Vulnerabilities — Page 3

Full-frame photoreal editorial image of a dimly lit corporate server room with rows of blue-lit racks, a soft red warning glow pulsing from one rack indicating
Vulnerabilities

US government orders emergency patch for critical Oracle finance software flaw

CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

4 min read
Photoreal news-editorial shot of a dimly lit enterprise telecom server rack with VoIP gateway hardware and blinking amber status LEDs, blue-green ambient light
Vulnerabilities

F5 Fixes Serious Security Flaws in NGINX and BIG-IP

Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.

3 min read
Photoreal news-editorial overhead view of a developer workstation with a glowing terminal window and an open code editor, abstract cloud-shaped server racks in
Vulnerabilities

AI Is Finding Software Flaws Faster Than Companies Can Fix Them. Something Has to Change.

Security experts are calling time on the old 'scan once a month, patch when you can' model. Artificial intelligence now finds vulnerabilities faster than human teams can close them.

3 min read
Photoreal editorial shot of a dimly lit server rack with amber warning LEDs reflecting off polished metal, rows of patch cables in soft focus, cool blue ambient
Vulnerabilities

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday

A prolific anonymous researcher drops yet another unpatched Windows flaw, this time one that lets ordinary users quietly take control of administrator accounts.

3 min read
Photoreal news-editorial 16:9 image of a dense tangle of fiber optic cables glowing under pressure in a dark server room, light fragmenting through the cables a
Vulnerabilities

Four Security Firms Patch Serious Flaws in Their Own Products

Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

3 min read
Full-frame photoreal editorial image of a close-up Windows laptop screen showing a generic blue security shield icon glowing, with faint reflection on a dark de
Vulnerabilities

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System

Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

3 min read
Extreme close-up of a glowing green terminal screen filled with cascading lines of package dependency text and vulnerability identifiers, shot from a low angle
Vulnerabilities

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks

Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

3 min read
Photoreal news-editorial image, full-frame 16:9, edge to edge
Vulnerabilities

Zoom patches critical Windows flaw that could hand attackers your account

A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

3 min read
Photoreal news-editorial image of a darkened enterprise network operations center, glowing amber warning indicators reflecting off polished server racks, blurre
Vulnerabilities

Popular AI Code Editor Cursor Has an Unpatched Flaw That Runs Malicious Files Automatically

A security firm disclosed the bug seven months ago. Cursor has still not patched it, leaving more than seven million developers exposed.

3 min read
Full-frame photoreal editorial shot of a modern laptop on a dark desk, screen glowing with an abstract orange and blue browser update notification, soft depth o
Vulnerabilities

Firefox Rushes Out Fix After Attack Code for Two Critical Bugs Appears Online

Mozilla says working exploit code is already public for two serious flaws in its browser. Users should update now.

3 min read
Overhead 16:9 editorial photo of a silver Apple laptop sitting open on a dark matte desk, its screen glowing with a faint green terminal-style light, surrounded
Vulnerabilities

A Hidden Door in Windows: How Attackers Can Blind Security Software to Malware

Researchers at Bitdefender have shown how a little-known Windows feature called bind links can be twisted to make malicious files invisible to the tools companies rely on to catch intrusions.

3 min read
Photoreal news-editorial shot of a darkened server room with a single Windows laptop open on a rack shelf, screen glowing pale blue with abstract registry-tree
Vulnerabilities

Researcher Publishes Windows Privilege-Escalation Exploit Hours After Microsoft's Monthly Patch

A proof-of-concept called LegacyHive targets the Windows User Profile Service, raising fresh questions about coordinated disclosure timing.

3 min read
Photoreal editorial shot of a developer's dark home office desk at night, a laptop open showing an abstract code editor interface with warning-red highlights on
Vulnerabilities

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning

A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

4 min read
Full-frame 16:9 photoreal editorial image of a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED, shallow de
Vulnerabilities

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform

A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, blue and amber status LEDs glowing, one server unit slightly pulled
Vulnerabilities

CISA sounds alarm on SharePoint Server flaws being used to break in right now

The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

3 min read
© 2026 Threat Vectr