ZeroHour

Search: “update-bug”

29 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

Oracle's September 2026 Critical Patch Update fixes 800+ vulnerabilities, including over 100 critical flaws and 240+ remotely exploitable without authentication.

Oracle released 673 new security patches in its September 2026 Critical Security Patch Update, resolving 672 unique CVEs across 17 risk matrices plus 130+ additional CVEs. More than 100 flaws are critical severity and over 240 are remotely exploitable without authentication. Oracle E-Business Suite received the largest batch with 159 patches, followed by Fusion Middleware (153, including 78 unauthenticated remote flaws) and Hyperion (102). Oracle reports no exploitation of these specific flaws but warns attackers routinely exploit unpatched Oracle products.

SecurityWeekupdated · 2h agofirst · 13h agoAdvisory 3 sources

Android’s September 2026 Updates Patch 180 Vulnerabilities

Google's September 2026 Android security updates patch 180 vulnerabilities including critical Wi-Fi memory corruption flaw CVE-2026-28662.

Google released September 2026 Android security updates addressing 180 vulnerabilities across two patch levels. The 2026-09-01 level fixes 95 bugs including 23 critical System component flaws enabling RCE, EoP, and DoS. The 2026-09-05 level addresses 85 additional defects in kernel and vendor components including a Wi-Fi memory corruption flaw (CVE-2026-28662) enabling remote code execution without privileges or user interaction.

SecurityWeek · 7d agoAdvisoryCVE-2026-28662

Chrome, Firefox Updates Patch 115 Vulnerabilities

Google and Mozilla patch 115 vulnerabilities across Chrome 153 and Firefox 156, including three critical Chrome bugs; no exploitation reported.

Google's Chrome 153 (153.0.8010.47/.48 for Windows/macOS) fixes 42 flaws, including three critical: CVE-2026-91726, an out-of-bounds read in WebGL, and use-after-free bugs CVE-2026-91721 and CVE-2026-91749 in Internals and Workers. Mozilla's Firefox 156 resolves 73 vulnerabilities, including 29 high-severity use-after-free and privilege escalation issues, with related fixes in Thunderbird and Firefox ESR branches. Neither vendor reports any of the defects being exploited in the wild.

libpcap 1.10.7 fixes 7 vulnerabilities

libpcap 1.10.7 fixes seven vulnerabilities, including CVE-2026-31912 affecting the deprecated bpf_filter(), and all users are advised to update.

libpcap 1.10.7 was published on 2026-09-05 with its main focus being fixes for seven vulnerabilities. Maintainer Denis Ovsienko announced the release on the oss-security mailing list, noting that each CVE record contains detailed accounts and links to git commits with further explanation. For the CVE-2026-31912 fix to take effect, applications using the now deprecated bpf_filter() must update their usage. All users are advised to update; no exploitation in the wild is reported.

oss-security · 7d agoVulnerabilityCVE-2026-319121

Re: Vulnerabilities fixed in libxml2-2.15.4

libxml2 2.15.4 patches two flaws including a heap buffer overflow in xmlDictAddQString tracked as CVE-2026-86137 and CVE-2026-86138.

libxml2 releases before 2.15.4 are affected by an integer overflow in xmlDictAddQString in dict.c that leads to a heap-based buffer overflow, tracked as CVE-2026-86137 and CVE-2026-86138. The oss-security post from Debian's Salvatore Bonaccorso flags the fixed release for downstream tracking. No exploitation is mentioned in the disclosure.

August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update causes recurring CompatTelRunner.exe 0xc0000409 crashes on Windows Server 2016 with Compatibility Appraiser enabled; no functional impact.

Microsoft confirmed a known issue in which the August 2026 Windows security update generates recurring Application Error events (Event ID 1000, exception code 0xc0000409) in CompatTelRunner.exe on Windows Server 2016. The issue affects physical and virtual machines, including VMware and Azure environments, and per Microsoft does not affect device functionality. A permanent fix is planned for a future update, and the event log entries can be dismissed temporarily.

BleepingComputer · 8d agoAdvisory

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle's August 2026 Critical Patch Update fixes 943 vulnerabilities; Oracle Fusion Middleware and Hyperion received the most patches at 262.

