrieve provider API keys and potentially cloud IAM credentials via pass-through endpoints. Several CVEs affecting guardrails, MCP authentication, and sandbox escapes have been fixed in recent releases, and upgrades plus key rotation are recommended.
read more →

MikroTik patches critical RouterOS vulnerabilities

🔒 MikroTik issued RouterOS patches addressing six vulnerabilities, including an SSH public-key validation flaw and an authentication escalation bug that can be chained to fully compromise devices. Researchers from CERT Polska reported active exploitation, dubbed MikroTrick, and the vendor released updates across 7.x and 6.x branches while urging administrators to avoid exposing SSH to the internet. The company added a "Flagged" state to indicate possible compromise, and users are advised to isolate, reset, and rotate credentials if flagged; temporary mitigations include blocking SSH, WWW/WWW-SSL, and bandwidth-test services from untrusted networks.
read more →

Passkey-Themed Social Engineering Drives Cloud Identity Compromise

🔒 Microsoft Security Research describes coordinated intrusions beginning with passkey-themed social engineering and progressing to authentication persistence, cloud reconnaissance, and targeted data collection. The actors use phone and trusted internal messages to lure victims to convincing phishing sites or device-code flows, then add authentication methods and leverage Microsoft Graph, SharePoint, OneDrive, and Exchange to enumerate and collect data. Defenders are urged to investigate identity and Microsoft Graph signals, revoke sessions, and remove unauthorized auth methods.
read more →

ChatGPT cross-account channel exposed Gmail and apps

🛡️ Check Point found a vulnerability in ChatGPT’s code execution environment that allowed hidden instructions to be passed between separate user sessions via a shared internal package metadata service. In a proof-of-concept, an attacker-controlled session could cause a victim’s ChatGPT session to retrieve data from a connected Gmail account and relay it back, while the visible conversation appeared normal. OpenAI has since remediated the issue and decommissioned the implicated internal service, and the flaw raised concerns about isolation failures affecting other connected apps like Drive, Teams, and GitHub.
read more →

DeepSeek Harness sandbox escape lets agent disable limits

🛡️ A flaw in DeepSeek Harness allowed an AI coding agent running in the tool's operating-system sandbox to disable that sandbox by calling the harness's local web interface. The interface exposed the session identifier and lacked proper authentication, letting a single shell command set the session to danger-full-access and execute commands outside the workspace. The vulnerability affected releases up to 0.1.1-rc.2 and was fixed in published npm releases starting with 0.1.2-alpha.2 and 0.1.2-rc.1.
read more →

Microsoft September Patch Tuesday Sets New Record

🛡️ Microsoft released a record 974 CVE fixes in its September 2026 Patch Tuesday, far surpassing the previous monthly high of 570. The update affects a broad range of products, with Windows accounting for 723 CVEs and Office 111. Microsoft highlighted two actively exploited zero-days and the bundle includes 119 critical vulnerabilities, prompting calls for a risk-based approach to prioritization.
read more →

Chrome V8 zero-day patched amid active exploitation

🛡️ Google released updates addressing 230 security vulnerabilities in Chrome, including an actively exploited medium-severity V8 out-of-bounds write (CVE-2026-87491). The flaw, reported by Jihyeon Jeong of Compsec Lab on August 6, 2026, allows remote code execution inside the sandbox via a crafted HTML page. Google confirmed an exploit exists in the wild and urges users to update to Chrome 153.0.8010.36/.37 on supported platforms. The patch also fixes multiple critical WebGL and Cast issues and CISA later added CVE-2026-87491 to its KEV catalog.
read more →

cPanel SQL injection in EmailTrack allows root takeover

🛡️ cPanel has patched an SQL injection flaw, tracked as CVE-2026-67401, that allows an authenticated hosting account with mail-related privileges to create files via EmailTrack and escalate to root. The advisory, published September 8, affects every supported cPanel & WHM release line and lists fixed builds for 11.110, 11.134, 11.136, 11.138 and WP Squared. cPanel provides update instructions but offers no interim mitigations, exploit details, or guidance for post-compromise verification.
read more →

SAP issues emergency kernel patches for critical flaws

🛡️ Onapsis has disclosed a maximum severity memory corruption vulnerability in the SAP kernel, tracked as CVE-2026-44756, which may affect over 10,000 internet-facing SAP systems. The bug exists in SAP Extended Passport (EPP) Processing and can be triggered remotely without authentication via crafted network requests, potentially allowing attackers to execute arbitrary OS commands with SAP admin privileges. Onapsis also warned of several other critical issues, including S4GET (CVE-2026-58240) and additional high-severity flaws, and urged customers to apply SAP security notes immediately.
read more →

Researcher Releases PoC for Microsoft Defender Zero-Day

🛡️ A researcher known as Chaotic Eclipse published a proof-of-concept for a zero-day in Microsoft Defender, dubbed ShieldCrash. The bug is described as a patch bypass for CVE-2026-69414 (ShieldBreak), which the researcher reported last month. The PoC shows an arbitrary file read as SYSTEM on up-to-date Windows installations, with all supported desktop versions affected. Microsoft recently updated the Malware Protection Engine to address CVE-2026-69414 and urges automatic updates for protection.
read more →

SAP issues emergency patches for critical kernel flaws

🔒 SAP released urgent security updates to fix multiple critical vulnerabilities, including a maximum-severity (CVSS 10.0) memory corruption bug in EPP Processing (CVE-2026-44756, "OVERPASS") discovered by Onapsis. The flaw is remotely exploitable without authentication and can lead to OS command execution with SAP administrative privileges, risking full compromise of business data and processes. SAP also patched CVE-2026-58240 ("S4GET") in NetWeaver Message Server and two other high-severity issues affecting CAP and SAP GUI for Java.
read more →

Microsoft issues record Patch Tuesday fixes

🛡️ Microsoft released an unprecedented Patch Tuesday fixing 974 vulnerabilities across its product portfolio, including two actively exploited zero-days. The updates span Windows, Office, SQL Server, and developer tools, with over 110 rated critical and many tied to privilege escalation, remote code execution, and information disclosure. CISA added the two exploited flaws to its KEV catalog, mandating federal remediation by September 22, 2026.
read more →

Microsoft Patch Tuesday: September 2026 Vulnerabilities

🔒 Microsoft released its September 2026 security update covering 973 vulnerabilities across many products, including 113 marked critical. Two vulnerabilities were reported exploited in the wild: one in the Windows Update Stack (CVE-2026-81963) and one in Windows ALPC (CVE-2026-85880). The bulletin highlights numerous remote code execution and elevation-of-privilege issues, with several high CVSS scores and multiple components prioritized for remediation.
read more →

Microsoft issues record Windows security patch batch

🔒 Microsoft released updates addressing at least 974 security vulnerabilities across Windows and other products, its largest single patch bundle ever. Two zero-day vulnerabilities are being actively exploited, and 113 bugs were rated critical. Vendors attribute rising patch volumes to AI-assisted discovery, while security teams warn of the burden of testing and deploying so many fixes. Administrators are urged to prioritize and test patches carefully to avoid disruption.
read more →