#patch management
110 stories taggedpatch management · page 5 of 8.

AI Scanner Finds Eight Serious Bugs in NodeBB Forum Software
Aikido Security's automated code review turned up admin takeover and private-message flaws in six hours. All eight are patched in version 4.14.2.

Check Point's Admin Console Has a Critical Flaw That Hands Attackers the Keys to Everything
A security hole in Check Point's management software lets criminals log in without a password and rewrite the rules of an entire network. Ten organisations have already been hit.

Hackers Are Actively Exploiting a Flaw in Check Point Security Software
A newly discovered hole in Check Point's network management tools let attackers log in as administrators without a password. Real attacks were already happening before the patch arrived.

What is a CVE and how does vulnerability scoring work?
CVEs are the universal ID system for software flaws, and CVSS scores tell you how bad each one actually is.

What is a zero-day vulnerability? A plain-English guide
Zero-days are unpatched security flaws the software vendor doesn't know about yet, making them among the most dangerous bugs in existence.

Microsoft sets a hard stop for Exchange 2016 and 2019 security fixes
After October 2026, on-premises Exchange 2016 and 2019 servers get no more patches, even for customers paying for extended support.

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.
Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing
When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

The Real Mythos Problem Isn't New Bugs. It's How Long Yours Stay Open.
Anthropic's AI-driven vulnerability finder has flooded the pipeline since April. But the harder question for defenders is how many days a known flaw sits unpatched on their own network.

Microsoft admits Windows update server sync has been broken for over a week
WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.