ZeroHour

Search: “patch”

37 stories in the last 3d

Oracle Critical Security Patch Update, September 2026 Review

Oracle's September 2026 Critical Patch Update fixes 673 vulnerabilities, including 104 critical, with many remotely exploitable in E-Business Suite and Fusion Middleware.

Oracle released 673 security patches in its September 2026 Critical Patch Update: 104 rated critical, 503 high, and 59 medium. Oracle E-Business Suite received the most patches (159, 24% of total), with 19 exploitable without credentials including CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462 at CVSS 9.8. Fusion Middleware received 153 patches with 78 remotely exploitable without authentication, and 41 patches address third-party open-source component flaws. Qualys published detection QIDs for vulnerable assets.

Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

Oracle's September 2026 Critical Patch Update ships 673 patches across 17 product families, including 100+ critical and 240+ remotely exploitable flaws.

Oracle's September 2026 Critical Security Patch Update ships 673 patches covering 672 unique CVEs, with more than 130 additional CVEs resolved through bundled fixes, pushing the effective total past 800. Over 100 flaws are critical severity and more than 240 are remotely exploitable without authentication. Oracle E-Business Suite received 159 fixes, Fusion Middleware 153 (78 unauthenticated and network-exploitable), and Hyperion 102. No in-the-wild exploitation of these specific flaws is reported, but Oracle cites CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0).

Cyber Security Newsupdated · 1h agofirst · 8h agoAdvisory 3 sourcesCVE-2026-21962

ENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch Up

ENISA warns frontier AI compresses attack lifecycles to minutes, with exploits possible within 15 minutes of disclosure and median 72-minute breach-to-exfiltration times.

ENISA's July 2026 paper 'ENISA's view on Cybersecurity in the Frontier AI Era' argues AI-assisted attackers may weaponize vulnerabilities within 15 minutes of disclosure and achieve initial-access-to-data-exfiltration in a median 72 minutes, creating a 'negative time-to-exploit' problem. The report cites one organisation whose CVE volume rose from roughly 80 in Q1 2025 to almost 500 in Q1 2026, then about 500 reports per day when frontier-AI tools were used. ENISA recommends machine-speed defence under 'Cybersecurity as Code', EPSS and VEX-based prioritisation, AI-assisted incident response with human oversight, and an assume-breached architecture.

Security Affairs · 2d agoAdvisory

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple released iOS 27 and iPadOS 27 patching roughly 126 vulnerabilities across kernel, WebKit, sandboxing, and authentication components; no active exploitation reported.

Apple released iOS 27 and iPadOS 27 on September 14, 2026, fixing approximately 126 vulnerabilities across more than 90 components, including the kernel, WebKit, AppleKeyStore, Sandbox, and TCC. Flaws include memory corruption, information disclosure, denial-of-service, logic errors, sandbox escapes enabling root privileges, and a Bluetooth issue permitting remote code execution in specific circumstances. Apple also shipped iOS 26.7 and iPadOS 26.7 with over 80 fixes for users delaying the major upgrade, including 75 vulnerabilities shared with iOS 27. No vulnerabilities were reported as actively exploited at release time.

GBHackers · 15h agoAdvisory

Microsoft Confirms Remote Desktop Services Might Stop Working Following Sept. 2026 Security Update

Microsoft's September 2026 Patch Tuesday updates (KB5124008) can break Remote Desktop Services, causing RDP failures and freezes across Windows clients and servers.

Microsoft confirmed its September 2026 security updates, including KB5124008 for Windows 11 24H2/25H2, introduced a reliability regression where RDP connections fail after several minutes and servers hang at the 'Please wait for the Remote Desktop Configuration' screen. MMC, RDS Licensing Diagnoser, File Explorer, and the Windows Update settings page may also stop responding. The issue affects Windows 10/11 clients and Windows Server 2012 through 2025; Microsoft marked it Mitigated on September 11 and is developing a permanent fix, with VM restart offered as a temporary workaround.

