#patchnow — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #patchnow, aggregated by home.social.
-
📰 CISA Adds Progress Kemp LoadMaster Flaw to KEV Catalog After Exploits
🚨 CISA KEV ALERT: A critical command injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) is actively exploited. Unauthenticated attackers can gain full control. Federal agencies must patch by Aug 10. #CVE #CISA #KEV #PatchNow
-
🟡 New security advisory:
CVE-2026-20316 affects Cisco Secure Firewall Management Center.
• Impact: Security weakness that could be exploited
• Risk: Potential for targeted attacks
• Mitigation: Schedule patching in your next maintenance windowFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-20316-fmc-static-credentials-leak-sensitive-data -
VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
⚠️ New security advisory:
CVE-2026-23698 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hoursFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-23698-vtiger-crm-lets-admins-upload-webshells-poc -
CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
#CISA #cybersecurity #infosec #patchnow #vulnerabilitymanagement #KEV
-
CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
#CISA #cybersecurity #infosec #patchnow #vulnerabilitymanagement #KEV
-
🔴 New security advisory:
CVE-2026-58138 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-58138-orkes-conductor-unauth-rce-poc -
🚩 Ivanti Sentry hit by two CRITICAL vulns: OS command injection (code exec as root) & auth bypass (rogue admin creation). Affects R10.5.2, R10.6.2, R10.7.1. Patch now — no exploitation seen yet. https://radar.offseq.com/threat/ivanti-max-severity-sentry-flaw-allows-code-execut-2899d337 #OffSeq #Ivanti #Vulnerability #PatchNow
-
📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog
📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow
🌐 cyber[.]netsecops[.]io
-
📰 Google Patches Fifth Actively Exploited Chrome Zero-Day of 2026
⚠️ Google patches its FIFTH Chrome zero-day this year! CVE-2026-11645 is a high-severity V8 bug actively exploited in the wild. Update your browser to version 149.0.7827.103+ immediately! #CyberSecurity #ZeroDay #GoogleChrome #PatchNow
🌐 cyber[.]netsecops[.]io
-
📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog
📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow
🌐 cyber[.]netsecops[.]io
-
📰 Critical RCE Flaw (CVE-2026-0826) in HP Poly VoIP Phones Allows Root Takeover
📢 CRITICAL FLAW: A 9.2 CVSS RCE bug (CVE-2026-0826) affects HP Poly VoIP phones. The flaw allows unauthenticated root access. HP has released patches. Update now! #CVE #Vulnerability #RCE #VoIP #PatchNow
🌐 cyber[.]netsecops[.]io
-
Oracle's May 2026 CSPU patches 77 vulnerabilities, including a dozen CRITICAL, remotely exploitable flaws in Database Server, E-Business Suite, and more. Immediate patching is advised — risk of active exploitation remains high. https://radar.offseq.com/threat/oracles-first-monthly-patches-resolve-77-vulnerabi-2f241f3f #OffSeq #Oracle #PatchNow
-
🔔 Oracle May 2026 CSPU covers 35 CVEs — 11 critical, 18 high. E-Business Suite & REST Data Services most affected. Remote, unauthenticated exploits possible. Apply patches ASAP! https://radar.offseq.com/threat/oracle-may-2026-critical-security-patch-update-add-373b10d6 #OffSeq #Oracle #VulnAlert #PatchNow
-
📰 Active Exploitation of Critical FortiClient EMS Flaw (CVE-2026-35616) Used to Deploy Credential Stealers
📢 ACTIVE EXPLOITATION: A critical FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) is being used to push credential stealers to all managed endpoints via PowerShell. Update to version 7.4.7 NOW. 🛡️ #Fortinet #CyberAttack #PatchNow
🌐 cyber[.]netsecops[.]io
-
📰 CISA Mandates Urgent Patch for Actively Exploited LiteSpeed cPanel Flaw Granting Root Access
⚠️ CRITICAL ALERT: CISA adds LiteSpeed cPanel plugin flaw (CVE-2026-48172) to its KEV catalog. The bug allows for root access and is actively exploited. Patch immediately! #CVE #LiteSpeed #cPanel #CyberSecurity #PatchNow
🌐 cyber[.]netsecops[.]io
-
⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. https://radar.offseq.com/threat/cisa-gives-feds-4-days-to-patch-actively-exploited-ebc57663 #OffSeq #vuln #patchnow
-
⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. https://radar.offseq.com/threat/cisa-gives-feds-4-days-to-patch-actively-exploited-ebc57663 #OffSeq #vuln #patchnow
-
📰 Critical 18-Year-Old 'NGINX Rift' Vulnerability (CVE-2026-42945) Under Active Attack
🚨 CRITICAL NGINX FLAW! An 18-year-old bug 'NGINX Rift' (CVE-2026-42945) is actively exploited for DoS & RCE. Affects millions of web servers. Patch immediately! #NGINX #CVE #Infosec #PatchNow
🌐 cyber[.]netsecops[.]io
-
🟡 New security advisory:
CVE-2026-9082 affects multiple systems.
