< ciso
brief />
Tag Banner

All news with #patch release tag

502 articles · page 2 of 26

Amazon Corretto August 2026 Security Updates

🔔 Amazon announced critical security patch updates for multiple Amazon Corretto distributions on Aug 18, 2026. The release includes Corretto 26.0.2.11.1, 25.0.4.8.1, 21.0.12.9.1, 17.0.20.10.1, 11.0.32.10.1, and 8u504. Amazon Corretto is a free, production-ready OpenJDK distribution available across platforms, and updates can be obtained via the Corretto homepage or by configuring Apt, Yum, or Apk repos. Feedback is welcomed.
read more →

Critical GeoServer SQL Injection Now Patched

🛡️ A critical SQL injection zero-day in GeoServer was disclosed on August 12, 2026, and saw active exploitation attempts within hours, according to watchTowr. The flaw, tied to the jsonArrayContains function in PostGIS DataStore, could lead to remote code execution under certain configurations and remained initially unpatched. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to remediate the issue, which carries a CVSS score of 9.8.
read more →

Microsoft patches LegacyHive Windows zero‑day

🛡️ Microsoft released patches addressing the Windows zero-day dubbed LegacyHive, disclosed after July 2026 Patch Tuesday. The flaw was revealed by a researcher using the "Nightmare Eclipse" handle, who published a proof-of-concept after the updates; the exploit requires additional credentials, limiting easy weaponization. Microsoft tracked the issue as CVE-2026-62832 and describes the bug as improper link resolution in the Windows User Profile Service that can allow local privilege escalation. ACROS Security also issued unofficial mitigations prior to Microsoft's August fixes.
read more →

Adobe issues urgent patches for critical ColdFusion flaws

🔒 Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

Cisco ASA and FTD HTTP DoS Flaw Exploited

🛡️ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more →

Windows 10 KB5120249 August 2026 Patch Update

🛡️ Microsoft released the Windows 10 KB5120249 Extended Security Updates (ESU) for 22H2 and 21H2, delivering the August 2026 Patch Tuesday fixes. The update is mandatory and raises OS Builds to 19045.7663 and 19044.7663. Install via Start > Settings > Update & Security > Windows Update or download from the Microsoft Update Catalog. The patch resolves a File History SMB backup failure and expands rollout of new Secure Boot certificates.
read more →

Windows 11 August 2026 cumulative updates released

🔔 Microsoft released Windows 11 cumulative updates KB512103 and KB5120240 for 25H2/24H2 and 23H2 to address security flaws, fix bugs, and add features. These August 2026 Patch Tuesday updates include fixes for roughly 400 vulnerabilities and are delivered via Windows Update or the Microsoft Update Catalog. Notable additions include improved Windows Search typo handling, Voice Access enhancements, touchpad gestures, and extended Windows Hello ESS support for peripheral fingerprint sensors.
read more →

Mozilla rotates GPG signing key after accidental exposure

🔐 Mozilla updated the GPG subkey used to sign Firefox and Thunderbird artifacts after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. The organization says the exposure risk is low because repository access was limited and its audit found no evidence of unauthorized access. Mozilla revoked the old key, published the new public key and revocation, and provided instructions for users who manually verify signatures or use RPM-based Linux distributions.
read more →

N‑able Issues Hotfixes After Active N‑central Exploitation

🔒 N‑able has issued Hotfix 2 for N‑central after detecting active exploitation of a recently disclosed RMM server vulnerability (CVE-2026-18577) first observed on July 31, 2026. The company says Hotfix 2 supersedes Hotfix 1 and provides additional hardening; on-prem customers must update to 2026.3.1.10 immediately. A limited set of customers were affected, and N‑able published IoCs plus a custom service template to scan Windows endpoints, while cautioning that results are not a guarantee of full remediation.
read more →

Critical LoadMaster Command Injection Added to CISA KEV

🔒 CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaw, rooted in improper input handling in an escape_quotes() function, allows unauthenticated attackers to execute arbitrary commands on affected appliances. Agencies are urged to apply patches immediately under BOD 26-04 to mitigate ongoing attacks.
read more →

WordPress pre-auth XSS patched in 7.0.3 release

🔒 WordPress patched a pre-auth reflected XSS in the login screen (CVE-2026-64638) that requires no attacker privileges and can execute JavaScript when a crafted username reaches the failed-login page. Researchers at pwn.ai demonstrated chaining the XSS to PHP code execution if an Administrator interacts with an attacker-controlled page, and WordPress issued fixes on August 6 across supported branches.
read more →

18-year Linux SCTP flaw lets attackers escalate root

🛡️ A long-standing use-after-free bug in Linux's SCTP implementation, tracked as CVE-2026-64564 and called SCTPhantom, can be exploited to achieve local privilege escalation and, according to Tencent Zhuque Lab, to escape containers and reach the host. Stable kernel fixes (7.1.6, 6.18.42, 6.12.101 and 6.6.148) were released on August 3. Systems with reachable SCTP should apply vendor updates or disable the module if unused.
read more →

Cisco releases critical SD‑WAN and IOS XE fixes

🔒 Cisco issued patches for multiple critical vulnerabilities in Catalyst SD‑WAN and IOS XE Software discovered during an internal security review. The flaws—ranging from improper input validation and access control to command injection—affect many releases and have been fixed across several patched versions. Cisco noted these were found during testing, including use of frontier AI models, and are not known to be actively exploited, urging customers to update promptly.
read more →

Critical patches issued for Veeam, HashiCorp, and Django

🔒 Vendors HashiCorp, Veeam, and the Django Software Foundation have released fixes for 11 vulnerabilities affecting Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe include an unauthenticated credential-exposure bug in Veeam (9.5), a cross-tenant token-reuse issue in Terraform MCP (10.0), and a GeoDjango spatial lookup flaw that can write files or trigger code execution. Operators are advised to upgrade to Terraform MCP Server 1.1.0+, Veeam 9.3.0.35057, and Django 6.0.8 / 5.2.17; exposure depends on configuration and none of the flaws show public exploitation as of August 5, 2026.
read more →

Critical Gitea file-read flaw patched in 1.27.1

🔒 An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1–1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
read more →

cPanel fixes critical DB privilege escalation bug

🔒 cPanel issued a targeted security release addressing a database privilege escalation flaw (CVE-2026-58048) that allowed an authenticated cPanel account with MySQL/MariaDB access to execute SQL in the administrative database context. The update also patches an HTTP request-smuggling issue in cpsrvd (CVE-2026-58047) and multiple Exim vulnerabilities; temporary workarounds are available for systems that cannot immediately upgrade. Administrators should apply the listed builds or revoke MySQL access until patched.
read more →

Thermo Fisher patches DNA data file tampering flaw

🔒 Thermo Fisher Scientific issued a July 31 security bulletin addressing a vulnerability in select Applied Biosystems human identification software that could allow .fsa and .hid files to be modified before analysis. The issue is tracked as CVE-2026-17583 with a High severity (CVSS v4.0 8.2). Five supported product lines received updates that add digital signatures, while three end-of-life products will receive no fixes. The vendor urges customers to install updates or follow recommended controls for file custody, access, and network restrictions.
read more →

Rails fixes critical Active Storage flaw with RCE risk

🛡️ The Rails project patched a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files and potentially achieve remote code execution when libvips is used. The flaw affects multiple Rails branches before specified patch releases and requires accepting uploads from untrusted users. Administrators should upgrade libvips to 8.13+, apply Rails updates, and rotate exposed secrets. ImageMagick users are not affected by this vector.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →