Back to articles

Tag archive

#patchmanagement

S
Jul 16, 2026

SonicWall SMA 1000 Zero-Days Actively Exploited in Attacks

SonicWall has released urgent security patches for two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA 1000 series appliances. Threat actors are chaining the flaws—a server-side request forgery (SSRF) and a code injection bug—to achieve unauthenticated remote code execution with root privileges. Rapid7 reported observing exploitation in the wild since late June 2026, weeks before patches were available. CISA has added both vulnerabilities to its KEV catalog, mandating immediate action for federal agencies.

Jul 16, 20264 min read0 reactions0 comments
A
Jul 12, 2026

Australian Cyber Security Centre Issues Alert on Mass Exploitation of CMS Vulnerabilities

The Australian Cyber Security Centre (ACSC) has issued a high-priority alert about a large-scale global campaign exploiting at least 17 known vulnerabilities in popular Content Management Systems (CMS) like WordPress and Joomla, and their plugins. Attackers are actively scanning for and exploiting these unpatched flaws to deploy webshells, enabling persistent access for data theft, malware distribution, and further network compromise. The ACSC urges all organizations to patch their systems immediately and inspect for signs of compromise.

Jul 12, 20264 min read0 reactions0 comments
G
Jul 18, 2026

Google Patches Three Critical Use-After-Free Flaws in Chrome

Google has released two emergency security updates for its Chrome browser in just 48 hours, addressing a total of three critical use-after-free vulnerabilities. The latest patch fixes flaws in the Camera, GPU, and Network components (CVE-2026-15899, CVE-2026-15900, CVE-2026-15901), which could be exploited to cause data corruption or execute arbitrary code. All three flaws were discovered internally by Google's own security teams.

Jul 18, 20263 min read0 reactions0 comments
W
Jul 18, 2026

WordPress Core RCE Vulnerability CVE-2026-63030 Patched

A critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-63030, has been discovered in WordPress Core. The flaw, which affects versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allows an attacker to gain complete control of a website via the REST API. WordPress has released security updates (versions 6.9.5 and 7.0.2) to address the issue, and administrators are urged to update their sites immediately due to the high risk of exploitation.

Jul 18, 20263 min read0 reactions0 comments
C
Jul 18, 2026

CISA KEV Catalog Adds SharePoint RCE Flaw CVE-2026-58644

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SharePoint Server vulnerability, CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. The 9.8 CVSS RCE flaw is being actively exploited as a zero-day. CISA has mandated that federal agencies apply patches by July 19, 2026, and warns that attackers are chaining it with three other SharePoint flaws for full server compromise. All organizations with on-premises SharePoint servers are urged to patch immediately.

Jul 18, 20263 min read0 reactions0 comments
C
Jul 17, 2026

CISA Adds SharePoint RCE CVE-2026-58644 to KEV Catalog

CISA has added CVE-2026-58644, a critical remote code execution (RCE) vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, rated 9.8 CVSS, was exploited as a zero-day before a patch was available. It allows an authenticated attacker with 'Site Owner' privileges to execute arbitrary code. Microsoft addressed the issue in its July 14 Patch Tuesday update. CISA has mandated federal agencies to patch by July 19, 2026, and urges all organizations to update systems, enable AMSI, and hunt for signs of compromise.

Jul 17, 20264 min read0 reactions0 comments
C
Jul 17, 2026

CISA Adds Fortinet FortiSandbox Flaws to KEV Catalog

CISA has added two critical OS command injection vulnerabilities in Fortinet's FortiSandbox product to its Known Exploited Vulnerabilities (KEV) catalog. The flaws, CVE-2026-25089 and CVE-2026-39808, are confirmed to be under active exploitation. Their inclusion in the KEV catalog mandates that U.S. federal agencies apply patches on an accelerated timeline. These vulnerabilities can allow an attacker to execute arbitrary commands on the affected appliance, potentially leading to a full system compromise. All organizations using FortiSandbox are urged to patch immediately.

Jul 17, 20264 min read0 reactions0 comments
C
Jul 17, 2026

CISA KEV: Oracle E-Business Suite Flaw CVE-2026-46817

CISA has added CVE-2026-46817, a critical improper privilege management vulnerability in Oracle E-Business Suite, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, rated 9.8 CVSS, allows a remote, unauthenticated attacker to completely take over the Oracle Payments module. Due to evidence of active exploitation, CISA has mandated an aggressive three-day patching deadline of July 18, 2026, for federal agencies. The vulnerability affects EBS versions 12.2.3 through 12.2.15 and was originally patched in Oracle's May 2026 update. Organizations are urged to patch immediately to prevent exposure of sensitive financial data.

Jul 17, 20264 min read0 reactions0 comments
M
Jul 16, 2026

Microsoft July 2026 Patch Tuesday Fixes Two Exploited Zero-Days

Microsoft has released its largest-ever security update for July 2026, addressing up to 622 vulnerabilities, a surge attributed to AI-driven bug discovery. The update includes critical patches for two actively exploited zero-day vulnerabilities: CVE-2026-56155 in Active Directory Federation Services (AD FS) and CVE-2026-56164 in SharePoint Server. Both flaws allow for privilege escalation and have been added to CISA's KEV catalog, mandating urgent patching for federal agencies. A third publicly disclosed but not exploited zero-day in Windows BitLocker was also fixed.

Jul 16, 20264 min read0 reactions0 comments
M
Jul 15, 2026

Microsoft July 2026 Patch Tuesday: 2 Zero-Days Exploited

Microsoft's July 2026 Patch Tuesday is its largest to date, addressing over 570 vulnerabilities. Two zero-day flaws are under active attack: an elevation of privilege bug in Active Directory Federation Services (CVE-2026-56155) and another in SharePoint Server (CVE-2026-56164). Both have been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, mandating urgent patching for federal agencies. The update also includes fixes for numerous critical Remote Code Execution (RCE) vulnerabilities, making immediate assessment and patching a top priority for all organizations.

Jul 15, 20265 min read0 reactions0 comments