Cyber Security News · 2d agoAdvisory

Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel

Microsoft confirms KB5002914 Excel security update silently breaks copy-paste in Excel 2016-2024, forcing admins to choose between usability and security fixes.

Microsoft added a known issue to KB5002914, the September 8, 2026 Excel security update, where paste, autofill, and formula dragging fail silently with no error in Excel 2016, 2019, 2021, and 2024. The update addresses remote code execution and information disclosure flaws including CVE-2026-81399, CVE-2026-81390, and CVE-2026-81954. No hotfix date has been published as of September 15, 2026; the only widely confirmed recovery is uninstalling or rolling back KB5002914, which drops the month's Excel security fixes.

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Cisco's September 2026 hardening release for Secure Email Gateway and Secure Email and Web Manager patches internally found flaws, one actively exploited.

Cisco issued a security hardening release for Cisco Secure Email Gateway and Secure Email and Web Manager covering multiple internally discovered vulnerabilities, grouped by CWE class to streamline patching. Cisco states one of the vulnerabilities is known to be actively exploited. The exploited issue is the Cisco Secure Email Gateway SQL Injection Vulnerability detailed in a companion advisory. Software updates are available.

Cisco Security Advisories · 2d agoAdvisory in the wild6

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

Cisco patched an authenticated command injection in ThousandEyes Virtual Appliance allowing arbitrary OS command execution with root privileges.

Improper validation of user-supplied input in the web-based management interface of Cisco ThousandEyes Virtual Appliance enables command injection. An authenticated remote attacker with valid administrative credentials can save configuration details containing malicious values to execute arbitrary operating system commands with root privileges. Cisco has released software updates that address the vulnerability.

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

Cisco patched an sftunnel flaw in Secure Firewall Management Center letting an authenticated remote attacker execute arbitrary commands as root.

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to execute commands as root. The flaw stems from incorrect permissions allowing a registered sftunnel peer to write an arbitrary file anywhere on the device, exploitable via connection hijacking or crafted sftunnel commands. Cisco has released software updates.

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Jenkins Security Advisory 2026-09-16

Jenkins released a security advisory patching vulnerabilities across 13 plugins, including GitLab, Bitbucket, Gradle, Keycloak Authentication, and Script Security.

The Jenkins security advisory dated September 16, 2026 addresses vulnerabilities in 13 plugins: Bitbucket Push and Pull Request, Bitbucket Server Integration, Coverage, Gitee, GitLab, Gradle, Keycloak Authentication, OWASP Dependency-Check, Pipeline: Groovy Libraries, Pipeline: Multibranch, Robot Framework, Script Security, and Warnings. Jenkins users should update the affected plugins to the patched versions listed in the advisory.

Jenkins Security Advisoriesupdated · 6h agofirst · 9h agoAdvisory 2 sources

USN-8772-1: AOM vulnerabilities

Ubuntu USN-8772-1 patches four libaom flaws (CVE-2026-56208 to CVE-2026-56211) that could cause heap overflow, arbitrary memory writes, or code execution.

Ubuntu Security Notice USN-8772-1 fixes a heap buffer overflow in libaom's first-pass statistics buffer handling in Look-Ahead Processing mode (CVE-2026-56208), potentially causing denial of service or arbitrary code execution. Three additional flaws in spatial and temporal layer ID validation in the SVC encoder controls (CVE-2026-56209, CVE-2026-56210, CVE-2026-56211) allow arbitrary memory writes, out-of-bounds heap reads, or code execution. Users should apply the updated packages.

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Cisco patched multiple argument-injection vulnerabilities in Cisco IMC's web management interface allowing authenticated attackers root command execution.

Cisco published an advisory covering multiple argument injection vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC). An authenticated, remote attacker could exploit them to execute arbitrary commands on the underlying operating system and elevate privileges to root. Cisco released software updates and states there are no workarounds; the advisory carries a High Security Impact Rating.

Cisco Security Advisories · 1d agoAdvisory

USN-8770-1: SimpleSAMLphp vulnerabilities

Ubuntu patches SimpleSAMLphp signature validation and XXE flaws enabling user impersonation, privilege escalation, and information disclosure.

