< ciso
brief />
Tag Banner

All news with #patch tuesday tag

190 articles · page 2 of 10

CISA Adds Five Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The issues include improper authorization and authentication flaws in Artifactory, a privilege management bypass in ScreenConnect, and two critical RouterOS bugs enabling kernel memory disclosure and privilege escalation. Federal agencies have specific patch deadlines in September 2026 to mitigate these risks.
read more →

Microsoft September Patch Tuesday Sets New Record

🛡️ Microsoft released a record 974 CVE fixes in its September 2026 Patch Tuesday, far surpassing the previous monthly high of 570. The update affects a broad range of products, with Windows accounting for 723 CVEs and Office 111. Microsoft highlighted two actively exploited zero-days and the bundle includes 119 critical vulnerabilities, prompting calls for a risk-based approach to prioritization.
read more →

Microsoft issues record Patch Tuesday fixes

🛡️ Microsoft released an unprecedented Patch Tuesday fixing 974 vulnerabilities across its product portfolio, including two actively exploited zero-days. The updates span Windows, Office, SQL Server, and developer tools, with over 110 rated critical and many tied to privilege escalation, remote code execution, and information disclosure. CISA added the two exploited flaws to its KEV catalog, mandating federal remediation by September 22, 2026.
read more →

Microsoft Patch Tuesday: September 2026 Vulnerabilities

🔒 Microsoft released its September 2026 security update covering 973 vulnerabilities across many products, including 113 marked critical. Two vulnerabilities were reported exploited in the wild: one in the Windows Update Stack (CVE-2026-81963) and one in Windows ALPC (CVE-2026-85880). The bulletin highlights numerous remote code execution and elevation-of-privilege issues, with several high CVSS scores and multiple components prioritized for remediation.
read more →

Microsoft issues record Windows security patch batch

🔒 Microsoft released updates addressing at least 974 security vulnerabilities across Windows and other products, its largest single patch bundle ever. Two zero-day vulnerabilities are being actively exploited, and 113 bugs were rated critical. Vendors attribute rising patch volumes to AI-assisted discovery, while security teams warn of the burden of testing and deploying so many fixes. Administrators are urged to prioritize and test patches carefully to avoid disruption.
read more →

Nearly 22,000 Exchange Servers Exposed to Hijack Bug

🔒 Tracked as CVE-2026-62911, a high-severity authentication bypass in Microsoft Exchange Server 2016, 2019, and SE allows attackers with basic privileges to hijack all user mailboxes via low-complexity, user-interaction attacks. Microsoft patched the flaw in August 2026 Patch Tuesday, but Shadowserver found 21,899 exposed IPs still unpatched, predominantly in the US and Germany. Authorities including NCSC-NL and Germany's BSI warn that exploit code is public and urge immediate updates or isolation of affected servers, especially as ESU updates for older Exchange versions end in October 2026.
read more →

CISA Adds Six Exploited Flaws, Urges Immediate Patching

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, urging prompt patching by government agencies and critical infrastructure. Two high-severity flaws—CVE-2026-8452 in Citrix NetScaler and CVE-2019-1068 in Microsoft SQL Server—carry CVSS scores of 8.8 and require immediate attention. Citrix has published updates to address the NetScaler memory overflow, while the SQL Server RCE remains actively exploited despite a seven-year-old patch. CISA set accelerated patch deadlines for the critical and other listed flaws.
read more →

CISA directs urgent patching for Citrix NetScaler RCE

🔒 CISA has ordered federal agencies to patch Citrix NetScaler appliances by Saturday due to an actively exploited vulnerability, CVE-2026-8452. The flaw is a memory overflow affecting NetScaler ADC and Gateway appliances configured with Gateway VPN or AAA virtual servers and can lead to unpredictable behavior, DoS, or remote code execution. Researchers have observed active exploitation in attacks deploying web shells, and Citrix's advisory has not yet acknowledged in-the-wild targeting. Shadowserver currently tracks thousands of exposed NetScaler instances online.
read more →

