Vulnerabilities — Page 5

Microsoft ships fixes for 570 flaws in July, including two bugs already used in attacks
The July 2026 Patch Tuesday is the largest on record, driven partly by an AI system Microsoft is using to hunt bugs in Windows.

Microsoft Ships July 2026 Patch Tuesday: 571 Fixes, Better AirPods Pairing, and a Quieter Widgets Panel
The mandatory Windows 11 update rolls up months of security holes and finally tames Bluetooth pairing gremlins. Here is what it actually changes on your PC.

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion
Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

Progress ShareFile zero-day forced emergency server shutdowns; patch is out
A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

RabbitMQ Bugs Could Have Handed Attackers the Keys to Corporate Messaging
Two access control flaws in the widely used RabbitMQ broker exposed OAuth secrets and let one tenant peek at another's data.

You Don't Need to Fire the Exploit to Know You're Exposed
A quieter way to test whether a vulnerability actually threatens your network: check the steps an attacker would need, not the payload itself.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns
A security firm reported the flaw seven months ago. Cursor has yet to patch it.

Eleven Old Microsoft-Signed Boot Files Could Let Hackers Slip Past Secure Boot
Researchers say the signed UEFI applications, still trusted by most PCs, can be used to load malicious code before Windows even starts.

KU Leuven Researchers Find 85 Browser Crypto Wallets Leak User Data
Academic study says the way popular wallet extensions talk to websites lets outsiders link separate crypto addresses to the same person.

SAP Patches Critical Flaws in NetWeaver, Approuter, and Commerce Cloud
Three SAP products used by thousands of businesses worldwide carried serious security holes. Patches are now available, and anyone running the affected software should move fast.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years
A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems
A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.