• Impact: Security weakness that could be exploited
• Risk: Potential for targeted attacks
• Mitigation: Schedule patching in your next maintenance windowFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-9082-drupal-core-sqli-actively-exploited-poc -
📰 Warning: Microsoft Defender Flaws Actively Exploited to Gain SYSTEM Privileges
⚠️ ACTIVE EXPLOITATION ALERT: Flaws in Microsoft Defender (CVE-2026-41091, CVE-2026-45498) are being used by attackers to gain SYSTEM privileges and disable AV. Patch the Malware Protection Engine immediately! #CyberSecurity #Vulnerability #PatchNow
🌐 cyber[.]netsecops[.]io
-
⛔ New security advisory:
CVE-2026-32985 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-32985-xerte-online-toolkits-rce-vulnerability-patch-immediately -
A third party report highlights a critical auth bypass in AdGuard Home that could grant admin control to attackers. Users are urged to patch immediately and review access controls. 🛡️🔧 Update to the latest release and rotate credentials. More: https://cyberinsider.com/adguard-home-vulnerable-to-critical-auth-bypass-allowing-admin-control/ #CyberSecurity #AdGuardHome #Vulnerability #PatchNow
-
📢⚠️🩹 #Cisco has patched 48 vulnerabilities in its Secure Firewall products, including 2 critical CVSS 10 flaws that could allow authentication bypass and remote code execution with root access - Patch NOW!
Read: https://hackread.com/cisco-patches-firewall-vulnerabilities-cvss-10-flaws/
-
⛔ New security advisory:
CVE-2026-1435 affects Graylog Graylog.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systemsFull breakdown:
https://yazoul.net/advisory/cve/cve-2026-1435 -
Microsoft warnt vor einer kritischen 0‑Day‑Lücke in Microsoft Office und ruft zur sofortigen Installation des Notfall‑Updates auf. um Unternehmen und Nutzer vor aktiven Angriffen zu schützen. 🛡️🧩 Mehr Infos: https://www.heise.de/news/Notfall-Update-gegen-Zeroday-in-Microsoft-Office-11154976.html #Microsoft #Office #Security #ITSecurity #PatchNow
#OnlyOffice ist auch sehr gut https://onlyoffice.com/de/download-desktop
-
Microsoft has rushed out an emergency security update for Office (CVE‑2026‑21509) after confirming the flaw is already being exploited in the wild. 🔐
The high‑severity security feature bypass lets attackers bypass OLE protections and run malicious code via specially crafted Office files. 📄⚠️
👉 Microsoft issues emergency fix for actively exploited Office flaw:
https://cyberinsider.com/microsoft-issues-emergency-fix-for-actively-exploited-office-flaw/
#Microsoft #Office #Security #CVE202621509 #PatchNowThrere is also #OnlyOffice
-
CISA warnt vor aktiven Angriffen auf Apple-WebKit-Lücken und Gladinet-Dienste – Updates sind bereits verfügbar. 🚨🔐 Wer iOS, macOS & Co. nutzt, sollte jetzt patchen, bevor Angreifer nachziehen. 👉 https://www.heise.de/news/Updaten-Warnung-vor-Angriffen-auf-Apple-Luecken-und-Gladinet-11116020.html #CyberSecurity #Apple #PatchNow #Newz
-
Cybersecurity Weekly Roundup (Nov 16–22)
Chrome zero day; Oracle Identity Manager RCE (KEV); FortiWeb exploited; SonicWall SSLVPN flaw; Cloudflare outage; WhatsApp enumeration. Plus: Logitech breach, 7-Zip PoC, Salesforce/Gainsight ripple, Dutch takedown.
