Patch management
Patch Tuesday roundups, update guidance, and the operational reality of keeping fleets current.
Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out
CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.
Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.
ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.
Two critical Next.js flaws let attackers run code on self-hosted servers
Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.
CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)
CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.
An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency
CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA's KEV list after a suspected Chinese operator stole nuclear-agency files.
A phpIPAM flaw lets an unauthenticated attacker read and delete every network record (CVE-2026-67602)
CVE-2026-67602 is a critical unauthenticated flaw in phpIPAM before 1.8.2 that lets anyone read, change, or delete every IP record through the REST API.
Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.
A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.
Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it
CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.
GitLab GraphQL flaw lets an unauthenticated attacker delete your public projects (CVE-2026-19478)
GitLab CVE-2026-19478 (CVSS 9.4) lets an unauthenticated attacker delete public projects on self-managed servers. Patch now to 19.2.4, 19.1.6 or 18.11.11.
Google's AI helped fix 1,072 Chrome bugs; patch cadence doubled
Google credits AI for fixing 1,072 Chrome bugs in two June releases, but never said how many AI found. The real shift for defenders is a faster patch cadence.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out
GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.
Windmill's unauthenticated file-read flaw (CVE-2026-29059) is under active attack
Windmill's unauthenticated file-read flaw CVE-2026-29059 is being exploited in the wild. Patch self-hosted instances to 1.603.3 and rotate any exposed secrets.
Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence
Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.
ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.
ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.
OpenSSL's HollowByte flaw freezes servers, and no CVE flags it
OpenSSL patched HollowByte, an 11-byte flaw that strands server memory, quietly in June with no CVE.
Fully patched Windows, no fix: a new local privilege zero-day
LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.
Two Microsoft zero-days were exploited before the fix shipped
Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.
SAP's highest-scored July flaw is not the one to patch first
SAP's July 2026 patch day has three criticals. The top-scored 9.9 NetWeaver bug needs a login; the two pre-auth 9.1s in AppRouter and Commerce Cloud go first.
Zimbra's Classic Web Client can run code from a crafted email again. Patch to 10.1.19 now.
Zimbra shipped ZCS 10.1.19 to fix a stored XSS in the Classic Web Client that runs code from a crafted email. Google TAG reported it; no public exploit yet.
Two pre-auth bypasses hit BeyondTrust's privileged-access appliances, found by the vendor's own AI
BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two pre-auth CVSS 9.2 bypasses. Upgrade to 25.3.3 and hunt the window.
Django shipped three low-severity security fixes. One of them deserves a closer look.
Django 6.0.7 and 5.2.16 patch three low-severity issues: a header injection, a cache data leak, and a heap over-read.
Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.
Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.
Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown
Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).
Oracle E-Business Suite is under attack again, and the patch has been out since May
CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle's May patch. What to check and how to fix it now.
Cisco Unified CM's flaw is being exploited. Whether it touches you depends on one default setting.
CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.
Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.
The US used export-control powers to pull a frontier AI model that finds software bugs at scale.
Your Splunk box runs a database sidecar you never configured. Attackers use it for root.
CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.
Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.
F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.