< ciso
brief />
Security Advisory and Patch Watch Banner

All news in category “Security Advisory and Patch Watch”

2493 articles · page 9 of 125

FreeIPA and 389-ds vulnerability chain risks domain admins

🛡️ A critical FreeIPA vulnerability allowed an anonymous client to create a Kerberos identity and gain administrator-group membership when combined with a separate 389 Directory Server access-control bug. Red Hat tracked the FreeIPA issue as CVE-2026-76578 (CVSS 9.8) and the directory-server flaw as CVE-2026-76560 (7.5); FreeIPA 4.13.4 contains the project's fix. Red Hat reproduced the chain on default installations and advises restricting LDAP access and disabling anonymous binds until patches are applied.
read more →

Adobe issues emergency patch for Magento zero-day

🛡️ Adobe has released emergency patches addressing a maximum-severity zero-day, CVE-2026-75650, actively exploited in Adobe Commerce and Magento Open Source. Sansec dubbed the flaw "StyleSmuggler" after detecting exploitation beginning September 4, 2026. The vulnerability enables PHP code injection via Magento's template system to generate a malicious email and achieve remote code execution. A VULN-39341 hotfix and encryption key rotation are required to remediate affected versions.
read more →

Amazon RDS adds latest CU and GDR for SQL Server

🔔 Amazon RDS for SQL Server now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) packages for multiple SQL Server versions, including 2016 SP3+GDR, 2017 CU31+GDR, 2019 CU32+GDR, 2022 CU26, and 2025 CU7. These updates address vulnerabilities tracked as CVE-2026-47295, CVE-2026-47296, CVE-2026-54118, and CVE-2026-55002. AWS recommends upgrading instances via the Amazon RDS Management Console, AWS SDK, or CLI and refers users to Microsoft KB articles and the Amazon RDS SQL Server User Guide for upgrade procedures.
read more →

N‑able issues hotfix for critical N-central RCE

🔒 N-able has released a hotfix addressing a critical pre-authentication remote code execution vulnerability, CVE-2026-86218, in its N-central monitoring and management platform. The flaw, given a maximum CVSS score of 10, impacts N-central versions before 2026.3.1.14 and could allow unauthenticated code execution on the server. N-able patched the issue in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) and reports no evidence of in-the-wild exploitation. This follows several recent high-severity vulnerabilities and prior hotfixes.
read more →

Telerik RadAsyncUpload padding oracle leads to RCE

🔒 Security researcher TantoSec published a proof-of-concept that chains an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution against applications in a specific, non-default configuration. Progress shipped a patch in July (2026.2.708) and published CVEs, and there are no confirmed in-the-wild exploit reports as of September 7. The chain targets RadAsyncUpload versions through 2026.2.519 and relies on an explicit custom encryption key and a server-side handler that reads upload results.
read more →

ConnectWise warns of new ScreenConnect file transfer flaw

🔐 ConnectWise has disclosed a new vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments and plans to release a patch later this week. The company provided immediate mitigation steps requiring administrators to remove the TransferFiles (or TransferFilesInSession) permission from session groups via Administration > Security > Roles. Shadowserver currently tracks nearly 6,000 public ScreenConnect instances, and the vendor cautions that these flaws are often targeted by financially motivated and state-backed threat actors.
read more →

N‑able issues fourth hotfix for N‑central RMM

🔒 N‑able released Hotfix 4 (build 2026.3.1.14) for its N‑central RMM to fix CVE-2026-86218, a pre-auth remote code execution vulnerability affecting all on‑premises builds prior to 2026.3.1.14. The company says hosted instances are patched and urges on‑premises customers to upgrade immediately; agents do not require updates. Communications diverge on whether the flaw has been observed exploited in the wild, and no indicators of compromise or interim mitigations were provided.
read more →

N‑able issues emergency hotfix for critical N-central RCE

🔒 N-able released an emergency hotfix addressing a maximum-severity remote code execution flaw in its N-central RMM platform. Tracked as CVE-2026-86218, the vulnerability allows unauthenticated attackers to execute code on internet-exposed instances. N-able issued N-central 2026.3 Hotfix 4 and urged immediate on-premises upgrades, while Shadowserver reports nearly 1,500 exposed servers. Security firms flagged related high-severity bugs and evidence suggesting active exploitation cannot be ruled out.
read more →

Critical VMware Workstation and Fusion Fixes Released

🔒 Broadcom has released patches for two vulnerabilities in VMware Workstation and Fusion, including a critical integer-overflow bug (CVE-2026-59346) that could allow arbitrary code execution from a privileged local VM user. A second fix addresses a stack-based buffer overflow in HGFS (CVE-2026-59347). Both flaws require the attacker to have local administrative privileges on the VM and have been fixed in VMware Workstation 26H1u1 and Fusion 26H1u1. Broadcom credited external researchers for reporting the issues and noted no current evidence of in-the-wild exploitation, though recent attacks on VMware products increase urgency.
read more →

PostgreSQL patch for long‑running logical decoding flaw

🔒 PostgreSQL released fixes for CVE-2026-6471, a vulnerability in logical decoding present since 2014 that allows accounts with the REPLICATION attribute to load arbitrary libraries and execute code as the OS user running the server. A new server parameter, output_plugin_libraries, whitelists allowed output plugins and defaults to 'pgoutput, test_decoding', causing non-default plugins like wal2json and decoderbufs to be blocked until administrators add them and reload configuration. The update affects supported branches 14–18 and is available in upstream and vendor packages; administrators are advised to identify used plugins, update, and add any required non-default plugins to the new parameter.
read more →