Actions: Patch edge first, push Chrome, rotate keys and OAuth, rehearse failover.
Read: https://www.kylereddoch.me/blog/cybersecurity-weekly-roundup-for-november-16-23-2025/
-
🚨 Fortinet has released patches for two actively exploited vulnerabilities in its #FortiWeb web-application firewalls. One allows full takeover, the other enables command injection.
Update now: https://hackread.com/fortinet-fixes-fortiweb-takeover-flaw-active-attacks/
-
🚨 Urgent patch alert: a 9.9/10 severity flaw (CVE-2025-42887) in #SAP Solution Manager allows code injection and full system takeover. Act now.
Read: https://hackread.com/sap-patch-cve-2025-42887-takeover-vulnerability/
-
Microsoft Issues Emergency Patch for Actively Exploited Windows Server Flaw CVE-2025-59287
#Microsoft #Cybersecurity #WindowsServer #WSUS #PatchTuesday #InfoSec #CVE #Vulnerability #Security #PatchNow #RCE #SysAdmin #ITPros #ZeroDay #Exploit
-
CISA just confirmed a nasty Windows SMB bug (CVE-2025-33073) is being actively exploited.
It lets an attacker gain SYSTEM privileges by tricking a machine into connecting to a bad SMB server.
All Windows Server versions, Win10, and Win11 are affected. A patch was released in June 2025.
CISA has officially added it to their must-patch (KEV) list.
#CyberSecurity #Windows #CVE #PatchNow
#CyberSecurity #InfoSec #CVE #Windows #SMB #CISA #Vulnerability
-
🚨 Critical Magento & Adobe Commerce Flaw (CVE-2025-54236 – SessionReaper) 🚨
Impact: Customer account takeover + unauthenticated remote code execution (CVSS 9.1 Critical).
👉 Full details and action steps: https://hostvix.com/sessionreaper-critical-magento-adobe-commerce-vulnerability-cve-2025-54236/
#Magento #AdobeCommerce #SessionReaper #CVE202554236 #CVE #Infosec #CyberSecurity #AppSec #WebSecurity #SecOps #BlueTeam #RedTeam #ThreatIntel #Vulnerability #PatchNow #ZeroDay #Exploit #EcommerceSecurity #DataSecurity #SecurityUpdate
-
🚨 CISA warns of active attacks on Linux, Android & Sitecore! 🐧📱🖥️ High & critical risks: privilege escalation & code injection. Updates available—patch now! More on CVEs & risks👇 #Cybersecurity #InfoSec #PatchNow #newz
https://www.heise.de/en/news/Attacks-on-vulnerabilities-in-Linux-Android-and-Sitecore-10633249.html
-
🔒 Die CISA warnt: Aktuelle Angriffe auf #Linux, #Android & #Sitecore nutzen kritische Schwachstellen aus! Jetzt dringend Updates installieren, um Systeme abzusichern. Mehr Details 👇
https://www.heise.de/news/Angriffe-auf-Luecken-in-Linux-Android-und-Sitecore-10633165.html
#CyberSecurity #PatchNow #newz -
Ny brist i WinRAR utnyttjas av minst två olika hackergrupper. Läs mer på bloggen:
https://kryptera.se/ny-brist-i-winrar-utnyttjas-av-minst-tva-hotaktorer/
#Cybersecurity #InfoSec #Security #Vulnerability #ZeroDay #PatchNow #WinRAR #CVE20258088 #PathTraversal #ThreatIntel #IncidentResponse #RomCom #PaperWerewolf #PhishingAlert