Patch Security News

Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.

Patches are the other half of the vulnerability story — the fixes vendors ship once a flaw is confirmed, ranging from routine monthly update bundles to emergency out-of-band releases for actively exploited bugs. This feed tracks patch and update announcements as they are published, so you can see what shipped and why. Pairing this with the CVE and zero-day feeds gives the full disclosure-to-fix timeline.

Recent Patch items

BREAKING - Attackers are exploiting an unpatched Magento and Adobe Commerce ZERO-DAY to backdoor online stores.No login required. No published CVE. No Adobe patch yet.Here's what to do and how the att…
@thehackernews · Sep 5, 2026
CVE-2026-86193 grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers w…
@cveNotify · Sep 5, 2026
CVE-2026-86169 Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard t…
@cveNotify · Sep 5, 2026
CVE-2026-63464 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their ow…
@cveNotify · Sep 4, 2026
CVE-2026-82911 Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to con…
@cveNotify · Sep 4, 2026
CVE-2026-64410 In the Linux kernel, the following vulnerability has been resolved:netfilter: flowtable: IPIP tunnel hardware offload is not yet supportNo driver supports for IPIP tunnels yet, give up…
@cveNotify · Sep 4, 2026
CVE-2026-85522 A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the comp…
@cveNotify · Sep 4, 2026
CVE-2026-85401 A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.…
@cveNotify · Sep 4, 2026
CVE-2026-82309 Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries.…
@cveNotify · Sep 4, 2026
VMware Workstation and Fusion Updates Patch Critical Vulnerability https://ift.tt/bKFS610
@ctinow · Sep 4, 2026
CVE-2026-85547 A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST r…
@cveNotify · Sep 4, 2026
CVE-2026-85546 MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __ini…
@cveNotify · Sep 4, 2026
CVE-2026-85538 An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions.The…
@cveNotify · Sep 4, 2026
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day https://ift.tt/G9EflRB
@ctinow · Sep 4, 2026
CVE-2026-85401 A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.…
@cveNotify · Sep 4, 2026
CVE-2026-75754 Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encry…
@cveNotify · Sep 4, 2026
CVE-2026-85242 PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the i…
@cveNotify · Sep 3, 2026
CVE-2026-85135 A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Servic…
@cveNotify · Sep 3, 2026
CVE-2026-85242 PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the i…
@cveNotify · Sep 3, 2026
CVE-2026-85239 A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field…
@cveNotify · Sep 3, 2026
CVE-2026-85238 MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored…
@cveNotify · Sep 3, 2026
CVE-2026-85237 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts.The email_otp() endp…
@cveNotify · Sep 3, 2026
CVE-2026-85230 A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were…
@cveNotify · Sep 3, 2026
CVE-2026-85226 MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharin…
@cveNotify · Sep 3, 2026
CVE-2026-85221 MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. Wh…
@cveNotify · Sep 3, 2026
CVE-2026-85216 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials.The custom LdapAuthenti…
@cveNotify · Sep 3, 2026
CVE-2026-85239 A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field…
@cveNotify · Sep 3, 2026
CVE-2026-85238 MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored…
@cveNotify · Sep 3, 2026
CVE-2026-85237 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts.The email_otp() endp…
@cveNotify · Sep 3, 2026
CVE-2026-85230 A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were…
@cveNotify · Sep 3, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.