ZeroHour

Source: Dark Reading

4 stories in the last 30d

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

Microsoft shipped emergency out-of-band fixes to correct glitches from a record Patch Tuesday covering nearly 1,000 CVEs.

Dark Reading reports that Microsoft issued emergency fixes following a massive Patch Tuesday that addressed nearly 1,000 CVEs. The out-of-band updates correct glitches introduced by the record-sized monthly release. The brief excerpt names no specific CVEs, affected products, or actively exploited flaws.

Dark Reading · 20h agoVulnerability

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

GitLab CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw affecting Community and Enterprise Editions, risking supply chain compromise.

CVE-2026-85706 is a path traversal vulnerability with a CVSS score of 10.0 affecting GitLab Community Edition and Enterprise Edition instances. Exploitation could enable attackers to tamper with repositories, posing software supply chain risks. The report does not mention active exploitation.

Dark Readingupdated · 1d agofirst · 1d agoVulnerability 18 sourcesCVE-2026-857061

Patch Tuesday Sets Another Record With 974 CVEs

Microsoft's September Patch Tuesday fixes a record 974 CVEs, with two vulnerabilities already actively exploited and 58 more likely to be targeted.

Microsoft's September Patch Tuesday shipped fixes for a record 974 vulnerabilities, the largest Patch Tuesday batch to date. The company stated that two of the flaws are being actively exploited and another 58 are more likely to be exploited. Defenders are urged to prioritize patching the actively exploited issues across Windows and related products.

Dark Reading · 7d agoVulnerability in the wild

Chinese Routers Sold Worldwide Contain Backdoors

Manufacturer-built backdoor implants were found in ZBT white-label routers sold worldwide, exposing affected devices to potential unauthorized access.

An untold number of ZBT routers distributed globally as white-label products contain multiple backdoor implants built into the devices by the manufacturer. The implants are pre-installed through the hardware and firmware supply chain rather than injected by attackers after deployment. The scale of affected deployments and whether the implants have been actively abused have not been disclosed.

Dark Reading · 19d agoVulnerability