Oracle released its August 2026 Critical Patch Update, addressing 943 security vulnerabilities across multiple product families, including third-party components bundled in Oracle products. Oracle Fusion Middleware and Oracle Hyperion received the highest number of fixes with 262 patches. Several of the addressed vulnerabilities impact more than one product.

Qualys ThreatPROTECT · 28d agoAdvisory2

Just a rumour of a bug is enough to find a security exploit these days

Commentary argues that an unverified rumor of a software bug is now enough for researchers or attackers to develop a working exploit.

A short blog note reflects on how modern exploit development has accelerated to the point that even a mere rumor of a vulnerability can be enough to locate and weaponize a bug. The piece is commentary on the current state of security research and attacker trends rather than a disclosure of a specific flaw.

Lobsters · security · 19d agoIndustry

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

Cyber Security News · 14h agoVulnerability in the wildCVE-2026-62721

Datasette 1.0a39 and 0.65.4 security releases

Datasette shipped security patches 1.0a39 and 0.65.4 fixing subtle bugs in instances mixing public and private tables, found via an AI-assisted audit.

Datasette released parallel security fixes for its current alpha series (1.0a39) and stable 0.65.x family (0.65.4), advising anyone running a Datasette instance on the public web to update, especially where public and private tables are mixed. The underlying issues were reported by Sevban Dönmez and Alex Garcia, followed by an extensive audit of the codebase using Claude Fable 5.1, GPT-5.6, and GPT-6 Astra. Fixes were developed and reviewed collaboratively over nearly a week. No CVE identifiers or observed exploitation are mentioned in the announcement.

Simon Willison · 5d agoVulnerability 3 sources2

TestFlight Update

Apple released an update to TestFlight, its beta app testing platform, with release notes published on the developer portal.

Apple published a software release notice for TestFlight, the company's beta testing platform for iOS, iPadOS, and other Apple platforms. The release notes are available through Apple's developer releases page. No security content or vulnerability details are provided in the notice.

Apple software releases · 22d agoAdvisory

Microsoft Patch Tuesday Update September 2026 – 974 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.

Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.

Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks

Google's September 2026 Android bulletin fixes over 30 critical flaws, including no-interaction system RCEs, a TIPC kernel RCE and a Qualcomm closed-source bug

Google's Android Security Bulletin for September 2026 (patch levels 2026-09-01 and 2026-09-05) fixes numerous critical System remote code execution flaws, including CVE-2026-28604, CVE-2026-28618, CVE-2026-28639, CVE-2026-28662, CVE-2026-49882, CVE-2026-49884, CVE-2026-49919 and CVE-2026-49921, none requiring user interaction or additional privileges. It also addresses critical kernel issues including a TIPC RCE (CVE-2026-52993) and elevation-of-privilege flaws in NFC and protected KVM, plus a critical Qualcomm closed-source component flaw (CVE-2026-25289). Affected versions span Android 14 through 17; the 2026-09-05 patch level extends coverage to Android TV and chipset components, with high-severity fixes for Arm Mali, PowerVR, MediaTek, Unisoc and Qualcomm components.

Microsoft Patch Tuesday for August 2026 Fixed a Zero

Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including an actively exploited WinSock zero-day CVE-2026-68820 and wormable DNS RCE CVE-2026-62878.

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, .NET and other products, with 62 rated Critical. The actively exploited CVE-2026-68820 is a use-after-free in the Windows WinSock afd.sys driver that can yield SYSTEM privileges via a race condition. CVE-2026-62878 is a critical, wormable stack buffer overflow in Windows DNS Server allowing unauthenticated, remote code execution without user interaction. Other notable fixes include WDS TFTP RCE CVE-2026-62893, a QUIC flaw affecting roughly 13.5 million sites (CVE-2026-62815), an Exchange authentication bypass EoP demonstrated at Pwn2Own Berlin (CVE-2026-62911), and two TPM 2.0 reference implementation fixes.

Security Affairs · Aug 12, 2026Advisory in the wildCVE-2026-68820CVE-2026-62878CVE-2026-62893+5 CVEs

AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

Dark Reading argues AI-assisted bug discovery is flooding vendors with vulnerability reports, straining disclosure processes and secure-by-design commitments.