Ubuntu security notice USN-8770-1 fixes multiple SimpleSAMLphp vulnerabilities. CVE-2019-3465 stems from incorrect cryptographic signature validation in XML messages, allowing an authenticated attacker to impersonate users or gain elevated privileges; it only affected Ubuntu 16.04 LTS and 18.04 LTS. CVE-2024-52596 involves improper handling of external entities when parsing untrusted XML, allowing a remote attacker to obtain sensitive information, and did not affect Ubuntu 24.04 LTS. An additional flaw in signature verification for SAML messages using the HTTP-Redirect binding is also addressed.

USN-8769-1: phpseclib vulnerability

Ubuntu patches phpseclib non-constant-time padding validation enabling remote padding oracle timing attacks against AES-CBC.

Ubuntu security notice USN-8769-1 addresses a vulnerability in phpseclib where padding validation was not performed in constant time when using AES in CBC mode. A remote attacker could leverage this timing side channel to conduct a padding oracle attack and decrypt sensitive information. Users are advised to update the phpseclib package.

Ubuntu Security Notices · 1d agoAdvisory

USN-8768-1: Shibboleth vulnerability

Ubuntu patches Shibboleth SQL injection in the ODBC storage plugin allowing remote attackers to extract sensitive information.

Ubuntu security notice USN-8768-1 fixes a Shibboleth vulnerability discovered by Florian Stuhlmann. The software incorrectly escaped input when using the ODBC storage plugin, allowing a remote attacker to perform SQL injection attacks and obtain sensitive information. Users are advised to update the Shibboleth package.

Ubuntu Security Notices · 1d agoAdvisory

USN-8767-1: Snapcast vulnerability

Ubuntu patches Snapcast mishandling of crafted JSON-RPC requests enabling remote code execution and data exposure.

Ubuntu security notice USN-8767-1 addresses a vulnerability in Snapcast, a multiroom audio streaming server. The software incorrectly handled crafted JSON-RPC requests, which could allow a remote attacker to execute arbitrary code or obtain sensitive information. Users are advised to update the snapcast package.

Ubuntu Security Notices · 1d agoAdvisory

USN-8766-1: Suricata-Update vulnerability

Ubuntu patches Suricata-Update path validation flaw allowing arbitrary file writes outside the rules directory from malicious rule archives.

Ubuntu security notice USN-8766-1 fixes a Suricata-Update vulnerability discovered by Guillem Lefait. The tool did not properly validate destination paths when extracting files referenced by downloaded rule archives, allowing an attacker to write arbitrary files outside the configured rules directory. Users are advised to update the suricata-update package.

Ubuntu Security Notices · 1d agoAdvisory

USN-8765-1: python-sql vulnerability

Ubuntu patches python-sql SQL injection flaw where values passed to unary operators are incorrectly escaped.

Ubuntu Security Notice USN-8765-1 fixes a vulnerability in python-sql discovered by Cedric Krier. The library incorrectly escaped values passed to unary operators, allowing an attacker to potentially perform SQL injection attacks against applications using the library.

Ubuntu Security Notices · 1d agoAdvisory

USN-8763-1: kitty vulnerabilities

Ubuntu patches three kitty terminal flaws including remote command execution via crafted escape sequences.

Ubuntu Security Notice USN-8763-1 fixes multiple vulnerabilities in the kitty terminal emulator. CVE-2026-42850 allows a remote attacker to execute arbitrary commands via improperly escaped error messages triggered by crafted terminal escape sequences. CVE-2026-42851 enables arbitrary code execution with the user's privileges through mishandled remote edit requests in terminal output. CVE-2026-54055 lets a local attacker overwrite arbitrary files via destination paths in kitty's file transmission protocol.

USN-8761-1: Linux kernel (Azure) vulnerabilities

Ubuntu patches multiple Linux kernel (Azure) flaws across ARM64, Bluetooth, Netfilter, NTFS3, SMB and other subsystems.

