home.social

#patchnow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #patchnow, aggregated by home.social.

fetched live
  1. 📰 Ivanti Patches Critical RCE Flaws in Endpoint Manager

    Ivanti has patched several critical, remotely exploitable vulnerabilities in its Endpoint Manager (EPM) solution. The flaws could lead to RCE and full endpoint compromise. Given Ivanti's history as a target, patch now. #Ivanti #RCE #PatchNow

    🔗 cyber.netsecops.io/articles/iv

  2. 📰 CISA Adds Progress Kemp LoadMaster Flaw to KEV Catalog After Exploits

    🚨 CISA KEV ALERT: A critical command injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) is actively exploited. Unauthenticated attackers can gain full control. Federal agencies must patch by Aug 10. #CVE #CISA #KEV #PatchNow

    🔗 cyber.netsecops.io/articles/pr

  3. 🟡 New security advisory:

    CVE-2026-20316 affects Cisco Secure Firewall Management Center.

    • Impact: Security weakness that could be exploited
    • Risk: Potential for targeted attacks
    • Mitigation: Schedule patching in your next maintenance window

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #CVE #PatchNow #InfoSecCommunity

  4. VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. radar.offseq.com/threat/critic #OffSeq #VMware #Vuln #PatchNow

  5. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  6. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  7. ⚠️ New security advisory:

    CVE-2026-23698 affects multiple systems.

    • Impact: Significant security breach potential
    • Risk: Unauthorized access or data exposure
    • Mitigation: Apply patches within 24-48 hours

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  8. 🔴 New security advisory:

    CVE-2026-58138 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #InfoSec #PatchNow #InfoSecCommunity

  9. 🚩 Ivanti Sentry hit by two CRITICAL vulns: OS command injection (code exec as root) & auth bypass (rogue admin creation). Affects R10.5.2, R10.6.2, R10.7.1. Patch now — no exploitation seen yet. radar.offseq.com/threat/ivanti #OffSeq #Ivanti #Vulnerability #PatchNow

  10. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  11. 📰 Google Patches Fifth Actively Exploited Chrome Zero-Day of 2026

    ⚠️ Google patches its FIFTH Chrome zero-day this year! CVE-2026-11645 is a high-severity V8 bug actively exploited in the wild. Update your browser to version 149.0.7827.103+ immediately! #CyberSecurity #ZeroDay #GoogleChrome #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/go

  12. 📰 CISA Mandates Patch for Actively Exploited SolarWinds DoS Flaw Added to KEV Catalog

    📢 CISA KEV ALERT! An actively exploited DoS flaw (CVE-2026-28318) in SolarWinds Serv-U is on the loose. Federal agencies must patch by June 19. All orgs using Serv-U are urged to update immediately! 🚨 #CVE #SolarWinds #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  13. 📰 Critical RCE Flaw (CVE-2026-0826) in HP Poly VoIP Phones Allows Root Takeover

    📢 CRITICAL FLAW: A 9.2 CVSS RCE bug (CVE-2026-0826) affects HP Poly VoIP phones. The flaw allows unauthenticated root access. HP has released patches. Update now! #CVE #Vulnerability #RCE #VoIP #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/cr

  14. Oracle's May 2026 CSPU patches 77 vulnerabilities, including a dozen CRITICAL, remotely exploitable flaws in Database Server, E-Business Suite, and more. Immediate patching is advised — risk of active exploitation remains high. radar.offseq.com/threat/oracle #OffSeq #Oracle #PatchNow

  15. 🔔 Oracle May 2026 CSPU covers 35 CVEs — 11 critical, 18 high. E-Business Suite & REST Data Services most affected. Remote, unauthenticated exploits possible. Apply patches ASAP! radar.offseq.com/threat/oracle #OffSeq #Oracle #VulnAlert #PatchNow

  16. 📰 Active Exploitation of Critical FortiClient EMS Flaw (CVE-2026-35616) Used to Deploy Credential Stealers

    📢 ACTIVE EXPLOITATION: A critical FortiClient EMS flaw (CVE-2026-35616, CVSS 9.1) is being used to push credential stealers to all managed endpoints via PowerShell. Update to version 7.4.7 NOW. 🛡️ #Fortinet #CyberAttack #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/fo

  17. 📰 CISA Mandates Urgent Patch for Actively Exploited LiteSpeed cPanel Flaw Granting Root Access

    ⚠️ CRITICAL ALERT: CISA adds LiteSpeed cPanel plugin flaw (CVE-2026-48172) to its KEV catalog. The bug allows for root access and is actively exploited. Patch immediately! #CVE #LiteSpeed #cPanel #CyberSecurity #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  18. ⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. radar.offseq.com/threat/cisa-g #OffSeq #vuln #patchnow

  19. ⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. radar.offseq.com/threat/cisa-g #OffSeq #vuln #patchnow

  20. 📰 Critical 18-Year-Old 'NGINX Rift' Vulnerability (CVE-2026-42945) Under Active Attack

    🚨 CRITICAL NGINX FLAW! An 18-year-old bug 'NGINX Rift' (CVE-2026-42945) is actively exploited for DoS & RCE. Affects millions of web servers. Patch immediately! #NGINX #CVE #Infosec #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ng

  21. 🟡 New security advisory:

    CVE-2026-9082 affects multiple systems.

