< ciso
brief />
Tag Banner

All news with #patch release tag

502 articles · page 3 of 26

Broadcom issues patches for multiple VMware flaws

🔒 Broadcom has released patches addressing five vulnerabilities across multiple VMware products, with three rated as critical. Affected products include vCenter, ESX, Workstation, Fusion, and various cloud and telco platforms. Issues range from authentication bypass and out-of-bounds write enabling remote code execution to syslog-related arbitrary code execution. Administrators should apply fixes from Broadcom's advisory promptly.
read more →

Google fixes over a thousand Chrome vulnerabilities

🔒 Google disclosed fixes for 1,072 security bugs across Chrome 149 and 150, and an additional 370 in Chrome 151, including seven critical issues. The company attributes a surge in discoveries to AI-assisted techniques and is shifting to faster release cadences and automated tooling to shorten disclosure and patch windows. Google is also piloting dynamic patching, session-preserving restarts, and moves toward memory-safe languages like Rust to reduce entire classes of C++-origin vulnerabilities.
read more →

Critical TeamCity RCE Patch Urged for On‑Prem Servers

🔒 JetBrains warned of a critical pre-authentication vulnerability in TeamCity On‑Premises that could allow unauthenticated HTTP(S) requests to bypass authentication and execute arbitrary OS commands. Tracked as CVE-2026-63077 and rated 9.8, the flaw affects all on‑prem deployments and has been fixed in versions 2025.11.7 and 2026.1.3. Customers unable to upgrade can apply a security patch plugin; TeamCity Cloud customers need take no action.
read more →

VMware patches critical auth bypass and VM escape flaws

🔒 Broadcom released emergency security updates for VMware vCenter, ESX, Workstation, and Fusion to address five vulnerabilities, including three critical flaws that allow authentication bypass, remote code execution, and VM escape. Affected products include VMware Cloud Foundation and various telco platform offerings; administrators should assume prepatched versions are vulnerable and apply fixes immediately. There are no effective workarounds, and some updates require service interruptions or host reboots.
read more →

Google credits AI for surge in Chrome vulnerability fixes

🔒 Google reports that AI has enabled Chrome to patch 1,072 security bugs across Chrome 149 and 150, exceeding the total fixed in the prior 23 milestones combined. The company uses large language models across the vulnerability lifecycle—from discovery and repro to patch generation and testing—and has developed multi-agent systems like Naptime and Big Sleep. Google is also accelerating updates with tighter release cycles and exploring dynamic patching to reduce the window between fix commit and user update.
read more →

Google Chrome fixes 370 vulnerabilities in update

🔒 Google’s Chrome team released version 151 (Windows, Mac and Linux) addressing 370 vulnerabilities, including seven critical flaws. The critical issues include several use after free bugs across Compositing, Views, Skia and Ozone, plus validation flaws in Dawn and ANGLE and a race condition in the Updater. These were reported between 18 May and 14 June 2026. The update also patches 71 high, 170 medium and 122 low severity issues, with researchers awarded $58,500 via the bug bounty.
read more →

Windows 11 KB5101684 preview brings 42 fixes

🔔 Microsoft released the optional KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, delivering 42 bug fixes and incremental feature rollouts. This non-security monthly preview updates systems to builds 26100.8973 and 26200.8973 and is installable via Settings > Windows Update or the Microsoft Update Catalog. Notable changes include File Explorer improvements, Voice Isolation for Voice Access, enhanced Windows Hello ESS support for external fingerprint readers, and fixes for File History and MDM enrollment issues. The update is optional and currently has no known issues.
read more →

Critical Gitea RCE in diffpatch fixed in 1.27.1

🔒 Gitea patched a critical remote code execution (RCE) vulnerability tracked as CVE-2026-60004 affecting versions 1.17 through 1.27.0. A user with repository write access could craft a malicious patch that becomes an active Git hook and executes shell commands as the Gitea service account. The flaw requires authentication and write permission, but default open registration allows outsiders to create accounts and exploit unpatched instances. Upgrading to 1.27.1 addresses the issue; Gitea Cloud upgrades were scheduled automatically.
read more →

Arista fixes critical VeloCloud Orchestrator flaw

🔒 Arista has released patches for a critical vulnerability in VeloCloud Orchestrator (VCO) that is actively being exploited in the wild. The vendor warned the flaw may allow remote attackers to access privileged internal functionality and impact VCO hosts, affecting confidentiality, integrity, and availability. Customers are urged to upgrade to fixed releases (VCO 5.2.3.14+, 6.1.3.4+, 6.4.2.4+) and to consider incident response actions such as credential rotation and device validation. Advisors stressed the severity—an unauthenticated command‑injection in an orchestration platform—and warned that on‑premises users often receive fixes more slowly than cloud deployments.
read more →

vBulletin fixes pre-auth RCE; public exploit published

🛡️ A critical pre-authenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x up to 5.7.5 and 6.2.1 allowed attackers to execute arbitrary PHP via template rendering. Researcher Egidio Romano reported the flaw via SSD Secure Disclosure and published a technical analysis and PoC showing the issue stems from improper input sanitization in runMaths(), which forwards data to PHP's eval(). vBulletin released patched 6.2.2 and backported fixes as Patch Level 1; users on older 5.x builds are advised to upgrade.
read more →

