#vulnerabilities
66 stories taggedvulnerabilities · page 3 of 5.

Microsoft Fixes Record 622 Security Flaws, Two Already Used in Live Attacks
This month's update from Microsoft is the largest on record. Two vulnerabilities in widely used business software were already being exploited by criminals before a fix existed.

Microsoft ships Windows 10 KB5099539 as record 570-flaw Patch Tuesday lands
The July 2026 update patches two actively exploited zero-days and quietly extends free security fixes for home users into 2027.

Microsoft ships fixes for 570 flaws in July, including two bugs already used in attacks
The July 2026 Patch Tuesday is the largest on record, driven partly by an AI system Microsoft is using to hunt bugs in Windows.

Microsoft Ships July 2026 Patch Tuesday: 571 Fixes, Better AirPods Pairing, and a Quieter Widgets Panel
The mandatory Windows 11 update rolls up months of security holes and finally tames Bluetooth pairing gremlins. Here is what it actually changes on your PC.

Adobe Rushes Out Fixes for 88 Security Flaws, Eight of Them Critical in ColdFusion
Two weeks after hackers exploited a separate ColdFusion flaw within hours of its disclosure, Adobe is back with another urgent patch batch covering a dozen products.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

SAP Patches Critical Flaws in NetWeaver, Approuter, and Commerce Cloud
Three SAP products used by thousands of businesses worldwide carried serious security holes. Patches are now available, and anyone running the affected software should move fast.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both scored a perfect 10 on the severity scale.

Six bugs in U-Boot bootloader open the door to hidden firmware attacks
Researchers found flaws in the open-source code that starts up millions of embedded devices, from routers to industrial kit. Fixes are out.

Six New Bugs in U-Boot Could Let Attackers Hijack Devices at Startup
Binarly researchers found flaws in the tiny program that boots routers, cameras and server chips. Two of them could let intruders run their own code before the device even wakes up.

Ubiquiti Rushes Fixes for a 10-out-of-10 Flaw Across UniFi Gear
The networking vendor patched serious holes in UniFi Connect, Talk, Access, Protect and the underlying UniFi OS. One bug scores a perfect 10 on the severity scale.

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code
A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

New Chinese AI Models Challenge Cyber Defenses
Recent advances in Chinese AI models reveal vulnerabilities at a rapid pace, posing a challenge to cybersecurity defenses.

Citrix NetScaler Vulnerability Sparks Exploitation Attempts
Citrix patches a high-severity flaw in NetScaler appliances as exploitation attempts are reported within 24 hours.