    • Impact: Security weakness that could be exploited
    • Risk: Potential for targeted attacks
    • Mitigation: Schedule patching in your next maintenance window

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  22. 📰 Warning: Microsoft Defender Flaws Actively Exploited to Gain SYSTEM Privileges

    ⚠️ ACTIVE EXPLOITATION ALERT: Flaws in Microsoft Defender (CVE-2026-41091, CVE-2026-45498) are being used by attackers to gain SYSTEM privileges and disable AV. Patch the Malware Protection Engine immediately! #CyberSecurity #Vulnerability #PatchNow

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/mi

  23. ⛔ New security advisory:

    CVE-2026-32985 affects multiple systems.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  24. A third party report highlights a critical auth bypass in AdGuard Home that could grant admin control to attackers. Users are urged to patch immediately and review access controls. 🛡️🔧 Update to the latest release and rotate credentials. More: cyberinsider.com/adguard-home- #CyberSecurity #AdGuardHome #Vulnerability #PatchNow

  25. 📢⚠️🩹 #Cisco has patched 48 vulnerabilities in its Secure Firewall products, including 2 critical CVSS 10 flaws that could allow authentication bypass and remote code execution with root access - Patch NOW!

    Read: hackread.com/cisco-patches-fir

    #CyberSecurity #Vulnerability #PatchNow

  26. ⛔ New security advisory:

    CVE-2026-1435 affects Graylog Graylog.

    • Impact: Remote code execution or complete system compromise possible
    • Risk: Attackers can gain full control of affected systems
    • Mitigation: Patch immediately or isolate affected systems

    Full breakdown:
    yazoul.net/advisory/cve/cve-20

    #Cybersecurity #PatchNow #InfoSecCommunity

  27. Microsoft warnt vor einer kritischen 0‑Day‑Lücke in Microsoft Office und ruft zur sofortigen Installation des Notfall‑Updates auf. um Unternehmen und Nutzer vor aktiven Angriffen zu schützen. 🛡️🧩 Mehr Infos: heise.de/news/Notfall-Update-g #Microsoft #Office #Security #ITSecurity #PatchNow

    #OnlyOffice ist auch sehr gut onlyoffice.com/de/download-des

  28. Microsoft has rushed out an emergency security update for Office (CVE‑2026‑21509) after confirming the flaw is already being exploited in the wild. 🔐

    The high‑severity security feature bypass lets attackers bypass OLE protections and run malicious code via specially crafted Office files. 📄⚠️

    👉 Microsoft issues emergency fix for actively exploited Office flaw:
    cyberinsider.com/microsoft-iss
    #Microsoft #Office #Security #CVE202621509 #PatchNow

    Threre is also #OnlyOffice

    onlyoffice.com/download-desktop

  29. CISA warnt vor aktiven Angriffen auf Apple-WebKit-Lücken und Gladinet-Dienste – Updates sind bereits verfügbar. 🚨🔐 Wer iOS, macOS & Co. nutzt, sollte jetzt patchen, bevor Angreifer nachziehen. 👉 heise.de/news/Updaten-Warnung- #CyberSecurity #Apple #PatchNow #Newz

  30. Cybersecurity Weekly Roundup (Nov 16–22)

    Chrome zero day; Oracle Identity Manager RCE (KEV); FortiWeb exploited; SonicWall SSLVPN flaw; Cloudflare outage; WhatsApp enumeration. Plus: Logitech breach, 7-Zip PoC, Salesforce/Gainsight ripple, Dutch takedown.

    Actions: Patch edge first, push Chrome, rotate keys and OAuth, rehearse failover.

    Read: kylereddoch.me/blog/cybersecur

    #Cybersecurity #Infosec #MSP #BlueTeam #PatchNow

  31. 🚨 Fortinet has released patches for two actively exploited vulnerabilities in its #FortiWeb web-application firewalls. One allows full takeover, the other enables command injection.

    Update now: hackread.com/fortinet-fixes-fo

    #Cybersecurity #InfoSec #Vulnerability #Fortinet #PatchNow

  32. 🚨 Urgent patch alert: a 9.9/10 severity flaw (CVE-2025-42887) in #SAP Solution Manager allows code injection and full system takeover. Act now.

    Read: hackread.com/sap-patch-cve-202

    #CyberSecurity #Vulnerability #ZeroDay #InfoSec #PatchNow

  33. CISA just confirmed a nasty Windows SMB bug (CVE-2025-33073) is being actively exploited.

    It lets an attacker gain SYSTEM privileges by tricking a machine into connecting to a bad SMB server.

    All Windows Server versions, Win10, and Win11 are affected. A patch was released in June 2025.

    CISA has officially added it to their must-patch (KEV) list.

    #CyberSecurity #Windows #CVE #PatchNow

    bleepingcomputer.com/news/secu

    #CyberSecurity #InfoSec #CVE #Windows #SMB #CISA #Vulnerability

  34. 🚨 CISA warns of active attacks on Linux, Android & Sitecore! 🐧📱🖥️ High & critical risks: privilege escalation & code injection. Updates available—patch now! More on CVEs & risks👇 #Cybersecurity #InfoSec #PatchNow #newz

    heise.de/en/news/Attacks-on-vu