< ciso
brief />
Tag Banner

All news with #patch release tag

502 articles

ServiceNow patches three maximum severity platform flaws

๐Ÿ”’ ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more โ†’

ServiceNow issues highโ€‘severity AI Platform security fixes

๐Ÿ”’ ServiceNow released patches on August 27, 2026, for four vulnerabilities affecting the ServiceNow AI Platform, three rated CVSS 10.0 and exploitable by unauthenticated attackers in certain conditions. The company deployed updates to hosted instances and provided fixes to partners and selfโ€‘hosted customers, who must apply them manually. ServiceNow stated it has no current evidence of exploitation and continues to support customers applying the patches.
read more โ†’

ServiceNow patches three critical AI Platform flaws

๐Ÿ”’ ServiceNow issued emergency patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) can be exploited by unauthenticated attackers with low complexity and no user interaction. The company also patched a high-severity sandbox escape (CVE-2026-6876) and urged customers to update self-hosted instances promptly.
read more โ†’

Critical cPanel flaw allows root code execution

๐Ÿ›ก๏ธ cPanel released patches for a critical vulnerability (CVE-2026-65643) affecting domain parking and addon domain handling in cPanel & WHM that could let authenticated users create arbitrary files and achieve root code execution. The company published fixed builds across multiple release branches on August 27, 2026, and advised administrators to update immediately or enable automatic updates. The advisory names patched builds including a WP Squared release, omits DNSOnly, and provides no interim mitigation or CVSS score. Servers on end-of-life versions must upgrade to receive the fix.
read more โ†’

Windows 11 preview update KB5120998: 35 fixes

๐Ÿ›ˆ Microsoft released the KB5120998 preview cumulative update for Windows 11 25H2 and 24H2, bringing 35 non-security changes and improvements to the Start menu, taskbar, search, and system behaviors. This optional update lets administrators test bug fixes and new features before they're broadly deployed in the next Patch Tuesday release. It also begins rolling out an administrator protection feature that supplies just-in-time privileges and profile separation, disabled by default and configurable via Intune or Group Policy.
read more โ†’

PaperCut zero-day actively exploited; emergency patch

๐Ÿšจ PaperCut warned customers that attackers are actively exploiting a zero-day affecting all versions of PaperCut NG and PaperCut MF. The vendor issued emergency patches for v25 and v26 and confirmed known customer incidents while an investigation continues. Indicators include suspicious post-exploitation activity by "pc-app.exe," missing or truncated server.log files, and specific error entries such as ERROR No suitable driver found for jdbc:no:x. Users with internet-exposed PaperCut servers are urged to immediately restrict access to trusted IPs and apply network controls.
read more โ†’

Next.js fixes critical RCE via AVIF and Windows path

๐Ÿ”’ Vercel released urgent patches for two critical remote code execution flaws in Next.js: one triggered by specially crafted AVIF images and another by a Windows-specific path traversal. Fixes are available in Next.js 15.5.24 and 16.3.3 published August 25, 2026; Vercel-hosted apps are already protected. Users on affected versions should upgrade immediately, especially Windows-hosted servers which have no workaround.
read more โ†’

Microsoft issues fix for Windows 11 gaming crashes

๐ŸŽฎ Microsoft has begun rolling out a permanent fix for an issue that caused system crashes and games to fail with EXCEPTION_ACCESS_VIOLATION on Windows 11 devices. The problem was traced to the inpoutx64.sys driver used by peripherals or internal components with RGB lighting. The company is deploying a block that disables the driver on affected consumer and unmanaged business devices and has provided a registry workaround for enterprise administrators.
read more โ†’

AWS Security: July 2026 updates and guidance

๐Ÿ›ก๏ธ This recap highlights AWS Security blog posts, new capabilities, code samples, and guidance published in July 2026. Topics include AI agent security, data protection, network and infrastructure protections, threat detection enhancements, compliance guidance, and 21 security bulletins addressing vulnerabilities. Vendors and practitioners can use the code samples and workshops to implement recommended controls and apply patches promptly.
read more โ†’

Ubiquiti fixes three maximum-severity vulnerabilities

๐Ÿ”’ Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more โ†’

Amazon RDS Adds Support for SQL Server 2025 CU6

๐Ÿ”” Amazon RDS for SQL Server now supports the latest Microsoft cumulative update: SQL Server 2025 CU6 (KB5093421) as RDS version 17.00.4055.5.v1. This update brings the fixes and improvements detailed in Microsoft's KB5093421. AWS recommends upgrading RDS instances using the Amazon RDS Management Console, AWS SDK, or CLI. Refer to the Amazon RDS SQL Server User Guide for detailed upgrade instructions.
read more โ†’

