Articles tagged "Patch"

Found 353 articles

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a significant vulnerability in Ray, an open-source distributed computing framework used for artificial intelligence and machine learning. This flaw allows remote code execution through web browsers and is currently being actively exploited. Developers and organizations using Ray should be particularly vigilant, as the vulnerability poses serious risks to their systems. CISA's inclusion of this issue in its Known Exploited Vulnerabilities catalog underscores the urgency for affected users to address the flaw promptly to avoid potential breaches or data loss. As of now, specific patch details or remediation steps have not been disclosed, making it crucial for users to monitor updates from the Ray project and implement security best practices.

Read Original
Actively Exploited

A serious vulnerability in SAP Commerce Cloud was quickly targeted by attackers just days after a patch was released to fix the issue. This flaw poses significant risks to organizations using the platform, as it could allow unauthorized access or manipulation of data. The rapid exploitation of this vulnerability emphasizes the need for companies to ensure they apply updates promptly and monitor their systems for any signs of intrusion. Cybersecurity experts recommend that users remain vigilant and implement additional security measures where possible to safeguard their environments. This incident serves as a reminder of the importance of proactive cybersecurity practices in protecting sensitive business information.

Read Original

A recently discovered vulnerability, identified as CVE-2026-54121, poses a serious risk to organizations using Enterprise Certificate Authorities (CAs). This flaw allows a standard domain user to escalate their privileges, effectively turning the Enterprise CA into a Domain Controller. This situation can lead to unauthorized access and control over sensitive resources within the network. Organizations need to treat their Public Key Infrastructure (PKI) as a critical part of their security framework, as it plays a vital role in identity management. The importance of addressing this vulnerability cannot be overstated, as it highlights the need for stringent security measures around privileged accounts and trust relationships within IT environments. Patching is essential to mitigate this risk.

Read Original
Actively Exploited

CISA has added a new vulnerability, CVE-2025-62593, related to code injection in the Ray-Project, to its Known Exploited Vulnerabilities Catalog. This vulnerability is currently being exploited, posing a significant risk to federal agencies and potentially impacting organizations that utilize the Ray framework. Under the Binding Operational Directive 26-04, federal agencies are required to prioritize fixing high-risk vulnerabilities, like this one, especially on systems that could give attackers complete control post-exploitation. CISA encourages all organizations, not just federal ones, to adopt similar risk-based vulnerability management practices to enhance their security posture. If anyone is aware of other exploited vulnerabilities not listed in the catalog, they can submit them for consideration through CISA's nomination form.

Read Original

Microsoft is currently developing a security patch for a zero-day vulnerability known as 'ShieldBreak,' which was disclosed last week by researcher Nightmare Eclipse. This vulnerability is tracked as CVE-2026-69414 and poses a significant risk, as it can potentially allow attackers to exploit Microsoft Defender, an essential security tool for many users and organizations. The information about this vulnerability is particularly concerning because it could be leveraged by cybercriminals to bypass security measures, compromising systems and data. Microsoft is urging users to stay vigilant while they work on a fix to mitigate the threat. As the situation develops, it’s crucial for users of Microsoft Defender to monitor for updates and implement any recommended patches as soon as they are available.

Read Original

A serious vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, has been actively exploited just three days after its disclosure. This flaw allows attackers to execute arbitrary code, which can compromise internal components of the affected systems. Organizations using SAP Commerce Cloud should be particularly vigilant, as the rapid exploitation indicates a high level of risk. The urgency for companies to patch their systems is critical to prevent unauthorized access and potential data breaches. Users and administrators need to prioritize updates to safeguard their environments against this vulnerability.

Read Original
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Security Affairs

Actively Exploited

A serious vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is currently being exploited by attackers. This flaw, which has a maximum severity score of 10.0, arises from insufficient authorization checks and poor input validation. Just days after SAP issued a patch, reports of active exploitation began to surface. This puts organizations using SAP Commerce Cloud at risk, as attackers could potentially gain unauthorized access to sensitive information or systems. Companies should prioritize applying the latest updates from SAP to protect their environments from these attacks.

Read Original
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

The Hacker News

Actively Exploited

A serious security vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is currently being exploited by attackers. This vulnerability has a maximum severity rating of 10.0 on the CVSS scale and stems from inadequate authorization checks and input validation. As a result, unauthorized users can take advantage of a default authentication client to execute malicious actions. The risk here is significant, as it could lead to unauthorized access to sensitive data or system controls within affected environments. Companies using SAP Commerce Cloud should take immediate action to secure their systems against this vulnerability.

