Patch Security News

Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.

Patches are the other half of the vulnerability story — the fixes vendors ship once a flaw is confirmed, ranging from routine monthly update bundles to emergency out-of-band releases for actively exploited bugs. This feed tracks patch and update announcements as they are published, so you can see what shipped and why. Pairing this with the CVE and zero-day feeds gives the full disclosure-to-fix timeline.

Recent Patch items

CVE-2026-46439compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `tre…
@cveNotify · Aug 14, 2026
CVE-2026-53970ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substit…
@cveNotify · Aug 14, 2026
CVE-2026-73673Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a…
@cveNotify · Aug 14, 2026
CVE-2026-19761A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. Th…
@cveNotify · Aug 14, 2026
CVE-2026-73673Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a…
@cveNotify · Aug 14, 2026
CVE-2026-72838FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. A…
@cveNotify · Aug 14, 2026
CVE-2026-19786A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site re…
@cveNotify · Aug 14, 2026
CVE-2026-19785A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component…
@cveNotify · Aug 14, 2026
CVE-2026-19784A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. Th…
@cveNotify · Aug 14, 2026
CVE-2026-19763A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creati…
@cveNotify · Aug 14, 2026
CVE-2026-19761A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. Th…
@cveNotify · Aug 14, 2026
CVE-2026-7210`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mit…
@cveNotify · Aug 14, 2026
Attackers are already probing an unpatched GeoServer zero-day.The SQL injection flaw drew hundreds of attempts within hours of disclosure and, under certain configurations, can lead to remote code exe…
@thehackernews · Aug 13, 2026
CVE-2026-19487Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.The prescan walk…
@cveNotify · Aug 13, 2026
Wireshark 4.6.8 Released to Patch 28 Security Vulnerabilitieshttps://gbhackers.com/wireshark-4-6-8-released/
@PentestingNews · Aug 13, 2026
CVE-2026-8328The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer addres…
@cveNotify · Aug 13, 2026
CVE-2026-7210`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mit…
@cveNotify · Aug 13, 2026
CVE-2026-50544NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windo…
@cveNotify · Aug 13, 2026
CVE-2026-71471A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a…
@cveNotify · Aug 12, 2026
CVE-2025-15687A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation result…
@cveNotify · Aug 12, 2026
CVE-2025-15684A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component CER Handler. The manipulation results…
@cveNotify · Aug 12, 2026
CVE-2024-14044A vulnerability was identified in Open5GS up to 2.7.1. This issue affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Diameter Rx Handler. The manipu…
@cveNotify · Aug 12, 2026
CVE-2024-14043A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diame…
@cveNotify · Aug 12, 2026
CVE-2024-14042A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s6a-path.c of the component Diameter S…
@cveNotify · Aug 12, 2026
CVE-2026-33167Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exceptio…
@cveNotify · Aug 12, 2026
CVE-2026-68969Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PAT…
@cveNotify · Aug 12, 2026
ShieldBreak Windows Defender 0-Day Lets Attackers Bypass Microsoft Patch and Gain SYSTEM Privilegeshttps://gbhackers.com/shieldbreak-windows-defender-0-day/
@PentestingNews · Aug 12, 2026
CVE-2026-73432Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for b…
@cveNotify · Aug 12, 2026
CVE-2026-73431Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed to…
@cveNotify · Aug 12, 2026
CVE-2026-73405An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/ end…
@cveNotify · Aug 12, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.