The Dark Reading analysis describes a surge of bug reports driven by AI-powered discovery, exposing bottlenecks in vendor triage and disclosure pipelines. It argues this volume is revealing secure-by-design failures and questions whether vendors can keep pace with the rising tide of findings.

Dark Reading · 12d agoIndustry

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google shipped Chrome 153 fixing 42 vulnerabilities, including three Critical use-after-free and out-of-bounds bugs, with no active exploitation reported.

Google's Chrome 153 Stable channel update (153.0.8010.47/.48 for Windows/macOS, 153.0.8010.47 for Linux) patches 42 vulnerabilities: three Critical, 27 High, ten Medium, and one Low. The Critical flaws are CVE-2026-91721 (use-after-free in Internals), CVE-2026-91749 (use-after-free in Workers), and CVE-2026-91726 (out-of-bounds read in WebGL). Google's bulletin states none of the patched issues are actively exploited, and detailed bug links remain restricted until most users receive the fixes. Bug bounty awards include $1,500 to Hafiizh for CVE-2026-91724 and $1,000 to Jihyeon Jeong of Seoul National University for CVE-2026-91728.

ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability

Cisco Identity Services Engine's PatchUpdateListener has an authenticated directory traversal (CVE-2026-20148, CVSS 4.9) enabling sensitive information disclosure.

ZDI advisory ZDI-26-582 describes a directory traversal information disclosure vulnerability in the PatchUpdateListener component of Cisco Identity Services Engine. Remote attackers can disclose sensitive information, but valid authentication is required to exploit the flaw. ZDI assigned a CVSS rating of 4.9 and CVE-2026-20148.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20148

GitLab Warns of Active Exploitation of Critical GraphQL Flaw

GitLab emergency-patches actively exploited flaw CVE-2026-19478 (CVSS 9.4), letting unauthenticated attackers modify or delete public projects on self-managed servers.

GitLab emergency-patched CVE-2026-19478 (CVSS 9.4) on August 17 after WatchTowr researchers warned of active exploitation. The flaw lets unauthenticated attackers remotely modify or delete public projects and user data through a GraphQL directive, affecting only self-managed installations. Fixes ship in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11; the 18.2-18.10 branches receive no patch and must upgrade. Until patching, defenders should restrict unauthenticated access to /api/graphql, disable public repositories, and hunt for @gl_introduced in logs.

Security Affairs · 24d agoExploit / PoC in the wildCVE-2026-194781

Mythos has made 2026 patching hell. It might make 2027 a breeze

Gartner analyst Craig Lawson argues AI bug-hunters like Anthropic's Mythos have audited major codebases so thoroughly that 2027 could see fewer severe vulnerabilities.

Speaking at Gartner's IT Symposium in Australia, research VP Craig Lawson said AI-driven bug hunting, exemplified by Anthropic's Mythos, is uncovering flaws at unprecedented scale, citing Microsoft shipping over 970 patches in one week and a recent series of CVEs in historically secure OpenBSD. He argued vendors are also using AI to find bugs before release, retiring technical debt and shrinking future zero-day avenues. Lawson predicts 2027 may be the first year with a net drop in vulnerability severity, if not aggregate counts. He also expects AI to enable near-continuous red-teaming and faster fixes, such as generating F5 iRule syntax for virtual patches via Gemini.

The Register · Security · 15h agoIndustry1

Update modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb

Rapid7 updated a Metasploit auxiliary scanner module that detects XML external entity injection in Elasticsearch via Apache Tika.

A commit in the Metasploit Framework updated modules/auxiliary/scanner/http/elasticsearch_tika_xfa_xxe.rb, an auxiliary scanner module. The module targets XML external entity (XXE) injection in Elasticsearch through Apache Tika, and was co-authored by jheysel-r7. The terse commit message contains no additional details, CVE references, or exploitation notes.

