#CVE
43 stories taggedCVE.

A single bad character can crash a vLLM server, and the fix is still pending
A moderate-severity flaw in the popular AI serving engine lets any logged-in user kill the whole process with one malformed request.

AI Is Cutting the Time Criminals Need to Turn a Known Bug Into a Working Attack
Exploitation of already-patched flaws is outpacing zero-days, CVE volumes are on track to hit 96,000 this year, and the window between public disclosure and first attack has shrunk to 80 days.

Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited
Microsoft's September 2026 Patch Tuesday lands 964 security fixes, two of them already in active use by criminals, plus roughly 20 bugs that could spread automatically across networks.

The Race to Answer 'Are We Exposed?' Is Getting Harder
A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

Oracle Fixes More Than 800 Security Flaws in Its Biggest Patch Drop of 2026
Oracle's September 2026 Critical Security Update bundles 673 patches covering over 800 vulnerabilities. More than 240 of those flaws can be exploited remotely by anyone, no password required.

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.
A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists
A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

Vulnerability management is drowning, and AI is being sold as the lifeboat
Security teams face more software flaws than they can patch, and vendors are pitching frontier AI as the fix. Lucy Green looks at what that actually means for the people running these programmes.

Silent Software Patches Protect Hackers, Not Users
When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Oracle Pushes 943 Security Fixes in August 2026 Patch Update
Oracle's August 2026 security release closes more than 1,000 flaws across two dozen products, with nearly 90 critical bugs scoring 9.8 or higher on the industry's 0-to-10 severity scale.

Firefox and Chrome Rush Out Patches for Dozens of Security Flaws
Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

Patching Once a Month Is No Longer Enough, Rapid7 Warns
Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.