New Record in Microsoft Patches
Microsoft fixes 974 flaws, including two exploited zero-days, but only a few matter to most orgs.
30 results for “patches”
Microsoft fixes 974 flaws, including two exploited zero-days, but only a few matter to most orgs.
Google moves Chrome to a two-week release cycle to speed security patches and feature delivery.
Broadcom patched one critical and one high-severity VMware Workstation and Fusion vulnerability, both enabling host code execution.
Microsoft's cloud patches, Dropbox account breaches, and Guardio's $1.1B funding round headline this week's security news.
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.
Patches cover three critical code injection bugs and a sandbox escape in the Now Platform.
CVE-2026-18963 allows full account takeover via reset flow; patches out.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
AI is supercharging both bug discovery and bug creation, driving patch counts to record highs — and reshaping how software gets fixed.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
Critical SQL injection flaw in Metabase allowed zero-day attacks; urgent patches released for self-hosted users.
Cisco has released security patches addressing two dozen vulnerabilities across its product lines, including several critical defects.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
A newly public exploit targeting GitLab reveals how silent patches for library bugs can leave critical vulnerabilities exposed.
A sophisticated campaign by the threat group Laundry Bear has bypassed user interaction to harvest sensitive government data.
A sophisticated threat actor utilized zero-day exploits to gain deep access to SonicWall VPN appliances before official patches existed.
F5 has issued an urgent series of patches addressing eight critical and high-severity vulnerabilities across its NGINX and BIG-IP lines.
Mozilla, Google, Adobe, and VMware issue urgent security patches to address a wave of critical vulnerabilities across major platforms.
Siemens, Schneider Electric, and Rockwell Automation have issued urgent security patches for critical industrial infrastructure.
Enterprise security teams must prioritize patches for severe vulnerabilities across NetWeaver and Commerce Cloud environments.
A set of seven severe vulnerabilities in the VMware Avi Load Balancer has been addressed following reports from external researchers.
Microsoft has addressed the RoguePlanet vulnerability, ending a contentious saga with security researcher Nightmare Eclipse.
Microsoft's latest record-breaking security cycle highlights the mounting pressures of AI-driven vulnerability discovery and exploitation.