Amazon RDS for Oracle July 2026 Release Update

๐Ÿ›ˆ Amazon RDS for Oracle now supports the Oracle July 2026 Release Update (RU) for Oracle Database versions 19c, 21c, and 26ai. The update includes security fixes and a revised naming format for 19c RUs: 19.0.0.0.ru-2026-07.mrp-2026-07.r1. You can apply the RU via the RDS console, AWS SDK/CLI, or enable Automatic Minor Version Upgrade. AWS Organizations upgrade rollout policy can stagger and validate upgrades across environments.
read more โ†’

Amazon Aurora adds minor PostgreSQL updates

๐Ÿ”” Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 bringing community bug fixes and Aurora-specific improvements. Automatic minor version upgrades can be applied during scheduled maintenance windows and can be orchestrated across accounts using the AWS Organizations Upgrade Rollout Policy. Enable automatic upgrades to address known CVEs and simplify large-scale operations. Aurora continues to offer high performance, global resilience, serverless scale-to-zero compute, and improved I/O price-performance.
read more โ†’

August .NET updates break WPF printing and PDF export

๐Ÿ› ๏ธ Microsoft confirmed that August 2026 .NET Framework cumulative updates are causing some Windows Presentation Foundation (WPF) applications to fail with a System.IO.FileFormatException when printing or generating PDF/XPS content using certain fonts such as Calibri. The issue affects multiple client and server Windows releases, and Microsoft provided a temporary AppContext switch workaround that must be added to the application config file. The company warns this workaround disables protections added in the update and should be used only temporarily while a permanent fix is developed.
read more โ†’

Critical Keycloak password reset vulnerability patched

๐Ÿ”’ Red Hat and the Keycloak project released patches to fix a critical flaw (CVE-2026-18963) that allows an unauthenticated remote attacker to take over user accounts by forcing a password reset. Upstream Keycloak users should update to 26.7.2 (released Aug 19, 2026); Red Hat build customers must apply fixes for 26.4.15 and 26.6.6. Red Hat rates the issue 9.1 CVSS and recommends disabling the "Forgot password" feature as a temporary mitigation while upgrading.
read more โ†’

Cisco issues patches for Crosswork and Secure Workload

๐Ÿ”’ Cisco released security updates for its Crosswork platforms and Secure Workload software following an internal review. Four critical flaws affecting Crosswork (including SQL injection and missing authentication) were fixed in Crosswork 7.2.1-SP. Five vulnerabilities impacting Secure Workload (SaaS and on-premises) were remediated in releases 3.10.9.1 and 4.0.4.16. Customers are urged to apply updates despite no known active exploitation.
read more โ†’

Citrix issues critical patches for NetScaler gateways

๐Ÿ”’ Citrix has released critical updates for customer-managed NetScaler ADC and NetScaler Gateway to address two serious vulnerabilities: a memory overflow that can cause unpredictable behavior or denial of service, and an authentication bypass that permits pre-authentication access. Supported on-premises builds and certain deployments are affected while Citrix-managed services have been updated; cloud marketplace images may still need manual replacement. Security experts urge immediate emergency patching, credential rotation, session termination, and active hunting due to the high risk of rapid weaponization against internet-facing gateways.
read more โ†’

Citrix NetScaler critical authentication bypass patched

๐Ÿ›ก๏ธ Citrix released patches for two NetScaler ADC and Gateway flaws, including a critical authentication bypass affecting certain appliance configurations. The issues impact customer-managed NetScaler ADC/Gateway, some FIPS/NDcPP builds, and SecurAccess ZTNA Hybrid using customer-managed instances, but not Citrix-managed cloud services. Administrators should verify configurations and apply updates for affected versions to mitigate risk.
read more โ†’

Citrix issues urgent NetScaler security update advisory

๐Ÿ”’ Citrix warned customers to immediately patch two NetScaler vulnerabilities impacting NetScaler Gateway and NetScaler ADC appliances. The most severe, CVE-2026-19490, can allow remote attackers to bypass authentication when SAML action is configured on certain AAA, Auth, or VPN virtual servers. The other, CVE-2026-19489, is a high-severity memory overflow that can enable remote DoS when SIP ALG is enabled on large-scale NAT group configurations. Citrix published recommended firmware builds and urged immediate upgrades for affected deployments.
read more โ†’

Microsoft fixes Windows Defender crash bug

๐Ÿ›ก๏ธ Microsoft resolved a bug causing Windows Defender to crash with 0xc0000005 access violation errors after a recent signature update. Affected users on Windows 10 and Windows 11 reported scan failures and service stoppages that in some cases led to system reinstalls. Microsoft says the issue is fixed in Microsoft Defender Antivirus signature update version 1.457.236.0 or later and recommends applying updates or enabling automatic updates. Users should check Windows Update and their security intelligence version to ensure the fix is applied.
read more โ†’