Vulnerabilities — Page 16

Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities
Oracle releases its biggest Critical Patch Update yet, addressing severe vulnerabilities in multiple products.

Eclypsium launches InfraTrust to flag the infrastructure flaws no one is patching
A new knowledge base and monthly report from firmware security firm Eclypsium aims to tell defenders which router, firewall and server bugs to fix first.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns
CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

Adobe's Acrobat Chrome extension leaked WhatsApp Web chats to any website you visited
Researchers at Guardio Labs found a chain of flaws, tracked as CVE-2026-48294, that let any web page silently read messages, contacts and chat lists from WhatsApp Web. Adobe patched the extension within two days.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses
A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

Siemens Rushes Fix for Smart Plug Riddled With Eight Serious Flaws
The SIDIS Secured SmartPlug carried a critical 9.8-rated bug plus seven more in bundled open-source libraries. Siemens says update to V7.26.0310.

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws
Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked
CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing
When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data
An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password
The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server
The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.