Topic · 61 stories
Patch Tuesday and security updates: what to install
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Timeline
- NVIDIA DCGM Exporter Flaw Exposes GPU Servers to Denial of Service Security
- Atlassian’s 9.3-rated flaw exposes eight Data Center products Security
- FBI Removes Accenture Contractor After Unpatched System Led to Breach Privacy
- Dell patches critical System Update flaw allowing root access Security
- Asus patches router flaws allowing command execution via VPN configs Security
- TeamViewer urges immediate patching of five high-severity flaws Security
- OpenBao patches full unauthenticated RCE chain, Vault left unfixed Security
- Apple fixes zero-click iMessage EXR heap overflow as CVE-2026-86869 Security
- Avast kernel driver double-fetch flaw detailed as CVE-2025-13032 Security
- OxygenOS 16 flaws give untrusted apps root on OnePlus 15 Security
Show older (51 stories)
- BigDiskBuster PoC blocks Microsoft Defender updates on Windows Security
- Critical vCenter pre-auth flaws patched after one hits active exploitation Security
- CISA flags active exploitation of three Linux kernel flaws, one critical Security
- WordPress Click2Shell flaw enabled pre-auth PHP execution Security
- Check Point patches critical flaw allowing root code execution Security
- Docker patches Mac hypervisor sandbox escape Security
- Public exploits released for four Linux kernel root flaws Security
- SolarWinds patches hard-coded key in Access Rights Manager Security
- Parallels Desktop Bug Lets Any macOS Process Gain Root Security
- ConnectWise Patches ScreenConnect Flaw Used in Worm-Like Attacks Security
- Frappe LMS Flaws Chain Student Access to Remote Code Execution Security
- GitLab CVE-2026-85706 Exploited After 10.0 Severity Score Security
- Microsoft ships record 974 fixes, with two zero-days already exploited Security
- CISA confirms ransomware gangs are exploiting WatchGuard Firebox flaw Security
- Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites Security
- Core Lightning Issues Emergency Warning Over Real Vulnerabilities Found by AI Security
- Hackers exploit critical Gitea flaw in code injection attacks, CISA adds to KEV Security
- Critical Calix GigaSpire Flaw Allows Remote Firewall Takeover, No Patch Available Security
- WordPress SSO Plugin Under Active Attack; Paid Editions Were Invisible to Vulnerability Databases Security
- CISA Gives Agencies 3 Days to Patch Actively Exploited Zimbra Command Injection Flaw Security
- Apple patches 29 flaws across iPhone, iPad, and Mac Security
- CISA Warns Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw Security
- Microsoft emergency patch closes Windows zero-day exploited by Lazarus Group Security
- Docker cp Vulnerability Allows Container-to-Host Takeover, Patched in Latest Release Security
- OP-TEE Flaws Allow Heap Underwrite, DoS, and Use-After-Free in Secure World Security
- Insecure Deserialization in imgmgr.exe Bypasses Windows Application Control Security
- N-able issues hotfix for N-central ‘god mode’ flaw under active attack Security
- AI is finding Apple security flaws faster than Apple can sort through them Security
- Microsoft Overwhelmed by AI-Discovered Bugs as Anthropic’s Mythos Uncovers Hundreds of Vulnerabilities Security
- Researchers Find 36,872 Exposed Server Management Interfaces, Many Using 20-Year-Old Vulnerability Security
- wp2shell: Pre-Auth RCE in WordPress Core (CVE-2026-63030) Security
- Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches Security
- Zoom Warns of Critical Account Takeover Vulnerability Security
- Microsoft’s July Patch Tuesday Sets Record with 570 Fixes, Two Zero-Days Under Attack Security
- Forgotten UEFI Shims Undermining Secure Boot Security
- Smashing the ServiceNow Sandbox – Pre Authentication RCE Security
- Microsoft Urges Shorter Windows Update Deployment Timelines Due to AI Threats Security
- Microsoft Patches RoguePlanet Defender Zero-Day After Researcher Dispute Security
- Januscape Linux KVM Flaw Lets Guest VMs Take Over Host after 16 Years Security
- Ubiquiti Patches Maximum-Severity CVE-2026-50746 and Six Other Critical Flaws Security
- GhostLock Linux Kernel Exploit Grants Root in Five Seconds, Breaks Containers Security
- 16-Year-Old Linux Kernel Flaw Enables VM Escape on Intel and AMD Security
- Seiko SkyBridge IoT Routers Have Permanent OS Injection Flaw – No Patch Security
- Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws Security
- CitrixBleed Vulnerability Allows Memory Overread in NetScaler SAML Configuration Security
- Apple Rushes Security Patches Amid AI-Powered Hacking Risks AI
- Apple Rushes Security Fixes in Response to AI-Powered Threats Security
- DirtyClone Linux Kernel Exploit Published, Enables Stealth Root Access Security
- Secure Boot Certificates to Expire June 24 — Update Your Systems Now Security
- Microsoft Shatters Patch Tuesday Record With Nearly 200 Fixes and Three Zero-Days Security
- Critical Veeam Backup & Replication Flaw Allows Remote Code Execution on Domain-Joined Servers Security