Home/ Blog/ Topics/ Patch management
Topic

Patch management

Patch Tuesday roundups, update guidance, and the operational reality of keeping fleets current.

Security news

Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out

CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.

Security news

Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.

ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.

Security news

Two critical Next.js flaws let attackers run code on self-hosted servers

Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.

Security news

CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)

CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.

Security news

An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency

CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA's KEV list after a suspected Chinese operator stole nuclear-agency files.

Security news

A phpIPAM flaw lets an unauthenticated attacker read and delete every network record (CVE-2026-67602)

CVE-2026-67602 is a critical unauthenticated flaw in phpIPAM before 1.8.2 that lets anyone read, change, or delete every IP record through the REST API.

Security news

Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.

A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Security news

GitLab GraphQL flaw lets an unauthenticated attacker delete your public projects (CVE-2026-19478)

GitLab CVE-2026-19478 (CVSS 9.4) lets an unauthenticated attacker delete public projects on self-managed servers. Patch now to 19.2.4, 19.1.6 or 18.11.11.

Security news

Google's AI helped fix 1,072 Chrome bugs; patch cadence doubled

Google credits AI for fixing 1,072 Chrome bugs in two June releases, but never said how many AI found. The real shift for defenders is a faster patch cadence.

Deep dive

For this week's most-exploited bugs, the patch was the easy part

This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.

Security news

A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out

GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.

Security news

Windmill's unauthenticated file-read flaw (CVE-2026-29059) is under active attack

Windmill's unauthenticated file-read flaw CVE-2026-29059 is being exploited in the wild. Patch self-hosted instances to 1.603.3 and rotate any exposed secrets.

Security news

Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence

Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.

Security news

ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.

ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.

Security news

OpenSSL's HollowByte flaw freezes servers, and no CVE flags it

OpenSSL patched HollowByte, an 11-byte flaw that strands server memory, quietly in June with no CVE.

Security news

Fully patched Windows, no fix: a new local privilege zero-day

LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.

Security news

Two Microsoft zero-days were exploited before the fix shipped

Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.

Security news

SAP's highest-scored July flaw is not the one to patch first

SAP's July 2026 patch day has three criticals. The top-scored 9.9 NetWeaver bug needs a login; the two pre-auth 9.1s in AppRouter and Commerce Cloud go first.

Security news

Zimbra's Classic Web Client can run code from a crafted email again. Patch to 10.1.19 now.

Zimbra shipped ZCS 10.1.19 to fix a stored XSS in the Classic Web Client that runs code from a crafted email. Google TAG reported it; no public exploit yet.

Security news

Two pre-auth bypasses hit BeyondTrust's privileged-access appliances, found by the vendor's own AI

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two pre-auth CVSS 9.2 bypasses. Upgrade to 25.3.3 and hunt the window.

Security news

Django shipped three low-severity security fixes. One of them deserves a closer look.

Django 6.0.7 and 5.2.16 patch three low-severity issues: a header injection, a cache data leak, and a heap over-read.

Security news

Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.

Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.

Security news

Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown

Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).

Security news

Oracle E-Business Suite is under attack again, and the patch has been out since May

CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle's May patch. What to check and how to fix it now.

Security news

Cisco Unified CM's flaw is being exploited. Whether it touches you depends on one default setting.

CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.

Security news

Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.

The US used export-control powers to pull a frontier AI model that finds software bugs at scale.

Security news

Your Splunk box runs a database sidecar you never configured. Attackers use it for root.

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.

Security news

Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.

F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.

Security news

Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.

CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.