HeadFlash

Topic · 61 stories

Patch Tuesday and security updates: what to install

Edited by Marcin Rybak

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. NVIDIA DCGM Exporter Flaw Exposes GPU Servers to Denial of Service Security
  2. Atlassian’s 9.3-rated flaw exposes eight Data Center products Security
  3. FBI Removes Accenture Contractor After Unpatched System Led to Breach Privacy
  4. Dell patches critical System Update flaw allowing root access Security
  5. Asus patches router flaws allowing command execution via VPN configs Security
  6. TeamViewer urges immediate patching of five high-severity flaws Security
  7. OpenBao patches full unauthenticated RCE chain, Vault left unfixed Security
  8. Apple fixes zero-click iMessage EXR heap overflow as CVE-2026-86869 Security
  9. Avast kernel driver double-fetch flaw detailed as CVE-2025-13032 Security
  10. OxygenOS 16 flaws give untrusted apps root on OnePlus 15 Security
Show older (51 stories)
  1. BigDiskBuster PoC blocks Microsoft Defender updates on Windows Security
  2. Critical vCenter pre-auth flaws patched after one hits active exploitation Security
  3. CISA flags active exploitation of three Linux kernel flaws, one critical Security
  4. WordPress Click2Shell flaw enabled pre-auth PHP execution Security
  5. Check Point patches critical flaw allowing root code execution Security
  6. Docker patches Mac hypervisor sandbox escape Security
  7. Public exploits released for four Linux kernel root flaws Security
  8. SolarWinds patches hard-coded key in Access Rights Manager Security
  9. Parallels Desktop Bug Lets Any macOS Process Gain Root Security
  10. ConnectWise Patches ScreenConnect Flaw Used in Worm-Like Attacks Security
  11. Frappe LMS Flaws Chain Student Access to Remote Code Execution Security
  12. GitLab CVE-2026-85706 Exploited After 10.0 Severity Score Security
  13. Microsoft ships record 974 fixes, with two zero-days already exploited Security
  14. CISA confirms ransomware gangs are exploiting WatchGuard Firebox flaw Security
  15. Critical Elementor Pro Flaw Exploited to Take Over WordPress Sites Security
  16. Core Lightning Issues Emergency Warning Over Real Vulnerabilities Found by AI Security
  17. Hackers exploit critical Gitea flaw in code injection attacks, CISA adds to KEV Security
  18. Critical Calix GigaSpire Flaw Allows Remote Firewall Takeover, No Patch Available Security
  19. WordPress SSO Plugin Under Active Attack; Paid Editions Were Invisible to Vulnerability Databases Security
  20. CISA Gives Agencies 3 Days to Patch Actively Exploited Zimbra Command Injection Flaw Security
  21. Apple patches 29 flaws across iPhone, iPad, and Mac Security
  22. CISA Warns Ransomware Gangs Exploit Windows Task Host Privilege Escalation Flaw Security
  23. Microsoft emergency patch closes Windows zero-day exploited by Lazarus Group Security
  24. Docker cp Vulnerability Allows Container-to-Host Takeover, Patched in Latest Release Security
  25. OP-TEE Flaws Allow Heap Underwrite, DoS, and Use-After-Free in Secure World Security
  26. Insecure Deserialization in imgmgr.exe Bypasses Windows Application Control Security
  27. N-able issues hotfix for N-central ‘god mode’ flaw under active attack Security
  28. AI is finding Apple security flaws faster than Apple can sort through them Security
  29. Microsoft Overwhelmed by AI-Discovered Bugs as Anthropic’s Mythos Uncovers Hundreds of Vulnerabilities Security
  30. Researchers Find 36,872 Exposed Server Management Interfaces, Many Using 20-Year-Old Vulnerability Security
  31. wp2shell: Pre-Auth RCE in WordPress Core (CVE-2026-63030) Security
  32. Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches Security
  33. Zoom Warns of Critical Account Takeover Vulnerability Security
  34. Microsoft’s July Patch Tuesday Sets Record with 570 Fixes, Two Zero-Days Under Attack Security
  35. Forgotten UEFI Shims Undermining Secure Boot Security
  36. Smashing the ServiceNow Sandbox – Pre Authentication RCE Security
  37. Microsoft Urges Shorter Windows Update Deployment Timelines Due to AI Threats Security
  38. Microsoft Patches RoguePlanet Defender Zero-Day After Researcher Dispute Security
  39. Januscape Linux KVM Flaw Lets Guest VMs Take Over Host after 16 Years Security
  40. Ubiquiti Patches Maximum-Severity CVE-2026-50746 and Six Other Critical Flaws Security
  41. GhostLock Linux Kernel Exploit Grants Root in Five Seconds, Breaks Containers Security
  42. 16-Year-Old Linux Kernel Flaw Enables VM Escape on Intel and AMD Security
  43. Seiko SkyBridge IoT Routers Have Permanent OS Injection Flaw – No Patch Security
  44. Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws Security
  45. CitrixBleed Vulnerability Allows Memory Overread in NetScaler SAML Configuration Security
  46. Apple Rushes Security Patches Amid AI-Powered Hacking Risks AI
  47. Apple Rushes Security Fixes in Response to AI-Powered Threats Security
  48. DirtyClone Linux Kernel Exploit Published, Enables Stealth Root Access Security
  49. Secure Boot Certificates to Expire June 24 — Update Your Systems Now Security
  50. Microsoft Shatters Patch Tuesday Record With Nearly 200 Fixes and Three Zero-Days Security
  51. Critical Veeam Backup & Replication Flaw Allows Remote Code Execution on Domain-Joined Servers Security