#patch
32 stories taggedpatch.

One flaw, eight Atlassian products, no login required
A critical file-access vulnerability published this month lets anyone on the internet read files inside Atlassian's most trusted enterprise tools without ever signing in.

A Fresh Citrix Zero-Day Is Already Being Exploited, and Federal Agencies Have Three Days to Fix It
CVE-2026-88779 hit live networks almost immediately after Citrix shipped patches for two earlier flaws, leaving IT teams scrambling again.

Kiteworks patches critical flaw in email gateway that let attackers seize root control
A chain of three bugs in the company's Email Protection Gateway handed unauthenticated outsiders a path to full appliance takeover. The fix is in version 9.4.1.

Apple Patches Actively Exploited Zero-Day Tied to WhatsApp Attack Chain
A graphics-processing flaw in iOS and macOS is being used in what Apple calls an 'extremely sophisticated' targeted attack. CISA gave US federal agencies three days to fix it.

Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

Three High-Severity BIND Flaws Let Attackers Crash the Internet's Phone Book
ISC patched 14 vulnerabilities in BIND 9 on 16 September 2026, including three remotely exploitable bugs that can knock DNS resolvers offline with a single crafted packet.

Check Point Fixes Two Critical VPN Flaws That Could Let Hackers In Without a Password
Both bugs score 9.8 out of 10 and affect the firewall gear that guards corporate networks.

GitLab Rushes Out Fixes for Two Critical Server Flaws, One Lets Strangers Read Private Files
A path traversal bug and a second critical flaw in GitLab's enterprise product prompted an urgent patch call for self-hosted installations.

Google Patches Fifth Chrome Zero-Day of 2022 as Attacks Continue
A flaw in how Chrome handles Android deep links is being actively exploited. It's the fifth Chrome vulnerability criminals have used in the wild this year, and the patch window is tight.

A Ten-Year-Old PostgreSQL Flaw Let a Backup Account Become a Backdoor
A security gap in widely used database software, hidden since 2014, could let a low-level account take over an entire server. Patches are out. Here's what you need to know.

WatchGuard Patches Five Critical Flaws That Could Let Attackers Seize Control Remotely
WatchGuard has fixed more than two dozen vulnerabilities in its firewall software and management tools, including five rated 9.3 out of 10 in severity.

A Single Website Visit Can Poison Your Local AI Agent, Researchers Find
A flaw in Nvidia's NemoClaw lets a malicious webpage secretly rewrite the instructions an AI assistant follows, and the damage survives every conversation that comes after.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company
A security research team chained four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.