#security-patches

[ follow ]
Information security
fromTechzine Global
3 days ago

Veeam Patches Critical Vulnerabilities in Backup & Replication

Veeam resolved four critical vulnerabilities in Backup & Replication that enable remote code execution on backup servers, with patches available in versions 12.3.2.4465 and 13.0.1.2067.
Information security
fromSecurityWeek
4 days ago

Critical N8n Vulnerabilities Allowed Server Takeover

Two critical vulnerabilities in n8n allowed unauthenticated remote code execution and sandbox escape, potentially exposing all stored credentials including AWS keys, passwords, OAuth tokens, and API keys.
Information security
fromSecurityWeek
5 days ago

Fortinet, Ivanti, Intel Patch High-Severity Vulnerabilities

Fortinet, Ivanti, and Intel released security patches for dozens of vulnerabilities including high-severity bugs enabling arbitrary code execution, privilege escalation, and security bypasses.
Information security
fromTheregister
5 days ago

Hotpatching goes default in Windows Autopatch

Windows Autopatch enables hotpatch security updates by default starting May 2026, installing patches without restarts, though administrators can opt out at the tenant or group level.
fromThe Hacker News
5 days ago

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

This month, over half (55%) of all Patch Tuesday CVEs were privilege escalation bugs, and of those, six were rated exploitation more likely across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server, and Winlogon. We know these bugs are typically used by threat actors as part of post-compromise activity, once they get onto systems through other means (social engineering, exploitation of another vulnerability).
Information security
Information security
fromThe Hacker News
1 week ago

Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

Cisco Catalyst SD-WAN Manager has two actively exploited vulnerabilities allowing file overwrite and information disclosure to authenticated attackers with valid credentials.
#android-security
fromTechRepublic
1 week ago
Information security

Google's Biggest Android Security Update in Years Fixes 129 Bugs, Including an Actively Exploited Zero-Day

Information security
fromTechRepublic
1 week ago

Google's Biggest Android Security Update in Years Fixes 129 Bugs, Including an Actively Exploited Zero-Day

Google released 129 security patches in March 2026, the largest update in eight years, including a critical zero-day vulnerability affecting 234 Qualcomm chipsets that is already under active exploitation.
Information security
fromThe Hacker News
1 week ago

Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited

Google disclosed a high-severity Qualcomm Graphics component vulnerability (CVE-2026-21385) being exploited in Android devices, with March 2026 patches addressing 129 total vulnerabilities including critical remote code execution and privilege escalation flaws.
Information security
fromInfoWorld
1 week ago

Angular releases patches for SSR security issues

Google's Angular team released two security updates for SSR vulnerabilities: a critical SSRF/header injection flaw and a moderate open redirect flaw, requiring immediate patching to prevent authorization header theft and phishing attacks.
fromSecurityWeek
2 weeks ago

Zyxel Patches Critical Vulnerability in Many Device Models

An attacker could exploit the flaw via crafted UPnP SOAP requests to execute OS commands on a vulnerable device. It is important to note that WAN access is disabled by default on these devices, and the attack can be carried out remotely only if both WAN access and the vulnerable UPnP function have been enabled.
Information security
fromGSMArena.com
2 weeks ago

Realme 16 Pro series gets extended software support in India

In a post on X, Realme India's official account confirmed that the Realme 16 Pro and 16 Pro+ will now receive four years of Android OS updates and six years of security patches. At launch, the company had promised three years of Android updates and four years of security support.
Gadgets
Information security
fromThe Hacker News
1 month ago

Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex

CVE-2026-20045 (CVSS 8.2) allows unauthenticated remote attackers to execute arbitrary OS commands and escalate to root in multiple Cisco Unified Communications and Webex Calling Dedicated Instance products.
#ios-26
Mobile UX
fromGSMArena.com
3 months ago

Motorola Edge 50 Ultra is now receiving the Android 16 update

Motorola Edge 50 Ultra units in Brazil are receiving Android 16 via a staged 1.64GB OTA (firmware W1UV36H.61-15).
Software development
fromIT Pro
4 months ago

Applications and the afterlife: how businesses can manage software end of life

End-of-life software continues to run without feature or security updates, increasing vulnerability and reducing vendor support availability.
fromInfoQ
4 months ago

Java News Roundup: Oracle Critical Patch Update, BellSoft, Grails, Hazelcast, Langchain4j

This week's Java roundup for October 20th, 2025, features news highlighting: Oracle's Critical Patch Update (CPU) for October 2025; BellSoft CPU patches for Liberica JDK; the GA release of Grails 7.0; point releases for Micronaut, Hazelcast, LangChain4j and OpenXava; and the November 2025 beta release of Open Liberty.
Java
Gadgets
fromGSMArena.com
5 months ago

Samsung Galaxy S22 series is now receiving the One UI 8 update

One UI 8 (Android 16) rollout has reached Galaxy S22 devices as a 3.1GB OTA update including September 1, 2025 security patches.
fromComputerWeekly.com
5 months ago

Plotting a path forward with VMware version 7 | Computer Weekly

October 2, 2025, marks the end of general support for VMware's version 7. After that, Broadcom won't release any new security patches or fixes, and you won't be able to log vendor support tickets for these versions. You'll still have access to previously published updates under the self-service policy (although this could change in time, but there won't be anything new coming.
Information security
#vmware
#microsoft
Bootstrapping
fromThe Hacker News
9 months ago

Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild

Microsoft patched 67 security flaws, including a critical zero-day vulnerability in WEBDAV exploited in active attacks.
DevOps
fromZero Day Initiative
10 months ago

Zero Day Initiative - The May 2025 Security Update Review

Critical vulnerabilities in Microsoft Office allow code execution without user interaction.
Microsoft has mitigated severe bugs in Azure, Dataverse, and Power Apps.
Multiple vulnerabilities in Office applications are being addressed with security patches.
fromZero Day Initiative
9 months ago

Zero Day Initiative - The June 2025 Security Update Review

Adobe's June 2025 updates address 254 CVEs across multiple products, prioritizing those in Commerce and introducing a substantial fix for Experience Manager, despite no known exploits.
Web frameworks
[ Load more ]