Vulnerabilities — Page 14

RoguePlanet PoC Drops: Another Defender Race Condition, Another Path to SYSTEM
An anonymous researcher publishing as Chaotic Eclipse dropped a proof-of-concept against Microsoft Defender that wins SYSTEM on fully patched Windows — when the race goes their way.

protobuf.js Ships Six Bugs That Turn Schemas Into RCE Triggers
A single malicious descriptor is enough. Node.js services parsing untrusted Protobuf are the obvious blast radius.

Microsoft Ships Record 200-Bug Patch Tuesday as 'Nightmare Eclipse' Drops Windows Zero-Days
AI-assisted bug hunting, a confrontational researcher, and a Shai-Hulud worm variant inside Microsoft's own repos shape an outsized June rollup.

Microsoft Ships KB5094127 ESU as Secure Boot Cert Rollover Looms
The June 2026 extended security update for Windows 10 patches Patch Tuesday bugs and adds telemetry to track the Secure Boot certificate transition.

Veeam Patches 9.4-Severity RCE in Backup & Replication; Domain Auth Required
CVE-2026-44963 lets any authenticated domain user run code on the backup server. Veeam shipped fixes Tuesday.

Chrome Ships Emergency V8 Fix for CVE-2026-11645 Already Under Attack
An out-of-bounds read/write in V8 is being exploited in the wild. Google's update covers 74 issues. Patch, then verify your browser fleet actually restarted.

Check Point Issues Emergency Patches After IKEv1 Auth Bypass Draws Qilin Affiliate
Two certificate-validation flaws in Check Point's VPN stack — one already exploited, one caught during the ensuing review — have prompted hotfixes across nine Quantum software versions.

Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation
A command-injection bug in Catalyst SD-WAN Manager is already being used in the wild. No patch exists yet — and a known espionage group may be involved.

Public Exploit Drops for nf_tables UAF: CVE-2026-23111 Gives Local Root, Container Escape
Exodus Intelligence published a full walkthrough four months after the upstream patch. The kernel bug is a one-liner. The exploit is not.

Six Flaws in protobuf.js Turn Serialized Schemas Into Execution Vectors
The JavaScript Protocol Buffers library — pulled 50 million times a week — ships patches for a cluster of CVEs that let attackers use schema metadata to run arbitrary code inside Node.js processes.

Check Point Confirms Active Exploitation of IKEv1 Cert-Bypass Flaw in Remote Access VPN
CVE-2026-50751 lets unauthenticated attackers slip past authentication on gateways still running the deprecated IKEv1 key exchange. Patch is out. Exploitation is not theoretical.

Schema as Weapon: Six Flaws in protobuf.js Open a Path to Remote Code Execution
Cyera researchers found that protobuf.js — pulled into apps 50 million times a week — will, under exploitable conditions, turn schema metadata into running code.

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft
A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

CISA Flags SolarWinds Serv-U DoS Bug as Actively Exploited
CVE-2026-28318 crashes the file transfer service. Federal agencies get the usual three-week patch window.

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes
An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.