Topic: software patching
-
ScreenConnect Zero-Day Now Under Active Attack
CISA confirmed that threat actors are actively exploiting CVE-2026-84869, a critical zero-day vulnerability in ConnectWise’s ScreenConnect software that allows unauthorized file transfers and execution. Over 1,000 exposed instances have been tracked globally, continuing a pattern of active exploi...
Read More » -
Shell probes cyber incident after Clop data theft claims
Shell is investigating a potential security breach after the Clop ransomware group claimed to have stolen 89GB of data, including engineering schematics and project documentation, from the energy giant. The attack is linked to exploitation of a critical vulnerability (CVE-2026-12569) in PTC Windc...
Read More » -
Zoom Screen-Sharing Bug Enabled Full Device Takeover on Calls
Researchers discovered critical vulnerabilities in Zoom's screen-sharing annotation protocol that could allow silent, zero-interaction takeover of any participant's device during a call, affecting all supported platforms. The flaws were found using publicly accessible AI models in fewer than 20 p...
Read More » -
KindaRails2Shell exploit targets Ruby on Rails apps (CVE-2026-66066)
CVE-2026-66066, dubbed "KindaRails2Shell," is a critical Ruby on Rails vulnerability in Active Storage that lets unauthenticated attackers read arbitrary server files via specially crafted image uploads, potentially escalating to remote code execution. The flaw affects Rails apps using the defaul...
Read More » -
Zimbra urges customers to patch critical XSS web client flaw
Zimbra has disclosed a critical cross-site scripting (XSS) vulnerability in its Classic Web Client that requires no authentication to exploit, potentially allowing attackers to steal session tokens, compromise accounts, or access sensitive data. The company urges all customers to immediately upgr...
Read More » -
Oracle EBS Payments Flaw Actively Exploited (CVE-2026-46817)
A critical vulnerability in Oracle Payments (CVE-2026-46817, CVSS 9.8) is being actively exploited, allowing unauthenticated remote attackers to compromise the Oracle E-Business Suite without credentials. Multiple automated exploitation attempts were detected over the weekend, targeting vulnerabl...
Read More » -
Critical SimpleHelp RMM bug CVE-2026-48558 exposes endpoints to takeover
A critical unauthenticated vulnerability (CVE-2026-48558) in the SimpleHelp RMM platform allows attackers to remotely create a "Technician" account, enabling full control over managed networks and endpoints. The flaw requires no authentication or user interaction, and due to SimpleHelp's deep sys...
Read More » -
Ivanti Sentry critical flaw enables root-level code execution
Ivanti released security updates for two critical vulnerabilities in its Sentry secure mobile gateway; the most severe, CVE-2025-22467, is a buffer overflow flaw with a CVSS score of 10.0 that allows unauthenticated remote attackers to execute arbitrary code with root-level privileges. The second...
Read More » -
Critical Auth Bypass Flaw Found in Progress MOVEit Automation
Progress Software has issued an urgent advisory for a critical authentication bypass vulnerability (CVE-2024-5806, CVSS 9.1) in MOVEit Automation's SFTP module, affecting versions 2023.0 and earlier, requiring an immediate upgrade to version 2023.1 or later. The flaw allows unauthenticated attack...
Read More » -
OpenSSH Flaw Gave Full Root Access for 15 Years
A critical 15-year-old vulnerability in OpenSSH was discovered, originating from a code reuse bug where commas in certificate principals were mistakenly processed as list separators. The flaw allowed attackers to bypass authentication and gain full root shell access by manipulating certificate fi...
Read More » -
Claude Uncovers Decade-Old Apache ActiveMQ RCE Flaw
A critical, decade-old remote code execution vulnerability (CVE-2026-34197) was discovered in Apache ActiveMQ Classic with the aid of an AI assistant, requiring immediate patching despite no current known exploitation. The flaw's complexity, stemming from the interaction of multiple components, m...
Read More » -
CISA Mandates Federal Patch for Actively Exploited Zimbra Flaw
A critical, actively exploited security flaw (CVE-2025-66376) in Zimbra's Classic UI allows attackers to hijack sessions and steal data via malicious emails, prompting an urgent federal mandate. CISA has ordered all federal agencies to patch by April 1st and strongly advises all Zimbra users to d...
Read More » -
Critical Veeam Flaws Expose Backup Servers to RCE Attacks
Veeam has patched multiple critical vulnerabilities in its Backup & Replication platform that allow unauthorized remote code execution, posing a severe risk to enterprise backup servers. The flaws, which include four critical RCE issues, can be exploited by low-privileged users to run malicious c...
Read More » -
Critical RCE Flaw Found in BeyondTrust Remote Support Software
A critical pre-authentication command injection flaw (CVE-2026-1731) in BeyondTrust's Remote Support and Privileged Remote Access software allows unauthenticated attackers to remotely execute arbitrary commands. The vulnerability, impacting thousands of on-premises instances, requires immediate m...
Read More » -
Critical SmarterMail Flaw Actively Exploited by Ransomware Gangs
A critical SmarterMail vulnerability (CVE-2026-24423) is being actively exploited, allowing unauthenticated attackers to execute remote code via a flawed API endpoint. The flaw affects all SmarterMail versions before build 100.0.9511, prompting urgent federal patching mandates and warnings for al...
Read More » -
Hackers Still Exploit WinRAR Flaw, Mandiant Reports
A critical WinRAR vulnerability (CVE-2025-8088) is being actively exploited by state-sponsored and criminal hackers, despite a patch being available for over six months. The exploit hides malicious payloads within archive files to execute automatically upon user login, with attacks linked to a si...
Read More » -
Critical "Ni8mare" Bug Allows Hackers to Take Over n8n Servers
A critical, maximum-severity vulnerability (CVSS 10.0) in n8n allows unauthenticated remote attackers to take control of servers, posing a major risk due to the platform's widespread use and integration with sensitive enterprise systems. The flaw, named "Ni8mare," is a path traversal issue where ...
Read More » -
Hackers Target Unpatched Fortinet Flaws After Fix
Attackers are exploiting two critical authentication bypass vulnerabilities (CVE-2025-59718 & CVE-2025-59719) in Fortinet products, gaining administrative access to steal sensitive system configuration files. The theft of these configuration files poses a severe risk, exposing network details and...
Read More » -
Test Updates Safely: CyDeploy's System Replica at Disrupt 2025
CyDeploy creates a digital twin of critical systems using machine learning, enabling safe testing of updates to patch vulnerabilities without disrupting operations. The platform combines automated data capture with human oversight, allowing system administrators to verify accuracy and accelerate ...
Read More » -
Gladinet patches critical zero-day flaw in file-sharing software
Gladinet has released a critical security update for CentreStack to address CVE-2025-11371, a zero-day vulnerability that allowed attackers to bypass protections and execute remote code on systems. The flaw, discovered by Huntress, involved inadequate input sanitization enabling directory travers...
Read More »