Vulnerabilities
Splunk Discloses Critical Splunk Enterprise Vulnerability
The SIEM at the center of many SOCs gets a critical-priority patch — verify deployments.
Stay ahead of security risks with effective patch management. Explore strategies, tools, and processes for applying updates, fixing vulnerabilities, and protecting systems from exploits and cyberattacks.
Vulnerabilities
The SIEM at the center of many SOCs gets a critical-priority patch — verify deployments.
Vulnerabilities
Twenty-four hours separated disclosure from in-the-wild exploitation — CISA's emergency directive gives federal agencies three days to patch.
Policy & Government
CISA's new directive ends CVSS-led patching for federal agencies — risk becomes the prioritization signal, and the most dangerous bugs must be patched in three days.
Vulnerabilities
The largest Patch Tuesday on record arrives with three publicly disclosed zero-days — and a running feud with one researcher producing a steady stream of Microsoft exploits.
Vulnerabilities
The fifth in-the-wild Chrome zero-day of the year, in the V8 JavaScript engine, is now patched — but the attack pattern shows no sign of slowing.
Vulnerabilities
An AI proxy that increasingly sits between corporate apps and model providers issues a patch — defenders should verify deployments and review proxy logs.
Vulnerabilities
A patch cycle on the backup-of-record for the enterprise — high-priority, given the ransomware-response context.
Vulnerabilities
A use-after-free in the Linux kernel's nf_tables code — patched in February, exploited publicly in June — shows how a single misplaced character in a critical subsystem becomes the keystone of a privilege-escalation chain.
Vulnerabilities
Cisco patched CVE-2026-20230, an unauthenticated server-side request forgery flaw in Unified Communications Manager that lets a network attacker write files and escalate to root. Public proof-of-concept code is already out; Cisco's PSIRT reports no in-the-wild exploitation yet.
Vulnerabilities
Two vulnerabilities disclosed this cycle were found by AI tooling: HTTP/2 Bomb (CVE-2026-49975), a remote DoS that crashes NGINX, Apache, IIS, Envoy and Cloudflare Pingora in default config, and CVE-2026-23479, a two-year-old authenticated RCE in Redis.
Vulnerabilities
Two more plugin RCEs are under active exploitation: Everest Forms Pro CVE-2026-3300 (CVSS 9.8), a PHP-injection flaw Wordfence has blocked tens of thousands of times, and Magento's Mirasvit Cache Warmer CVE-2026-45247 (CVSS 9.8), now added to CISA's KEV catalog.
Vulnerabilities
A critical flaw in the Kirki WordPress plugin (CVE-2026-8206, CVSS 9.8) lets an unauthenticated attacker send any account's password-reset link — including an admin's — to their own email and seize it. Versions 6.0.0–6.0.6 are fixed in 6.0.7; BleepingComputer reports exploitation.