Patch Security News

Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.

Patches are the other half of the vulnerability story: the fixes vendors ship once a flaw is confirmed, ranging from routine monthly bundles to emergency out-of-band releases for actively exploited bugs. Pair this feed with CVE and zero-day to see the full disclosure-to-fix timeline.

Recent Patch items

CVE-2026-102261 A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media Crop…
@cveNotify · Sep 29, 2026
CVE-2026-102244 A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Docu…
@cveNotify · Sep 29, 2026
CVE-2026-79766 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store att…
@cveNotify · Sep 29, 2026
CVE-2026-101281 A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendm…
@cveNotify · Sep 29, 2026
CVE-2026-92357 A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the…
@cveNotify · Sep 28, 2026
CVE-2026-90046 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP"…
@cveNotify · Sep 28, 2026
Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th) https://ift.tt/ukya0eq
@ctinow · Sep 28, 2026
CVE-2026-93302 MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certifi…
@cveNotify · Sep 28, 2026
CVE-2026-101132 A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of…
@cveNotify · Sep 28, 2026
CVE-2026-88816 DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key…
@cveNotify · Sep 28, 2026
CVE-2026-88815 DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and lengt…
@cveNotify · Sep 28, 2026
CVE-2026-101078 A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the compo…
@cveNotify · Sep 28, 2026
CVE-2026-101080 A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File A…
@cveNotify · Sep 28, 2026
CVE-2026-101078 A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the compo…
@cveNotify · Sep 28, 2026
CVE-2026-100835 Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patc…
@cveNotify · Sep 28, 2026
CVE-2026-100885 A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component…
@cveNotify · Sep 28, 2026
CVE-2026-101035 A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipu…
@cveNotify · Sep 28, 2026
CVE-2026-101035 A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipu…
@cveNotify · Sep 28, 2026
CVE-2026-101014 A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmar…
@cveNotify · Sep 28, 2026
CISA orders feds to patch exploited Citrix flaws by Wednesday The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems…
@bleepingcomputer · Sep 28, 2026
CISA orders feds to patch exploited Citrix flaws by Wednesday https://ift.tt/Cp4aFyd
@ctinow · Sep 28, 2026
CVE-2026-101003 A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Bro…
@cveNotify · Sep 28, 2026
CVE-2026-97521 In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_init() checks for duplicate quota_change IDs while holding qd_lock and…
@cveNotify · Sep 28, 2026
CVE-2026-100909 A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The…
@cveNotify · Sep 28, 2026
CVE-2026-100885 A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component…
@cveNotify · Sep 27, 2026
CVE-2026-100884 A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the com…
@cveNotify · Sep 27, 2026
CVE-2026-100883 A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can…
@cveNotify · Sep 27, 2026
CVE-2026-100882 A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php…
@cveNotify · Sep 27, 2026
CVE-2026-93302 MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certifi…
@cveNotify · Sep 27, 2026
WARNING — Citrix NetScaler is facing two unpatched RCE 0-days under active exploitation. Researchers at watchTowr say the flaws are being exploited in the wild. Citrix has not confirmed them or releas…
@thehackernews · Sep 27, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.