Ubuntu security notice USN-8761-1 corrects several security issues in the Linux kernel for Azure, spanning ARM32, ARM64, and PowerPC architectures plus subsystems including Bluetooth, Netfilter, EFI core, GPU drivers, InfiniBand, SCSI, NTFS3, and SMB. An attacker could possibly use these flaws to compromise the system.

Ubuntu Security Notices · 1d agoAdvisory 2 sources

USN-8760-1: Linux kernel (NVIDIA) vulnerabilities

Canonical issues USN-8760-1 patching multiple Linux kernel (NVIDIA) vulnerabilities across numerous subsystems and CPU architectures.

Canonical published USN-8760-1 to correct several Linux kernel (NVIDIA) vulnerabilities that an attacker could possibly use to compromise the system. The update fixes flaws spanning UAPI, the kernel build system, ARM32, ARM64, RISC-V, S390, and x86 architectures. Patched subsystems also include the block layer, cryptographic API, Compute Acceleration Framework, Intel NPU driver, ACPI and Bluetooth drivers, and the hardware random number generator core.

Ubuntu Security Notices · 1d agoAdvisory

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft released emergency out-of-band Windows updates fixing Remote Desktop Services failures and Hyper-V issues caused by September 2026 security patches.

Microsoft issued out-of-band updates on September 14, 2026 to fix Remote Desktop Services instability introduced by the September security updates, which caused RDP connection and sign-in failures and unresponsive servers. Updates include KB5129194 (Windows 11 26H1), KB5129195 (Windows 11 24H2/25H2), KB5129236 (Windows 10), KB5129235 (Windows Server 2025), and KB5129237 (Windows Server 2022). The Windows 11 updates also fix a Hyper-V Plan9 shared folder issue and some USB Audio Class 1.0 multichannel problems, though remaining USB audio issues await a fix. Admins had previously used Group Policy mitigations or uninstalled the security updates, which removed security protections.

BleepingComputerupdated · 1d agofirst · 2d agoAdvisory 3 sources1

USN-8758-1: dracut vulnerability

Ubuntu patches dracut CVE-2026-15816, where a rogue adjacent-network DHCP server can inject root-executed commands during boot-failure handling.

Ubuntu security notice USN-8758-1 fixes CVE-2026-15816 in dracut, where messages written by the die() function to the emergency hook directory are not properly shell-quoted. An attacker on an adjacent network controlling a rogue DHCP server could exploit this to inject commands executing as root during boot-failure handling. Users should apply the patched dracut package.

Samsung mobile security advisory (AV26-919)

Canadian Cyber Centre relays Samsung's September 2026 mobile security update (SMR-SEP-2026) fixing multiple vulnerabilities; users urged to apply patches.

The Canadian Centre for Cyber Security issued advisory AV26-919 on September 14, 2026, relaying Samsung's September 8, 2026 security update for Samsung mobile devices. The update covers versions prior to SMR-SEP-2026 and resolves multiple identified vulnerabilities. Users and administrators are encouraged to review the Samsung bulletin and apply the necessary update.

Canadian Centre for Cyber Security · 2d agoAdvisory

MongoDB security advisory (AV26-918)

Canadian Cyber Centre advisory AV26-918 urges patching MongoDB Server vulnerability fixed in 7.0.43, 8.0.32, 8.3.11, and 9.0.1.

The Canadian Centre for Cyber Security issued advisory AV26-918 on September 14, 2026, regarding a vulnerability in MongoDB Server. Affected versions include those prior to 7.0.43, 8.0.32, 8.3.11, 9.1.0-rc0, and 9.0.1. The fix shreds collection validator constants during parsing. Users and administrators are encouraged to review MongoDB's advisory and apply updates as they become available.

Canadian Centre for Cyber Security · 2d agoAdvisory

USN-8756-1: Yelp vulnerability

Ubuntu patches Yelp help viewer flaw allowing crafted help documents to execute arbitrary scripts and expose sensitive user information.

