Articles tagged "Patch"

Found 353 articles

Actively Exploited

PaperCut has issued a second emergency patch for its NG and MF print management software due to two vulnerabilities that are currently being exploited. Researchers found that there were ways to bypass the initial fixes provided in the first patch, which prompted the urgent release of this new update. Organizations using PaperCut's software should prioritize applying this patch to protect against potential attacks, as the vulnerabilities can lead to unauthorized access and exploitation. It’s critical for users to stay informed and ensure their systems are updated to mitigate these risks.

Read Original

A serious vulnerability has been found in the GiveWP donation plugin for WordPress, which could allow an unauthenticated attacker to execute arbitrary commands on the server where the plugin is hosted. This flaw poses a significant risk to websites using this plugin, as it could lead to unauthorized access and control over the server. The issue affects all versions of the GiveWP plugin prior to the latest patch, making it crucial for site administrators to update their installations immediately. Given the nature of the vulnerability, there is a potential for widespread exploitation, which could compromise sensitive data and functionality for many organizations relying on this donation tool. Users and organizations should prioritize applying the necessary updates to safeguard their systems.

Read Original

Attackers are taking advantage of a recently patched vulnerability in PaperCut NG and MF software, allowing them to execute arbitrary code without needing authentication. This flaw gives unauthorized users remote access to the application's trusted configuration, which can be exploited to run Java code within the system. PaperCut has responded by releasing an emergency fix to address this issue and enhance security measures. Organizations using these PaperCut products should act quickly to apply the latest updates to safeguard their systems from potential exploitation. Failure to patch could leave systems vulnerable to significant security breaches.

Read Original

PaperCut has issued a warning about a serious vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. This flaw is currently being exploited in the wild, leading to confirmed incidents among its customers. To address the issue, PaperCut has released an emergency patch for versions 25 and 26. The company is prioritizing the resolution of this vulnerability as attackers are actively taking advantage of it. Organizations using these versions should apply the patch immediately to protect their systems from potential breaches.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies must address a serious remote code execution vulnerability affecting Citrix NetScaler appliances by this Saturday. This flaw is currently being exploited by attackers, which raises urgent concerns for the security of government networks. Citrix NetScaler is widely used for application delivery and load balancing, making it critical for agencies to implement the patch to prevent unauthorized access and potential data breaches. The deadline emphasizes the need for swift action to mitigate risks, as failure to patch could lead to significant security incidents. Agencies are strongly advised to prioritize this update to protect their systems and sensitive information.

Read Original

A recent study conducted by Tenable and SentinelOne has revealed concerning trends showing that both state-sponsored actors and criminal organizations are targeting the same weak spots in edge infrastructure. This shared interest in exploiting vulnerabilities raises alarms about the security posture of systems that are often overlooked. The research indicates that attackers are increasingly using similar tactics to breach these defenses, which could lead to significant data breaches and service disruptions. Companies that rely on edge infrastructure must take immediate action to identify and patch these vulnerabilities to protect themselves from potential exploitation. This convergence of threat actors highlights the need for heightened vigilance and improved security strategies in safeguarding perimeter defenses.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are currently being exploited in the wild. These vulnerabilities affect a variety of systems, including Red Hat Libuser, Microsoft SQL Server, and Citrix NetScaler, among others. The identified vulnerabilities range from privilege escalation to remote code execution, posing serious risks to federal agencies and potentially impacting other organizations as well. CISA urges all entities to prioritize fixing these vulnerabilities to protect their systems, especially those that expose critical assets to attackers. The agency encourages reporting any additional exploited vulnerabilities that are not yet in the KEV Catalog for potential inclusion.

Read Original
Actively Exploited

CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-60004, which is a code injection vulnerability in Gitea. This vulnerability is being actively exploited and poses significant risks, particularly to federal agencies. In response, CISA has emphasized the urgency for federal agencies to prioritize the remediation of this high-risk vulnerability, as it can grant attackers total control over affected systems. While the directive primarily targets Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management practices. The agency will continue to update the KEV Catalog with vulnerabilities that meet its criteria, and organizations are encouraged to report any known exploits not currently listed.

Read Original
Critical
Ebyte NE2-D11

All CISA Advisories

Ebyte's NE2-D11 firmware, version FW-9167-0-11, has multiple serious vulnerabilities that could allow attackers to gain unauthorized access and control over devices. Issues include inadequate authentication, cleartext transmission of sensitive information, and weaknesses in session management, which could lead to unauthorized configuration changes and data breaches. The vulnerabilities, which have a CVSS score as high as 9.8, affect critical sectors like manufacturing and energy, and their impact is global. Ebyte has acknowledged the problems and is working on a patch, but there has been little communication about its status. Users are advised to contact Ebyte for updates and to implement security measures in the meantime.

Read Original
Critical
Rently Smart Home

All CISA Advisories

Rently Smart Home has a critical vulnerability affecting versions 20.1.0 and earlier, which allows attackers to access sensitive information, including Master Pins, and override user permissions. This issue arises from insufficiently protected credentials. The vulnerability is particularly concerning for users in commercial facilities and information technology sectors across the United States and India. Rently has addressed this flaw with a patch released in late June 2026, meaning users do not need to take any additional action. However, organizations are still encouraged to improve their cybersecurity measures to mitigate risks associated with such vulnerabilities.

Read Original

Australian officials are warning TeamCity users to address a critical vulnerability that is currently being exploited by attackers. This alert follows a similar warning from the US government, indicating that the flaw poses a significant risk to organizations using TeamCity. The vulnerability could allow unauthorized access or control over affected systems, making it crucial for users to take immediate action. By patching their servers, companies can protect themselves from potential breaches and data loss. With active exploitation confirmed, the urgency for a fix is clear, and organizations should prioritize this update to safeguard their operations.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent three-day deadline for agencies to address a serious vulnerability in Zimbra, identified as CVE-2026-73570. This flaw enables attackers to take complete control over a user's communications, posing a significant risk to organizations using this software. The vulnerability could lead to unauthorized access to sensitive information and disrupt business operations. As Zimbra is widely used for email and collaboration, the implications of this vulnerability are considerable, affecting both public and private sector entities. Agencies are urged to act quickly to implement the necessary patches to mitigate this risk.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, specifically CVE-2026-21962, which affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This vulnerability involves improper access control and has been linked to active exploitation, making it a significant risk for federal agencies and other organizations. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal agencies prioritize fixing high-risk vulnerabilities like this one, especially on publicly exposed systems. While the directive is aimed at federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Companies are urged to act swiftly to mitigate this risk and report any additional vulnerabilities for consideration in the KEV Catalog.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for U.S. government agencies to patch a vulnerability in the Zimbra Collaboration Suite (ZCS) within three days. This flaw is currently being exploited by attackers, raising concerns about the potential for data breaches and unauthorized access to sensitive information. Zimbra is widely used for email and collaboration, making it critical that organizations act quickly to secure their systems. The agency's move underscores the need for immediate action to prevent exploitation and safeguard government communications. Agencies should ensure their ZCS installations are updated to mitigate this risk effectively.

Read Original

A serious vulnerability has been discovered in the isolated-vm package, which is commonly used in Node.js applications. This type confusion bug allows attackers to escape the V8 sandbox, potentially leading to remote code execution (RCE) on the host machine. If exploited, the vulnerability could give attackers control over the host process, posing significant risks to any systems relying on this package. Developers using isolated-vm need to be vigilant and apply necessary updates to protect their applications. The situation underscores the importance of regular security audits and patch management in software development.

Read Original
Page 1 of 24Next