Skip to content
Threat Feed

Tag

Patch-Management

32 briefs RSS
medium advisory

Multiple Vulnerabilities in PHP Runtime Environment

Multiple vulnerabilities across several PHP versions allow remote attackers to cause denial-of-service, access sensitive data, and compromise data integrity.

PHP vulnerability web-application patch-management
high advisory

Multiple Vulnerabilities in PaperCut Software

PaperCut has released security updates addressing critical vulnerabilities including remote code execution, unauthorized data access, and XSS across PaperCut Hive and PaperCut NG/MF platforms.

PaperCut Hive Embedded Application +2 vulnerability remote-code-execution patch-management
4c
high advisory

Security Policy Bypass in Forcepoint Security Engine (NGFW)

Forcepoint has disclosed CVE-2026-12974, a security policy bypass vulnerability affecting multiple versions of the Forcepoint Security Engine (NGFW) that requires urgent administrative review and patching.

Forcepoint Security Engine vulnerability network-security patch-management
1c
medium advisory

Vulnerabilities in Erlang/OTP

Multiple security vulnerabilities identified in Erlang/OTP across various version branches require immediate patching to mitigate potential risks.

OTP +3 vulnerability erlang patch-management
2c
critical threat

Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard

Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.

exploited Secure Firewall Management Center +4 vulnerability cisco network-security patch-management
2t 3c
high advisory

CSRF Vulnerability in phpList Mass Subscriber Removal

phpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.

phpList web-vulnerability csrf patch-management
1t 1c
critical advisory

Hard-coded Cryptographic Keys in Wärtsilä FOS-Onboard

Wärtsilä FOS-Onboard version 5.07.0923.01 contains hard-coded cryptographic keys in the Update Controller and robot testing framework that could facilitate unauthorized code execution, update deployment, and credential theft.

FOS-Onboard ics transportation patch-management cve-2026-78225 cve-2026-81855
2t
medium advisory

Multiple Critical Vulnerabilities in MongoDB Drivers and Core Server

Multiple vulnerabilities across MongoDB drivers and the Core Server identified on September 10-11, 2026, pose risks of remote denial-of-service, unauthorized data access, and integrity compromise.

C Driver +10 vulnerability database patch-management
3c
high advisory

Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry

Ivanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.

Endpoint Manager Mobile +4 vulnerability patch-management security-advisory
2c updated
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
high advisory

Multiple Vulnerabilities in strongSwan

Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.

strongSwan +1 vulnerability network-security patch-management
high advisory

Multiple Vulnerabilities in SonicWall Network Security Manager

SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.

Network Security Manager On-Prem vulnerability remote-code-execution privilege-escalation patch-management
high threat

Cisco Releases Patches for Critical Infrastructure Vulnerabilities

Cisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.

exploited Secure Email +6 vulnerability network-security patch-management informational
2t 5c
high advisory

Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX

Progress Software has patched two vulnerabilities, including path traversal (CVE-2026-18672) and input tampering (CVE-2026-19219), in Telerik UI for ASP.NET AJAX versions prior to 2026.3.812.

Telerik UI for ASP.NET AJAX vulnerability web-application patch-management
2c
high advisory

Multiple Vulnerabilities in Curl

Multiple vulnerabilities were discovered in the Curl library (versions 7.44.0 through 8.21.x), potentially allowing attackers to compromise data integrity, confidentiality, or bypass security policies.

Curl vulnerability library patch-management
low advisory

Security Constraint Bypass in VMware Tanzu Spring Framework

A vulnerability in VMware Tanzu Spring Framework identified as CVE-2024-38816 allows a remote, unauthenticated attacker to bypass security restrictions.

Spring Framework vulnerability web-framework patch-management
1c
critical advisory

SSRF Vulnerability in SiYuan via DNS Rebinding

SiYuan versions prior to 3.8.1 are vulnerable to server-side request forgery through a DNS rebinding attack, enabling unauthorized access to cloud metadata services and internal network resources.

SiYuan +5 ssrf vulnerability cloud-security web-vulnerability xss information-disclosure credential-access cve-2026-85174 +8
2r 6t 1c updated
medium advisory

Security Vulnerabilities in Plesk Management Interface and Extensions

WebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.

Plesk +2 vulnerability patch-management web-hosting
2c
high advisory

Cross-Site Scripting Vulnerability in Element maps-ng

A stored cross-site scripting (XSS) vulnerability in the si-map component of Element maps-ng allows unauthenticated attackers to execute arbitrary scripts in a victim's browser via crafted map pin tooltips.

maps-ng xss web-vulnerability patch-management
1c
critical advisory

Multiple Vulnerabilities in Google Chrome and Microsoft Edge

Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.

Chrome +4 vulnerability browser-security patch-management
1t 2c updated
low advisory

Multiple Vulnerabilities in Oracle Hyperion

Oracle has disclosed a series of 25 vulnerabilities affecting Hyperion, enabling remote, anonymous, or authenticated attackers to compromise system confidentiality, integrity, and availability.

Hyperion vulnerability enterprise-software patch-management
2c
high advisory

Mattermost Security Update for CVE-2026-9816

Mattermost has released critical security patches for multiple versions to address vulnerabilities tracked under CVE-2026-9816.

Mattermost +2 vulnerability-management security-advisory patch-management
1c
high advisory

Multiple Vulnerabilities in WordPress

Multiple vulnerabilities, including CVE-2026-64638, affect WordPress versions prior to 7.0.3, enabling privilege escalation, data breaches, and Server-Side Request Forgery (SSRF).

PoC WordPress +1 cve web-application patch-management
1c 1i
high advisory

Critical Security Vulnerabilities in Progress MarkLogic Server

Progress Software has released a security bulletin addressing ten critical vulnerabilities, including CVE-2026-7326 through CVE-2026-9203, affecting MarkLogic Server versions prior to 11.3.6 and 12.0.3.

MarkLogic Server vulnerability security-advisory patch-management
5c 2i
medium advisory

Multiple Vulnerabilities in Nextcloud Products

Multiple vulnerabilities, including CVE-2026-61527 and CVE-2026-61545, affect Nextcloud Server and Mail components, posing risks to data confidentiality and security policy enforcement.

Nextcloud Server 32 +4 vulnerability nextcloud patch-management
medium advisory

Vulnerabilities in MISP cti-transmute

The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.

cti-transmute vulnerability misp patch-management
3i
low advisory

Multiple Vulnerabilities in GitLab

Multiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.

GitLab Community Edition +1 vulnerability gitlab patch-management
5c
medium advisory

Progress Software Security Advisory Addresses Multiple Vulnerabilities

Progress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.

ECS Connection Manager < 7.2.63.3 +4 vulnerability cve security-advisory patch-management
5c
low advisory

Information Published for CVE-2026-64191

Information has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.

vulnerability patch-management informational
1c
high advisory

Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak

Juniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.

Juniper cRPD +6 vulnerability network-device juniper patch-management
2t 1c
high advisory

Multiple Vulnerabilities in Google Chrome (CVE-2026-13774 through CVE-2026-13895)

Multiple vulnerabilities, including CVE-2026-13774 through CVE-2026-13895, have been discovered in Google Chrome, allowing an attacker to cause an unspecified security problem on affected Windows, Linux, and macOS systems by exploiting these flaws.

PoC Chrome +5 vulnerability patch-management browser google-chrome cve chromium v8 rce +1
5c 5i updated
critical advisory

Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities

Progress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.

PoC Sitefinity CMS +9 vulnerability web-application cms load-balancer patch-management cve
3r 1t 5c 4i updated