Topic: patch deployment
-
CISA orders feds to patch exploited Ivanti zero-day in 4 days
CISA has issued an urgent directive requiring federal agencies to patch a high-severity Ivanti zero-day vulnerability (CVE-2026-6973) within four days, as it is being actively exploited in attacks against Ivanti Endpoint Manager Mobile (EPMM) versions 12.8.0.0 and earlier. The vulnerability allow...
Read More » -
CISA Orders Urgent Patch for Actively Exploited Fortinet Flaws
CISA has added two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) to its Known Exploited Vulnerabilities catalog, with a CVSS score of 9.1, and is requiring federal agencies to patch by July 19. CVE-2026-39808 is an OS command injection flaw in FortiSandbox versions 4.4...
Read More » -
Libraesva ESG Zero-Day Exploited in Active Attacks (CVE-2025-59689)
A critical zero-day vulnerability (CVE-2025-59689) in the Libraesva Email Security Gateway is being actively exploited by a suspected state-sponsored actor, allowing arbitrary command execution on affected systems. The flaw is a command injection vulnerability caused by improper input sanitizatio...
Read More » -
Active Attack Exploits Critical Adobe Commerce, Magento Flaw
Security researchers have identified active exploitation of a critical Adobe Commerce and Magento vulnerability (CVE-2025-54236, SessionReaper), which allows attackers to hijack customer accounts and potentially execute remote code, with over 250 attack attempts blocked in a single day. The vulne...
Read More » -
Over 1,200 IceWarp Servers Exposed to Critical RCE Flaw
A critical remote code execution vulnerability (CVE-2025-14500) in IceWarp software puts over 1,200 internet-facing servers at immediate risk, requiring urgent patching. The flaw is an unauthenticated OS command injection that grants attackers full system control, and patches have been available ...
Read More » -
Chrome could update instantly without a restart
Google is shifting from rapid-release updates to potentially twice-weekly patches due to a surge in bug fixes driven by AI-powered security analysis, aiming to keep Chrome secure without disrupting users. Chrome 149 and 150 together addressed 1,072 bug fixes, surpassing the total of the previous ...
Read More » -
Hidden Device in US Cars Creates Hacking Risk - Update Now
Security researchers at UC San Diego discovered that the KARR Security System, an aftermarket car alarm installed in about 2 million US vehicles, has a severe Bluetooth vulnerability allowing hackers to unlock, disable, track, or immobilize the car. The devices are typically installed by car deal...
Read More » -
Urgent Microsoft WSUS Flaw Actively Exploited After Patch
A severe security vulnerability (CVE-2025-59287) in Microsoft's WSUS allows unauthenticated remote code execution with SYSTEM privileges, prompting an urgent out-of-band patch due to incomplete initial fixes. The flaw arises from unsafe deserialization via BinaryFormatter in the `GetCookie()` end...
Read More » -
CISA Mandates Urgent Patch for Actively Exploited Gogs Flaw
A critical remote code execution flaw (CVE-2025-8110) in Gogs is being actively exploited, allowing attackers to run arbitrary commands by manipulating Git configuration files. CISA has mandated all federal agencies to patch the vulnerability by February 2026, as over 1,400 public Gogs servers ar...
Read More » -
Linux Distros at Risk: Chaining 2 LPEs for Root Access (CVE-2025-6018/19)
Two critical Linux vulnerabilities (CVE-2025-6018 and CVE-2025-6019) allow attackers to gain full system control by chaining exploits, affecting major distributions like Ubuntu and openSUSE. CVE-2025-6018 misconfigures PAM to grant remote attackers local user privileges, while CVE-2025-6019 explo...
Read More » -
Google Issues Emergency Chrome Update for 2 Billion Users
Google has issued an emergency security patch for Chrome to address a high-severity vulnerability (CVE-2025-13223) that is already being actively exploited, allowing attackers to execute arbitrary code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its Kn...
Read More » -
Apple Patches Hide My Email Flaw After Report
Apple fixed a Hide My Email vulnerability in July 2026 after being aware of it for over a year, which could have exposed users' real email addresses when emails were rejected as spam. The flaw was discovered by Tyler Murphy, who found that 100% of tested Hide My Email addresses were exploitable, ...
Read More » -
Google Patches Actively Exploited Chrome Zero-Day Flaws
Google has urgently patched two actively exploited Chrome vulnerabilities (CVE-2026-3909 & CVE-2026-3910) and advises users to update immediately. The flaws involve an out-of-bounds write in the Skia graphics library and an inappropriate implementation in the V8 JavaScript engine, both posing ser...
Read More »