PaperCut Zero-Day Patch Urged
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
30 results for “patch”
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
Adobe and Nvidia address dozens of vulnerabilities, including critical flaws in AI infrastructure and GPU attack mitigations.
Microsoft says the time to patch vulnerabilities is shrinking, urging network-level controls to bridge the gap.
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
Printing and PDF export fail in some WPF apps after August 2026 .NET updates; Microsoft offers a risky workaround.
CVE-2026-18963 allows full account takeover via reset flow; patches out.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
GitLab's CVE-2026-19478 is under active exploitation, days after disclosure, urging immediate patching.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
Experts discuss if detection-first security can keep pace as AI accelerates exploitation and shrinks patch-to-exploit timelines.
CISA orders federal agencies to fix actively exploited Ray bug in 3 days, citing unique risk.
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.
AI is supercharging both bug discovery and bug creation, driving patch counts to record highs — and reshaping how software gets fixed.
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
SecurityOracle's new Database Security Central tool is free until February 2027, arriving amid rising database attacks.
A growing backlog of unresolved vulnerabilities is not a security problem but an organizational failure of ownership, capacity, and decision-making.
Adobe Commerce bug CVE-2026-71362 was exploited within hours of disclosure; Sansec reports active attacks.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
A researcher's PoC bypasses Microsoft's Defender patch, granting system-level access to attackers with initial foothold.
ACRO's unpatched Kentico CMS exposed sensitive data of up to 10,920 people, with alerts unread for months.
Attacks exploiting CVE-2026-59310 target hundreds of victims, deploying reverse_ssh for persistent access.
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
August 2026 ICS Patch Tuesday advisories from Siemens, Schneider Electric, Phoenix Contact address critical vulnerabilities, including a maximum-severity flaw in Siemens IoT devices.
Microsoft's August 2026 Patch Tuesday brings mandatory updates for Windows 11, adding security fixes and new features like Voice Isolation.