Tag

#CVE

43 stories taggedCVE.

Illustration: a dark server rack with a single blade pulled halfway out, cooling fans still spinning
Vulnerabilities

A single bad character can crash a vLLM server, and the fix is still pending

A moderate-severity flaw in the popular AI serving engine lets any logged-in user kill the whole process with one malformed request.

3 min read
Illustration: rows of blinking server rack indicator lights in a dimly lit data centre
Vulnerabilities

AI Is Cutting the Time Criminals Need to Turn a Known Bug Into a Working Attack

Exploitation of already-patched flaws is outpacing zero-days, CVE volumes are on track to hit 96,000 this year, and the window between public disclosure and first attack has shrunk to 80 days.

4 min read
A Windows update installation screen showing a progress bar at completion, with security patch notification badges and version numbers visible in the background
Vulnerabilities

Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited

Microsoft's September 2026 Patch Tuesday lands 964 security fixes, two of them already in active use by criminals, plus roughly 20 bugs that could spread automatically across networks.

4 min read
A security operations center with six different security dashboards and tools displayed across multiple monitors, with a CVE notification appearing on one scree
Vulnerabilities

The Race to Answer 'Are We Exposed?' Is Getting Harder

A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

3 min read
An Oracle data center or server infrastructure with multiple systems simultaneously receiving security patches, represented by flowing update data and progress
Vulnerabilities

Oracle Fixes More Than 800 Security Flaws in Its Biggest Patch Drop of 2026

Oracle's September 2026 Critical Security Update bundles 673 patches covering over 800 vulnerabilities. More than 240 of those flaws can be exploited remotely by anyone, no password required.

3 min read
A software developer's workstation with multiple monitors displaying code repositories and vulnerability scanning tools, with notification alerts cascading acro
AI Security

AI Is Finding Software Flaws Faster Than Anyone Can Fix Them. Here's Why Experts Say Don't Panic Yet.

A new report tracked nearly 40,000 software vulnerability reports across a year of real data. The headline number is alarming. The fine print is more reassuring.

4 min read
A security analyst's desk with multiple monitors displaying vulnerability scanning software dashboards, with one screen highlighting early-warning alerts appear
Vulnerabilities

Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists

A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

4 min read
A security team's war room with walls covered in charts and graphs showing vulnerability backlogs, patch management timelines, and AI-powered threat assessment
Opinion

Vulnerability management is drowning, and AI is being sold as the lifeboat

Security teams face more software flaws than they can patch, and vendors are pitching frontier AI as the fix. Lucy Green looks at what that actually means for the people running these programmes.

3 min read
A corporate development environment showing Spring framework code with security patches being silently applied in the background, while a security team at separ
Policy & Regulation

Silent Software Patches Protect Hackers, Not Users

When companies fix security flaws without telling anyone, the people paid to defend your data are flying blind. A new Broadcom programme for its Spring software framework shows exactly how that plays out.

4 min read
A Microsoft security patch notification dashboard showing 22 fixes rolling out across cloud services, with six critical severity indicators glowing red at maxim
Vulnerabilities

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity

A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

3 min read
A software company's website or dashboard visible on screen with security advisory banners prominently displayed, showing patch release notifications and update
Vulnerabilities

Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs

Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

3 min read
A large digital display in a software company showing a rolling list of hundreds of security patches and fixes being deployed, with critical severity indicators
Vulnerabilities

Oracle Pushes 943 Security Fixes in August 2026 Patch Update

Oracle's August 2026 security release closes more than 1,000 flaws across two dozen products, with nearly 90 critical bugs scoring 9.8 or higher on the industry's 0-to-10 severity scale.

3 min read
Browser windows for both Firefox and Chrome open side-by-side, each displaying security update notifications with patch notes listing dozens of vulnerability fi
Vulnerabilities

Firefox and Chrome Rush Out Patches for Dozens of Security Flaws

Mozilla fixed 58 vulnerabilities in Firefox 154, while Google addressed 15 in Chrome 151, including two critical bugs that could let attackers run malicious code on your device.

3 min read
A calendar showing traditional monthly patch days with a rapidly growing pile of unpatched vulnerabilities cascading across subsequent weeks, visualized as an o
Vulnerabilities

Patching Once a Month Is No Longer Enough, Rapid7 Warns

Security firm Rapid7 says the old model of fixing software flaws on a fixed schedule is breaking down, as the number of new vulnerabilities grows faster than most organisations can respond.

3 min read
A vast digital database visualization showing cascading vulnerability reports flooding a screen, with AI algorithms processing the data stream indicated by anim
Policy & Regulation

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?

The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

4 min read
© 2026 Threat Vectr