#patch management
88 stories taggedpatch management · page 2 of 6.

Broadcom Patches Three Critical VMware Bugs, Including a vCenter Login Bypass
One flaw lets an attacker skip the login screen on vCenter entirely. Two more allow code execution and virtual machine escape across ESX, Workstation and Fusion.

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control
Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.

AI Is Shrinking the Time Between Bug and Break-In. Playbooks Haven't Caught Up.
Vendors are pitching AI-driven vulnerability tools like Mythos as the answer. The harder question is what defenders have been doing wrong for years.

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands
CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

The US Government Just Changed How Agencies Must Fix Security Flaws. It Is Not Enough.
A new federal directive finally ties patch deadlines to real-world risk. Then AI rewrote the problem.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals walk in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

Microsoft sets a hard stop for Exchange 2016 and 2019 security fixes
After October 2026, on-premises Exchange 2016 and 2019 servers get no more patches, even for customers paying for extended support.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing
When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In
Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.