Microsoft issues temporary fix for Windows 11 gaming bug

🎮 Microsoft provided a temporary workaround for a gaming crash issue introduced with the August 11, 2026 Windows 11 updates (KB5121003). The bug caused crashes, freezes, EXCEPTION_ACCESS_VIOLATION errors, and restarts when launching certain games on 24H2 and 25H2 systems. Investigation linked the problem to RGB device drivers/components, specifically files like inpoutx64.sys. Microsoft’s interim fix disables the driver via a Registry change, with warnings to back up and potential loss of RGB functionality.
read more →

CISA orders federal patching for TrueConf flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more →

Microsoft August Windows Update Causing Game Crashes

🎮 Microsoft is investigating reports that August 2026 updates may prevent some games from launching or cause crashes on affected Windows 11 systems. Affected users report freezes, unexpected closures, EXCEPTION_ACCESS_VIOLATION errors, and random restarts after installing KB5121003. The company confirmed it is probing the issue and asked impacted gamers to submit Feedback Hub reports while it works to determine if Microsoft is the cause.
read more →

Critical Windows IKE Extension Flaw Actively Exploited

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are exploiting a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824. The vulnerability affects supported Windows 10, Windows 11, and Windows Server versions and can be triggered by unauthenticated attackers sending crafted packets to UDP ports 500 or 4500. Microsoft issued a Patch Tuesday advisory and recommended firewall mitigations for organizations that cannot immediately apply updates.
read more →

Windows 11 24H2 Home and Pro reach end of support

🛡️ Microsoft warned that Windows 11 version 24H2 Home and Pro editions will stop receiving security and preview updates on October 13, 2026. Enterprise and Education editions of 24H2 remain supported until October 2027, and Microsoft recommends upgrading to Windows 11 25H2, widely available since September 2024. unmanaged Home and Pro devices will auto-upgrade to 25H2, though users can postpone restarts; administrators should use Settings > Windows Update to check availability.
read more →

Microsoft patches 400 vulnerabilities in August update

🔒 Microsoft released its August Patch Tuesday addressing 400 CVEs, including one actively exploited zero-day and two publicly disclosed zero-days. The exploited flaw, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock that can allow local low-privileged attackers to gain system privileges. Other notable fixes include EoP issues in the User Profile Service (CVE-2026-62832) and a Windows Container Isolation FS Filter Driver tampering flaw (CVE-2026-72971). Organizations without automated, risk-based patching will face challenges prioritizing these updates.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

Microsoft Patch Tuesday — August 2026 Update Summary

🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
read more →

Microsoft issues massive August security patch bundle

🔒 Microsoft released updates addressing 398 security vulnerabilities across Windows and related software in its August Patch Tuesday, including one actively exploited zero-day and two publicly disclosed flaws. The company rated 42 of the fixes as critical, and attributed the flood of discoveries to AI-assisted vulnerability research. Experts caution that AI may accelerate bug finding but human oversight remains essential for safe, effective patching.
read more →

Microsoft patches 398 vulnerabilities, including active zero-day

🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
read more →

Windows 10 KB5120249 August 2026 Patch Update

🛡️ Microsoft released the Windows 10 KB5120249 Extended Security Updates (ESU) for 22H2 and 21H2, delivering the August 2026 Patch Tuesday fixes. The update is mandatory and raises OS Builds to 19045.7663 and 19044.7663. Install via Start > Settings > Update & Security > Windows Update or download from the Microsoft Update Catalog. The patch resolves a File History SMB backup failure and expands rollout of new Secure Boot certificates.
read more →

Windows 11 August 2026 cumulative updates released

🔔 Microsoft released Windows 11 cumulative updates KB512103 and KB5120240 for 25H2/24H2 and 23H2 to address security flaws, fix bugs, and add features. These August 2026 Patch Tuesday updates include fixes for roughly 400 vulnerabilities and are delivered via Windows Update or the Microsoft Update Catalog. Notable additions include improved Windows Search typo handling, Voice Access enhancements, touchpad gestures, and extended Windows Hello ESS support for peripheral fingerprint sensors.
read more →