Metasploit Framework commits · 8d agoTools

Vulnerabilities fixed in libxml2-2.15.4

libxml2 2.15.4 fixes an out-of-bounds read in xmlregexp's NXT macro plus several integer overflow and parsing flaws.

libxml2 2.15.4 (released September 1, 2026) includes security fixes: an out-of-bounds read in the xmlregexp NXT macro, missing overflow checks in dict.c, uri.c, and valid.c, an integer overflow in xmlIO before the writecallback, and an overflow check in xmlXPtrEvalXPtrPart. The release also propagates parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree. No CVE identifiers, exploitation, or severity ratings are given in the announcement.

oss-security · 12d agoVulnerability

Chrome 153 Patches Seventh Zero-Day of 2026

Google patches Chrome V8 zero-day CVE-2026-87491, exploited in the wild, marking the seventh exploited Chrome zero-day of 2026, in an update fixing 230 flaws.

Google released Chrome 153 with fixes for 230 vulnerabilities, including CVE-2026-87491, a medium-severity out-of-bounds write in the V8 JavaScript and WebAssembly engine that Google says is being exploited in the wild. It is the seventh zero-day patched in Chrome in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-11645 and CVE-2026-85046. The update also fixes five critical bugs (four in WebGL, one in Cast), 41 high-severity defects, and more than 180 medium/low issues, rolling out as 153.0.8010.36/.37 for Windows/macOS and 153.0.8010.36 for Linux.

SecurityWeek · 7d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-2441CVE-2026-3909+4 CVEs

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

Microsoft's record September 2026 Patch Tuesday fixes 974 CVEs, including two exploited Windows privilege-escalation zero-days and 20 wormable bugs.

Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two actively exploited zero-days: CVE-2026-85880, an ALPC heap buffer overflow, and CVE-2026-81963 in the Windows Update Stack, both CVSS 7.8 local privilege escalations. It also addresses an unauthenticated Exchange RCE (CVE-2026-55007) triggered by Visio attachment content indexing under memory pressure, an RDP use-after-free (CVE-2026-69525, CVSS 9.8), and 20 wormable flaws in DNS, DHCP, SMB, Active Directory, and other components. ZDI attributed the rising volume partly to AI-assisted vulnerability discovery, noting no corresponding spike in active exploits yet.

Security Affairs · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-55007+3 CVEs2

Microsoft Fixes 400 Flaws on August Patch Tuesday

Microsoft's August Patch Tuesday delivers fixes for 400 security vulnerabilities across its product lineup.

Microsoft released its August Patch Tuesday security updates, fixing 400 vulnerabilities, described as another massive monthly batch. The source text provides no breakdown of severity classes, affected products, or whether any flaws were actively exploited. Defenders should prioritize patching based on Microsoft's exploitation status ratings in the official bulletin.

Infosecurity Magazine · Aug 12, 2026Advisory

automatic module_metadata_base.json update

Routine automated Metasploit Framework commit updating module metadata, with no disclosed vulnerability or exploitation activity.

The Metasploit Framework repository received an automatic update to its module_metadata_base.json file. The commit text contains no vulnerability details, CVE references, or new exploit modules. This is routine maintenance activity on the open-source penetration testing framework.

Metasploit Framework commits · 15d agoTools

datasette-publish-fly 1.4

Datasette-publish-fly 1.4 sets force_https in fly.toml, fixes a volume detection bug, and adds support for app-scoped Fly deploy tokens.

Version 1.4 of the datasette-publish-fly plugin for deploying Datasette to Fly.io has been released. It sets force_https=true in fly.toml, fixes a 'Volume could not be found' bug, and adds compatibility with app-scoped deploy tokens. No security vulnerabilities are mentioned in the release notes.

Simon Willison · 5d agoTools1

Google Pixel owners urged to patch actively exploited modem flaw

Google's September 2026 Pixel bulletin fixes 110 vulnerabilities, including CVE-2026-58704, a modem permission bypass under limited targeted exploitation enabling remote privilege escalation.

Google released the September 2026 Pixel Update Bulletin addressing 110 vulnerabilities, including CVE-2026-58704, a high-severity logic error in the cellular modem that allows remote escalation of privilege with no additional execution privileges or user interaction required. Google says there are indications the flaw may be under limited, targeted exploitation; attackers need adjacent network access and some existing foothold on the device, which the bulletin does not explain how to obtain. The fix ships at the 2026-09-05 patch level and appears only in the Pixel-specific bulletin, so other Android vendors do not receive this specific fix.

Malwarebytes Labsupdated · 3h agofirst · 11h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704