Google patches active Chrome zero-day in V8 engine

🔒 Google released an urgent Chrome update to fix an actively exploited high-severity zero-day (CVE-2026-85046) in the V8 JavaScript engine along with 11 other vulnerabilities across Windows, macOS, and Linux. The type confusion bug, reported by researcher Salvatore Gulizia (“Serotav”), can be triggered by crafted web content and may lead to remote code execution within Chrome’s sandboxed renderer. Google withheld technical exploit details while rolling out Chrome 152.0.7977.82/.83 to give users time to update; a restart is required once the update downloads.
read more →

Mass exploit attempts target WordPress plugins

🛡️ Wordfence reports that threat actors have been actively exploiting critical vulnerabilities in the WordPress plugins Super Forms and Elementor Pro, enabling unauthenticated file uploads that lead to remote code execution. Both flaws permit attackers to upload PHP web shells, which can be used to create admin accounts, exfiltrate data, or seize control of sites. Over 440,000 exploit attempts have been blocked, and site owners are urged to apply patches and scan for compromises.
read more →

Plex issues urgent update to fix multiple flaws

🔒 Plex has released updates for Plex Media Server (1.43.3) and Plex Desktop (1.115.0) to address multiple security flaws and is urging users to upgrade immediately. The vendor has requested CVE identifiers for the patched issues but did not provide technical specifics. Plex recommends manual installation for NAS users if package managers have not yet received the updated builds. This advisory follows prior high-severity fixes and historical exploitation events involving Plex servers.
read more →

Google issues Chrome update to fix active V8 zero-day

🔒 Google released security updates fixing 12 Chrome vulnerabilities, including an actively exploited high-severity V8 type confusion bug (CVE-2026-85046) with a CVSS of 8.8. Researcher Salvatore Gulizia (Serotav) reported the flaw on August 4, 2026, and received a $1,000 bounty. Google confirmed exploits exist in the wild and urges users to update Chrome to 152.0.7977.82/.83 on supported platforms. Other Chromium-based browser users should apply vendor fixes when available.
read more →

HPE fixes critical ArubaOS‑CX remote code flaw

🔒 HPE has released patches for a critical buffer overflow in ArubaOS‑CX (CVE-2026-73749) that lets unauthenticated attackers send crafted packets to a daemon and achieve remote code execution with elevated privileges. The vendor lists fixed builds across multiple release branches and warns that some versions have reached End of Maintenance, receiving only selective critical fixes. The bulletin also addresses 23 additional vulnerabilities ranging from high to low severity and urges customers to upgrade to the patched releases.
read more →

Critical Cisco Nexus 9000 Flaw and IOS XR Hardening

🔒 Cisco released patches for a critical Nexus 9000 vulnerability (CVE-2026-20212) that allows unauthenticated remote root code execution via TCP ports 43210 and 43211. The advisory affects 10 Silicon One-based Nexus 9000 PIDs and lists mitigations including iACLs and a Live Protect shield while customers use the Software Checker to pick fixed releases. Cisco also published an IOS XR hardening release bundling seven umbrella CVEs, two rated 9.8, and provided SMUs and upgrade guidance for affected XR trains.
read more →

Microsoft preview update resets Windows desktop settings

🛠️ Microsoft confirmed that installing the KB5120998 August 27, 2026 preview update can cause desktop settings to fail to load on some Windows 11 devices. Affected systems running Windows 11 24H2 and 25H2 may see wallpapers revert to a solid black background and experience lost themes, slideshow, or contrast settings. The issue also prevents users from restoring their custom settings, and a related mouse settings regression was acknowledged. KB5120998 is an optional, non-security preview update that may install automatically if users enabled immediate update delivery.
read more →

Decade-old PostgreSQL flaw risks backup accounts

🛡️ A decade-old vulnerability in PostgreSQL’s logical replication can let low-privilege REPLICATION accounts load and execute arbitrary code, potentially escalating to superuser and full server compromise. Cyera Research named the issue PostGREShell and reported it to the PostgreSQL Security Team; patches were issued in August for supported releases including 18.6, 17.11, 16.15, 15.19, and 14.24. Windows systems are especially exposed due to UNC/SMB loading vectors. Administrators are urged to patch, audit replication accounts, and restrict outbound SMB/NFS access.
read more →

Plex urges immediate updates to address security flaws

🔒 Plex has urged users to immediately update Plex Media Server and the Plex Desktop client to patch multiple security vulnerabilities affecting Server v1.43.2 and earlier. The company released Plex Media Server 1.43.3 (May 19) and Plex Desktop 1.115.0 (Aug 13) and has emailed affected customers asking them to upgrade. CVE identifiers have been requested and Plex warns users to update before attackers reverse-engineer the fixes. NAS package managers may not yet carry the updated server build, so manual installation could be required.
read more →

CISA Adds Seven Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The list includes critical issues in SonicWall SMA, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM, ranging from SSRF and SQL injection to authentication bypasses and command injection. Several of the flaws have been observed in real-world attacks that deployed reverse shells, minted admin tokens, and delivered cryptocurrency miners. Federal agencies are being directed to prioritize patches under BOD 26-04 with staggered remediation deadlines in September 2026.
read more →