Every so often a vendor decides the smart move is to fix a vulnerability quietly. No advisory, no CVE, no explanation, just the vaguest handwave in a changelog. The logic sounds reasonable on its face: if you don’t explain what… Read More "Silent Patches Don’t Stop Attackers – They Blind Defenders"
Microsoft Patches Exploited Entra ID Vulnerability
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited in attacks. The exploited Entra ID flaw is tracked as CVE-2026-69836, and it could have… Read More "Microsoft Patches Exploited Entra ID Vulnerability"
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
Cisco on Wednesday announced patches for 15 vulnerabilities across its products, including critical- and high-severity flaws in Crosswork and Secure Workload. Crosswork version 7.2.1-SP was released with fixes for four critical-severity CVEs. Three of them, CVE-2026-20030, CVE-2026-20357, and CVE-2026-20358, have… Read More "Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities"
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with… Read More "Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities"
Chrome, Firefox Updates Patch Dozens of Vulnerabilities
Google and Mozilla on Tuesday announced fresh Chrome and Firefox security updates that address multiple critical- and high-severity vulnerabilities. Firefox 154 was released to the stable channel with patches for 58 CVEs, including 20 high-severity flaws, roughly half of which… Read More "Chrome, Firefox Updates Patch Dozens of Vulnerabilities"
943 Patches Rolled Out With Oracle’s August 2026 Security Update
Oracle on Tuesday announced the release of 943 new security patches as part of the August 2026 Critical Security Patch Update (CSPU), its third monthly security rollout. The company’s advisory mentions more than 1,000 unique CVEs across two dozen products,… Read More "943 Patches Rolled Out With Oracle’s August 2026 Security Update"
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
Apple on Monday announced a fresh round of macOS, iOS, and iPadOS security updates that address dozens of vulnerabilities, most of which affect the web browser engine WebKit. macOS Tahoe 26.6.2 is now rolling out with fixes for 28 security… Read More "Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates"
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could… Read More "Fortinet Patches Authentication Flaws in FortiWeb and FortiManager"
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most… Read More "SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities"
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft on Tuesday announced patches for 421 CVEs, including a high-severity vulnerability that has been exploited in the wild as a zero-day. The exploited flaw, tracked as CVE-2026-68820, is described as a use-after-free issue in Ancillary Function Driver for WinSock… Read More "August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day"