Vulnerabilities — Page 9

Microsoft restores missing Copilot buttons in Classic Outlook
A licensing bug wiped the AI assistant's buttons from the desktop email client. Microsoft says a June 29 fix has now landed.

Adobe Rushes Out Fixes for a Dozen Flaws in ColdFusion and Campaign Classic — Six Are as Bad as It Gets
Twelve security holes, six of them rated the highest possible severity, were quietly sitting in two widely used Adobe products. Patches are out. The clock is ticking.

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
A vulnerability in SharePoint — Microsoft's widely used workplace file-sharing and collaboration platform — lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately
A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

CitrixBleed Redux: PoC Drop Triggers Immediate NetScaler Memory-Scrape Campaign
Attackers wasted no time after proof-of-concept code surfaced for a new Citrix NetScaler memory-disclosure bug — the gap between publish and exploit measured in hours, not days.

Unpatched Argo CD Flaw Turns Your GitOps Engine Into a Deployment Backdoor
A gRPC endpoint that skips authentication, network policies off by default, and Redis credentials sitting in the environment. Synacktiv's research shows how one compromised pod can become a supply-chain pivot.

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited
The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

No Patch, No CVE: Argo CD Repo-Server Flaw Opens Door to Kubernetes Cluster Takeover
Synacktiv reported the unauthenticated RCE bug to maintainers. There's still no fix.

Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic
Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Administrators face a short remediation window before public exploit code is likely.

Active Exploitation Reported Against Progress Kemp LoadMaster Pre-Auth RCE (CVE-2026-8037)
Threat responders flag in-the-wild attempts against a 9.6-rated OS command injection flaw in the load balancer, days after Progress issued a fixed build.

Citrix Patches Six NetScaler Flaws, Including HTTP/2 Bomb DoS and a CitrixBleed Echo
Citrix is pushing customers to patch NetScaler after disclosing six vulnerabilities — among them a denial-of-service vector exploiting HTTP/2 frame handling and a high-severity information disclosure bug drawing uncomfortable comparisons to last year's CitrixBleed.

Apple Ships Multi-Component Patch Round Covering iOS, macOS, and Safari
Fixes land for WebKit, the kernel, WebRTC, and Web Extensions — touching every major Apple platform in a single release cycle.

Citrix Ships Fixes for Six NetScaler Bugs, Including a File-Read Flaw Scoring 8.8
The patch batch covers NetScaler ADC and Gateway, with input-validation and DoS issues that admins should not sit on.

Langflow RCE Is Back on the Menu — This Time for a Monero Miner
Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.

SimpleHelp OIDC Bypass Gets Weaponized: TaskWeaver and Djinn Stealer Land on Unpatched Servers
An unauthenticated auth bypass scoring a perfect 10.0 is dropping two new malware families on remote-support boxes that nobody remembered were internet-facing.