#patch management
114 stories taggedpatch management.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

Six Critical Flaws in Adobe Connect Could Let Attackers Take Over Accounts
Two of the worst bugs require no action from the victim. Adobe wants patches applied within 30 days, but one score of 9.9 makes that window feel generous.

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped
A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

Meltdown and Spectre Opened a Door That Won't Fully Close
Seven years on from the chip flaws that rewrote the rules of hardware security, dozens of variants keep arriving. Here's what ordinary users need to understand about vulnerabilities baked into the silicon itself.

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.
A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

WordPress 7.1.1 Fixes a Flaw That Could Install a Theme on an Admin's Click
The maintenance release patches 11 security bugs, including a Click2Shell chain that abuses a logged-in administrator's browser session.

CISA Is Scrapping Its Weekly Vulnerability Bulletin
The agency is retiring its regular digest of known security flaws in favour of a new directive that tells federal agencies to patch based on real-world danger, not scores on a chart.

Cisco Patches Eight Flaws in Network Software Used by Telecoms Worldwide, Two Rated Near-Maximum Severity
Cisco's own engineers found the vulnerabilities using artificial intelligence tools. No fixes exist beyond the patches, and two of the flaws score 9.8 out of 10 on the standard severity scale.

Ivanti Fixes Critical Security Holes in Three Business Software Products
Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

The Race to Answer 'Are We Exposed?' Is Getting Harder
A new CVE drops and the clock starts. Security teams still hop between six tools to find out if it matters. AI is making that lag more dangerous.

AMD, Arm, and Nvidia Fix Security Flaws in Graphics and AI Chips
Three of the world's biggest chipmakers released patches this week for flaws that could let attackers crash systems or quietly read private data. Here is what each company fixed and who needs to act.

Hackers Are Exploiting a Fortinet Flaw to Plant Remote-Control Malware on Network Devices
A security bug in Fortinet's firewall and switch software is being used to silently take over devices and steal data. More than 178 machines are already infected, attacks have been running since at least July 2026, and the US government is telling federal agencies they have three days to patch.

CISA Warns of Active Attacks on Critical NetScaler Flaw
Federal agencies have three days to patch CVE-2026-19490 after CISA confirmed criminals are actively exploiting the high-severity flaw in Citrix's widely used network gateway software.

The Week's Security Mess: Why Did Any of This Work in the First Place?
From greedy browser extensions to phishing pages built inside trusted services, this week's incidents share one uncomfortable answer.

Hackers Chain Two JFrog Artifactory Bugs to Plant Backdoors on Unpatched Servers
Wiz tracked the attacks from August 15 to September 8. Both flaws were already fixed. Servers that skipped the update paid the price.