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →

Arista patches VeloCloud Orchestrator zero-day exploit

🔒 Arista released fixes for a maximum-severity unauthenticated command injection in on-premises VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited. The flaw allows remote attackers network access to the VCO web interface to execute privileged commands without credentials, potentially impacting confidentiality, integrity, and availability. Affected on-premises versions include 5.2.x, 6.1.x, 6.4.x and early 7.0.x releases; hosted and dedicated deployments are already patched. Administrators are urged to apply the provided updates, restrict VCO web access, block listed malicious IPs, and review logs for signs of compromise.
read more →

Redis fixes multiple authenticated RCE paths via RESTORE

🔒 Redis issued seven security releases on July 23 after published PoCs demonstrated authenticated remote code execution chains against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All exploit chains require RESTORE; Streams chains also need EVAL and XGROUP, while the 8.8.0 chain needs EVAL plus the bundled RedisBloom module. Users should upgrade to the fixed branch and, until then, revoke RESTORE from unnecessary accounts and block untrusted network access.
read more →

Check Point patches SmartConsole zero-day exploit

🔒 Check Point has released a patch for an actively exploited SmartConsole zero-day (CVE-2026-16232) that permits unauthenticated attackers to obtain an application login token and authenticate with administrator privileges. Successful exploitation requires the Management Server to be reachable from the Internet and Trusted Clients not being restricted, allowing attackers to alter security configurations and policies. The vendor urged affected customers to apply updates and recommended mitigations, while CISA has added the flaw to its known exploited vulnerabilities catalog and ordered federal agencies to patch by July 25.
read more →

Zimbra update fixes nine critical vulnerabilities

🔒 Zimbra Collaboration Suite 10.1.20 addresses nine vulnerabilities across commercial and open-source editions, including a permanent fix for an SNMP command injection flaw and four XSS issues in the Classic Web Client. The update also patches mailbox delegation and EWS access control problems, an SSRF in Nextcloud integration, and a bypass for email forwarding restrictions. Synacor urges administrators to upgrade promptly to prevent exploitation by threat actors.
read more →

Amazon Corretto July 2026 Quarterly Updates

🛡️ Amazon announced quarterly security and critical updates for Amazon Corretto on July 22, 2026, releasing Corretto 26.0.2, 25.0.4, 21.0.12, 17.0.20, 11.0.32, and 8u502. The Corretto distribution remains a no-cost, multi-platform production-ready build of OpenJDK. Default Docker images now use Amazon Linux 2023 while Amazon Linux 2 remains available as a non-default option. JavaFX binaries are no longer included with Corretto 8; migration guidance is provided on GitHub.
read more →

Zimbra issues patch for critical SNMP command flaw

🔧 Zimbra released version 10.1.20 to address nine vulnerabilities, led by a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The update also fixes four cross-site scripting (XSS) issues in the Classic Web Client and a mail forwarding restriction bypass (CVE-2026-50055) reported by Jonah Burgess. The vendor limited details per industry best practices and urged customers to apply the fixes promptly.
read more →

Microsoft issues WSUS sync fix and manual mitigation

🛠️ Microsoft published manual steps to remediate a WSUS synchronization problem that causes Windows Update scans to fail or time out on affected servers. The issue affects client (Windows 10, v1607+) and server (Windows Server 2012+) platforms and leads to prolonged sync times or operation timeouts due to accumulating publishing metadata. A service-side mitigation was rolled out for new or rebuilt WSUS installations, while administrators with existing servers are advised to back up SUSDB, run cleanup SQL queries, reset MaxXMLPerRequest, reindex SUSDB, run the WSUS Server Cleanup Wizard, and restart IIS or the WsusPool to restore normal sync behavior.
read more →

Amazon RDS adds latest CU and GDR for SQL Server

🔔 Amazon RDS now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for Microsoft SQL Server, including specific builds for SQL Server 2016 SP3, 2017, 2019, and 2022. The GDR updates address vulnerabilities detailed in CVE-2026-40370. AWS recommends upgrading RDS for SQL Server instances via the Amazon RDS Management Console, AWS SDK, or CLI to apply these security and stability updates. See the Amazon RDS SQL Server User Guide for upgrade instructions.
read more →

7‑Zip XZ Vulnerability Fixed in 26.02 Update

🛡️ 7‑Zip 26.02 fixes CVE-2026-14266, a heap-based buffer overflow in its XZ decoder that can lead to code execution when a crafted XZ archive is opened. ZDI disclosed the flaw on July 15 after it was reported June 5; the patch shipped June 25. Exploitation requires the victim to open a malicious file, and on Windows the code runs with 7‑Zip's process token, not elevated privileges. Users should manually update to 26.02 or later, and vendors bundling 7‑Zip must issue their own fixes.
read more →