USN-8756-1 fixes a vulnerability in Yelp, Ubuntu's help viewer, where help documents could execute arbitrary scripts. An attacker could trick a user into opening a specially crafted help document to obtain sensitive information. Ubuntu has released updated packages.

Ubuntu Security Notices · 2d agoAdvisory

USN-8755-1: libvips vulnerability

Ubuntu patches libvips flaw where crafted TIFF images converted to HEIF cause a crash, enabling denial of service.

USN-8755-1 fixes a libvips vulnerability in which specially crafted TIFF images are incorrectly handled when saved as HEIF, causing the library to crash. The impact is limited to denial of service with no code execution indicated. Ubuntu shipped updated packages.

Ubuntu Security Notices · 2d agoAdvisory

USN-8754-1: Freeciv vulnerability

Ubuntu patches Freeciv stack overflow where remote attackers crash clients or servers using crafted network packets.

USN-8754-1 fixes a Freeciv vulnerability where certain network packets trigger a stack overflow. A remote attacker could use this to crash Freeciv clients or servers, resulting in denial of service. Ubuntu released updated packages.

Ubuntu Security Notices · 2d agoAdvisory1

USN-8753-1: libinput vulnerability

Ubuntu patches libinput flaw letting local attackers inject udev properties and execute arbitrary code as root.

USN-8753-1 fixes a libinput vulnerability where device properties are not properly escaped. A local attacker could inject arbitrary udev properties and execute arbitrary code as root, a full local privilege escalation on affected Linux desktop systems. Ubuntu shipped updated packages.

Ubuntu Security Notices · 2d agoAdvisory

USN-8752-1: Konsole vulnerability

Ubuntu patches Konsole URL-handling flaw that could let a remote attacker execute arbitrary code under specific circumstances.

USN-8752-1 fixes a Konsole vulnerability where certain URLs are incorrectly handled under specific circumstances. A remote attacker could possibly exploit this to execute arbitrary code on a victim's system. Ubuntu released updated packages for affected releases.

Ubuntu Security Notices · 2d agoAdvisory

USN-8563-5: nginx vulnerability

Ubuntu ships improved nginx fix for CVE-2026-42533 after earlier patch regression; flaw allows remote crash and possible code execution.

USN-8563-5 provides a better fix for CVE-2026-42533 after the original fix from USN-8563-1 was backed out in USN-8563-2 because it caused a regression. The flaw stems from nginx incorrectly handling certain map directives using regex matching and capture variables, allowing a remote attacker to crash nginx, causing denial of service, or possibly execute arbitrary code. The original advisory also described a use-after-free in the ngx_http_ssi_module when configured with Server-Side Includes, proxy_pass, and proxy buffering.

USN-8751-1: Urwid vulnerabilities

Ubuntu USN-8751-1 patches Urwid weak PRNG issue allowing local attacker possible denial of service or code execution.

Katriel Moses discovered that Urwid used a weak pseudo-random number generator. A local attacker could potentially exploit this issue to cause a denial of service or execute arbitrary code. Ubuntu has released a patch under USN-8751-1.

Ubuntu Security Notices · 2d agoAdvisory1

USN-8749-1: CivetWeb vulnerabilities

Ubuntu USN-8749-1 patches CivetWeb URI and HTTP request parsing flaws enabling remote DoS or possible code execution.

Ubuntu Security Notice USN-8749-1 addresses two CivetWeb vulnerabilities. CVE-2025-55763 involves incorrect URI parsing that could allow a remote attacker to cause denial of service or execute arbitrary code, affecting Ubuntu 22.04 LTS and 24.04 LTS. CVE-2025-9648 involves incorrect HTTP request parsing enabling remote denial of service.

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Identity Services Engine Hardening Release: September 2026

Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.

Cisco released September 2026 hardening updates for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) following a comprehensive internal security review that uncovered multiple vulnerabilities. One of the flaws, an ISE authentication bypass, is known to be actively exploited. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching and streamline disclosure.

Cisco Security Advisories · 5h agoAdvisory in the wild 15 sources