Read Original

GeoServer is currently facing a serious security issue due to an unpatched zero-day vulnerability that allows for SQL injection and potentially remote code execution (RCE). This flaw has already attracted the attention of attackers who are probing exposed systems, raising concerns for organizations using this open-source geospatial platform. A security researcher named q1uf3ng disclosed the vulnerability, but as of now, there is no available patch to fix it. Companies running GeoServer should immediately assess their systems for exposure to this vulnerability and take steps to secure their installations. The urgency of the situation is heightened by the active exploitation attempts underway, making it crucial for users to act quickly to protect their data.

Read Original
Actively Exploited

A recently patched vulnerability in SAP Commerce Cloud, classified as a maximum-severity remote code execution flaw, is now being actively targeted by attackers. The flaw was fixed just three days ago, and threat intelligence firm Defused has reported that cybercriminals are already exploiting it. This vulnerability puts users of SAP Commerce Cloud at risk, as it allows unauthorized code execution, potentially leading to data breaches or service disruptions. Companies using this platform need to ensure they apply the latest security updates to protect their systems. The urgency of the situation is underscored by the rapid exploitation following the announcement of the patch, making swift action essential for affected organizations.

Read Original

A significant vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, is being actively exploited by attackers. This flaw, which allows for the bypassing of authentication and the impersonation of users, can lead to unauthorized access to files and the ability to alter data. Microsoft issued a patch for this vulnerability during its July 2026 Patch Tuesday updates, but the release of proof-of-concept exploit code by Rapid7 has prompted immediate exploitation in the wild. Organizations using SharePoint should prioritize applying the provided security updates to protect against potential data breaches and unauthorized modifications. The situation highlights the ongoing risks associated with unpatched vulnerabilities, especially when exploit tools become publicly available.

Read Original
Critical
Johnson Controls Metasys

All CISA Advisories

A serious vulnerability has been identified in Johnson Controls' Metasys building automation system, affecting versions 12, 13, 14, and 15. This flaw allows a low-privilege user to inject malicious code into the Metasys user interface via a specially crafted URL. This can enable session hijacking, where attackers could gain unauthorized access to the system as other users, including administrators. Organizations using these affected versions should take immediate action to apply the latest patches or upgrade to version 16.0, which is not impacted by this vulnerability. Without prompt remediation, the risk of exploitation could pose significant security threats to critical infrastructure sectors worldwide, including manufacturing and transportation.

+1 more
Read Original
Critical
Siemens Siveillance Video

All CISA Advisories

Siemens has identified a serious vulnerability in its Siveillance Video Management Servers that could allow attackers to execute arbitrary code remotely. This flaw, classified as CVE-2026-3014, affects several versions of the software, specifically Siveillance Video V2023 R3 versions prior to 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions below 25.1.15. Siemens urges users to update their systems to the latest versions to mitigate the risk. The vulnerability poses a significant threat to critical infrastructure sectors, including manufacturing and communications, making it crucial for organizations using these systems to act promptly. Users are also advised to enhance their network security measures to protect against potential exploitation.

Read Original
Critical
Haiwell IoT Cloud HMI Gateway

All CISA Advisories

A serious security vulnerability has been discovered in the Haiwell IoT Cloud HMI Gateway, specifically in version 3.40.1.12. This flaw allows attackers to inject and execute arbitrary operating system commands with root privileges, posing a significant risk to critical infrastructure sectors like energy and water management. The vulnerability stems from improper input handling in the Net Check feature, which fails to sanitize user inputs effectively. Although no active exploitation has been reported yet, organizations using this product should take immediate action to mitigate potential risks. Haiwell has released a patch (version Scada-v3.50.1.19) to address this issue, which users are urged to implement as soon as possible.

Read Original
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Security Affairs

Actively Exploited

A serious vulnerability in SharePoint, identified as CVE-2026-55040, is currently being exploited by attackers following the release of a public proof-of-concept on August 12. This flaw, which has a CVSS score of 9.1, allows unauthenticated users to impersonate SharePoint administrators, posing a significant risk to organizations using this platform. The vulnerability was patched in July, but the rapid exploitation indicates that many systems may still be vulnerable. Companies using SharePoint need to prioritize applying the latest security updates to protect their environments from unauthorized access. The situation underscores the importance of timely patch management in preventing exploitation.

Read Original
PreviousPage 3 of 24Next