Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
About This Hashtag
#patchnow
18 posts
Last used 2d
#patchnow
18 posts· Last used 2d
The WordPress 7.1.1 security release fixes 11 flaws, including stored cross-site scripting and path traversal. Update your sites immediately.
#WordPress #WordPress711 #WebSecurity #XSS #CMS #Vulnerability #InfoSec #PatchNow #CyberSecurity #WebDev
https://securityonline.info/wordpress-7-1-1-security-release/?utm_source=mastodon&utm_medium=jetpack_social
Cisco patched 18 Secure Firewall vulnerabilities in FMC, ASA, and FTD, including critical unauthenticated root remote code execution flaws. Update now.
#Cisco #SecureFirewall #FMC #ASA #FTD #CVE #RCE #NetworkSecurity #InfoSec #PatchNow
https://securityonline.info/cisco-secure-firewall-vulnerabilities-september-2026/?utm_source=mastodon&utm_medium=jetpack_social
MongoDB fixed 24 MongoDB Server vulnerabilities, including a critical auth bypass (CVE-2026-82067) and unauthenticated denial of service flaws. Patch now.
#MongoDB #Vulnerability #CVE #DatabaseSecurity #DenialOfService #InfoSec #PatchNow #CyberSecurity #MongoDBServer #AppSec
https://securityonline.info/mongodb-server-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-59346, a critical VMware Workstation vulnerability, lets an attacker escape a guest VM and execute code on the host. Broadcom rates it 9.3 CVSS.
#VMware #Workstation #Fusion #CVE202659346 #VMXNET3 #Broadcom #InfoSec #PatchNow
https://securityonline.info/vmware-cve-2026-59346-code-execution-host/?utm_source=mastodon&utm_medium=jetpack_social
This weekly CVE report covers 1,877 new CVEs and 6 actively exploited flaws added to CISA KEV, including N-able, TeamCity, and Langflow bugs.
#CVE #CISAKEV #VulnerabilityManagement #InfoSec #PatchNow #CyberSecurity
https://securityonline.info/weekly-cve-report-august-2026/?utm_source=mastodon&utm_medium=jetpack_social
A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now.
#Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec
https://securityonline.info/veeam-one-cve-2026-64633-rce/?utm_source=mastodon&utm_medium=jetpack_social
The latest GitLab patch release fixes 13 vulnerabilities, including CVE-2026-6267, a high-severity data exposure flaw. Update self-managed GitLab now.
#GitLab #CVE20266267 #DevSecOps #Vulnerability #PatchNow #InfoSec
https://securityonline.info/gitlab-patch-release-19-2-1/?utm_source=mastodon&utm_medium=jetpack_social
🟡 New security advisory:
CVE-2026-20316 affects Cisco Secure Firewall Management Center.
• Impact: Security weakness that could be exploited
• Risk: Potential for targeted attacks
• Mitigation: Schedule patching in your next maintenance window
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-20316-fmc-static-credentials-leak-sensitive-data
#CVE #PatchNow #InfoSecCommunity
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation.
#Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow
http://securityonline.info/konnectivity-vulnerability-cve-2026-16242/?utm_source=mastodon&utm_medium=jetpack_social
Google's Chrome security update fixes four high-severity bugs, including CVE-2026-16807, a Codecs flaw that could enable a sandbox escape. Update now.
#Chrome #ChromeUpdate #SandboxEscape #UseAfterFree #Google #PatchNow
https://securityonline.info/chrome-150-security-update-2/?utm_source=mastodon&utm_medium=jetpack_social
An HTTP/2 DoS vulnerability lets unauthenticated attackers exhaust server memory via stalled flow control. CVE-2026-59762 and CVE-2026-59173 are patched.
#HTTP2 #DoS #DenialOfService #CVE202659762 #CVE202659173 #FlowControl #InfoSec #PatchNow
http://securityonline.info/http2-dos-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Google's Chrome security update patches 12 high-severity flaws in Chrome 150, including V8 and WebAudio bugs. Update to 150.0.7871.181 today.
#Chrome #GoogleChrome #Vulnerability #Cybersecurity #PatchNow #V8 #WebAudio
https://securityonline.info/chrome-security-update-12-flaws/?utm_source=mastodon&utm_medium=jetpack_social
Zimbra 10.1.20 fixes multiple Zimbra vulnerabilities, including an SNMP command injection flaw and several XSS bugs. Admins should upgrade now.
#Zimbra #Zimbra10120 #Vulnerability #XSS #SNMP #Cybersecurity #PatchNow
https://securityonline.info/zimbra-10-1-20-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.
#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow
https://securityonline.info/wp2shell-wordpress-core-rce/?utm_source=mastodon&utm_medium=jetpack_social
Microsoft patched the RoguePlanet Microsoft Defender zero-day, CVE-2026-50656, a race condition that grants SYSTEM privileges. A public PoC exists.
#MicrosoftDefender #RoguePlanet #ZeroDay #CVE #PrivilegeEscalation #Windows #InfoSec #PatchNow
https://securityonline.info/rogueplanet-defender-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
Foxit fixed 28 flaws in Foxit PDF Reader and PDF Editor. Twenty allow arbitrary code execution via crafted PDFs. Update to 2026.1.2 now.
#Foxit #FoxitPDFReader #ArbitraryCodeExecution #PDFSecurity #CVE #PatchNow #InfoSec
https://securityonline.info/foxit-pdf-reader-code-execution/?utm_source=mastodon&utm_medium=jetpack_social
⚠️ New security advisory:
CVE-2026-23698 affects multiple systems.
• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-23698-vtiger-crm-lets-admins-upload-webshells-poc
#Cybersecurity #PatchNow #InfoSecCommunity
CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/07/07/cisa-adds-three-known-exploited-vulnerabilities-catalog
#CISA #cybersecurity #infosec #patchnow #vulnerabilitymanagement #KEV
You've seen all posts