Vulnerabilities — Page 3

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.
Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday
A prolific anonymous researcher drops yet another unpatched Windows flaw, this time one that lets ordinary users quietly take control of administrator accounts.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Zoom patches critical Windows flaw that could hand attackers your account
A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

Popular AI Code Editor Cursor Has an Unpatched Flaw That Runs Malicious Files Automatically
A security firm disclosed the bug seven months ago. Cursor has still not patched it, leaving more than seven million developers exposed.

Firefox Rushes Out Fix After Attack Code for Two Critical Bugs Appears Online
Mozilla says working exploit code is already public for two serious flaws in its browser. Users should update now.

A Hidden Door in Windows: How Attackers Can Blind Security Software to Malware
Researchers at Bitdefender have shown how a little-known Windows feature called bind links can be twisted to make malicious files invisible to the tools companies rely on to catch intrusions.

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch
A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform
A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

CISA sounds alarm on SharePoint Server flaws being used to break in right now
The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.