#patch management
114 stories taggedpatch management · page 4 of 8.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

Fortinet Patches Eight Flaws, Including Two That Let Attackers Log In Without Real Credentials
Two high-severity bugs in Fortinet's security products could let criminals talk their way past login screens they should never be able to reach.

Ivanti Patches Three High-Severity Flaws in Endpoint Manager That Attackers Could Hit Remotely
Two of the bugs needed no password to exploit. Ivanti says no customers were hit before the fixes landed.

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.
Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug
A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

Cisco Warns Windows Users of High-Severity ClamAV Flaws, Two With Working Attack Code Released
Seven vulnerabilities in the ClamAV antivirus engine affect Cisco's Secure Endpoint Connector software across Windows, macOS, and Linux. Patches land in August.

AI Patches Security Flaws Correctly Only 26% of the Time, 1Password Study Finds
An internal evaluation by the security company 1Password found that AI coding tools produce flawed or incomplete security fixes more than half the time, and sometimes make things worse.

The Window Between a New Vulnerability and an Active Attack Is Getting Shorter
Security teams are buried in alerts while attackers move faster than ever. The real problem isn't a shortage of warnings. It's knowing which ones actually matter before criminals act on them.

Most companies understand CTEM. Almost none of them can run it.
Knowing the five phases of Continuous Threat Exposure Management is the easy part. Building a system that actually proves your defences are improving is where programmes fall apart.

Patched Doesn't Mean Safe: Why Security Teams Need to Test After They Fix
A new survey of 750 security leaders finds that fewer than one in three organisations check whether a fix actually stopped an attacker. The gap between completing work and reducing risk is where breaches still happen.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain weaknesses across apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries, then cold-calling victims to pile on the pressure.

Google Patches 1,442 Chrome Flaws Across Three Releases, More Than the Prior 23 Combined
Chrome 149, 150 and 151 together resolved more security bugs than nearly two years of previous updates, with Google's own researchers flagging the bulk of the issues.

Broadcom Patches Three Critical VMware Bugs, Including a vCenter Login Bypass
One flaw lets an attacker skip the login screen on vCenter entirely. Two more allow code execution and virtual machine escape across ESX, Workstation and Fusion.

Windows 11 gets a 42-fix preview update with quieter alerts and better voice control
Microsoft's optional KB5101684 preview for Windows 11 24H2 and 25H2 clears up File History backup errors, a DFS drive quirk that scared File Explorer, and a compliance bug that locked new work laptops out of company resources.