Alerts

F5 Security Updates – 13 May 2025

F5 has released security updates to address several vulnerabilities affecting multiple F5 products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, manipulate files, bypass security restrictions, perform denial of service attacks, or gain access by using SSH key-based authentication to the affected product. Sample of the addressed vulnerabilities: 1. F5OS Improper Authorization […]

F5 Security Updates – 13 May 2025 Read More »

VMware Security Updates – 13 May 2025

VMware has released security updates to fix multiple vulnerabilities across several VMware products. The addressed vulnerabilities could allow the remote attacker with non-administrative privileges on a guest VM to manipulate certain files or perform cross-site scripting attacks on the affected product. Sample of the addressed vulnerabilities: VMware Aria Automation DOM-Based Cross-Site Scripting Vulnerability (CVE-2025-22249): CVSS:

VMware Security Updates – 13 May 2025 Read More »

SAP Security Updates – 13 May 2025

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products, such as SAP NetWeaver, SAP Supplier Relationship Management, SAP Business Objects Business Intelligence Platform, SAP PDCE, SAP Service Parts Management (SPM), and SAP Landscape Transformation. The attacker could exploit

SAP Security Updates – 13 May 2025 Read More »

Cisco Security Updates – 08 May 2025

Cisco has released security updates to fix multiple vulnerabilities affecting several Cisco products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, upload arbitrary files, conduct cross-site request forgery (CSRF) attacks, read and modify the outgoing proxy configuration settings, perform cross-site scripting attacks, bypass security restrictions, conduct command injection attacks, escalate

Cisco Security Updates – 08 May 2025 Read More »

Elasticsearch Kibana Security Update – 07 May 2025

Elasticsearch has released a security update to a fix critical vulnerability affecting Kibana versions from 8.3.0 to 8.17.5, 8.18.0, and 9.0.0. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected product by uploading a crafted HTTP request. Kibana Code Execution Vulnerability via Prototype Pollution (CVE-2025-25014): CVSS:

Elasticsearch Kibana Security Update – 07 May 2025 Read More »

Mozilla Firefox Security Updates – 04 May 2025

Mozilla has released an updated Firefox version 138, Firefox ESR versions 128.10, and 115.23 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Improper Process

Mozilla Firefox Security Updates – 04 May 2025 Read More »

Microsoft Edge Security Update – 04 May 2025

Microsoft has released an updated Microsoft Edge stable channel “136.0.3240.50” to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to perform a denial of service attack, obtain sensitive information, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based) Heap Buffer Overflow

Microsoft Edge Security Update – 04 May 2025 Read More »

SonicWall Security Update – 04 May 2025

SonicWall has released a security update to fix one vulnerability affecting SonicWall SMA1000. The addressed vulnerability could allow the remote attacker to perform a serverside request forgery (SSRF) which will cause the appliance to make requests to an unintended location. Sonicwall SMA1000 Server-Side Request Forgery Vulnerability (CVE-2025-2170): CVSS: 7.2 Attack Vector: Network Attack Complexity: Low

SonicWall Security Update – 04 May 2025 Read More »

SonicWall Security Update – 27 April 2025

SonicWall has released a security update to address a vulnerability across SonicOS SSLVPN Virtual Office interface. The addressed vulnerability could allow the unauthenticated remote attacker to cause a denial of service attack and crash the affected firewall system. SonicOS SSLVPN NULL Pointer Dereference Denial-of-Service Vulnerability (CVE-2025-32818): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low Privileges

SonicWall Security Update – 27 April 2025 Read More »

SAP Security Updates – 27 April 2025

SAP has released security updates to address several vulnerabilities affecting SAP NetWeaver, SAP S/4 HANA, and SAP Field Logistics. The addressed vulnerabilities could allow the attacker to perform cross-site request forgery attacks, manipulate data, or execute arbitrary code and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Missing Authorization Check in

SAP Security Updates – 27 April 2025 Read More »

Google Chrome Security Update – 22 April 2025

Google has released an updated Chrome version “135.0.7049.95/.96” for Windows, Mac, and “135.0.7049.95” for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code via a crafted HTML page and gain access to the affected system. Sample of the addressed vulnerabilities: Google Chrome Heap Buffer Overflow in Codecs Vulnerability (CVE-2025-3619): CVSS: 8.8

Google Chrome Security Update – 22 April 2025 Read More »

Cisco Security Updates – 22 April 2025

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, collect sensitive information, or execute arbitrary commands and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Cisco Webex App Client-Side Remote Code Execution Vulnerability (CVE-2025-20236): CVSS: 8.8

Cisco Security Updates – 22 April 2025 Read More »

SonicWall Security Updates – 17 April 2025

SonicWall has released security updates to address several vulnerabilities across SonicWall NetExtender Windows, Connect Tunnel Windows, and the SMA 100 series. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, cause file corruption, manipulate file paths, or execute arbitrary code and gain access to the affected system. Sample of the addressed

SonicWall Security Updates – 17 April 2025 Read More »

Apple Security Updates – 17 April 2025

Apple has released security updates to address several vulnerabilities across macOS Sequoia. The addressed vulnerabilities could allow the attacker to bypass security restrictions, execute arbitrary code, and gain access to the affected system. The addressed vulnerabilities: 1. Apple macOS Sequoia Code Execution Vulnerability ( CVE-2025-31200): CVSS: 7.5 Attack Vector: Network Attack Complexity: High Privileges Required:

Apple Security Updates – 17 April 2025 Read More »

Oracle Security Patch Update – 16 April 2025

Oracle released its critical patch updates for April 2025, containing (378) new security patches for multiple affected products in Oracle code and third-party components. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, conducting denial of service attacks, performing data manipulation (update, insert, or delete access), or executing

Oracle Security Patch Update – 16 April 2025 Read More »

Microsoft Edge Security Update – 13 April 2025

Microsoft has released an updated Microsoft Edge stable channel “135.0.3179.73” to address a vulnerability. The addressed vulnerability could allow the remote attacker to execute arbitrary code by persuading the victim to visit a malicious page. Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2025-29834): CVSS: 7.5 Attack Vector: Network Attack Complexity: High Privileges Required: None User

Microsoft Edge Security Update – 13 April 2025 Read More »

Juniper Security Updates – 10 April 2025

Juniper has released security updates to fix several vulnerabilities affecting multiple Juniper Networks products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, obtain sensitive information, or execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Juniper Networks Junos OS (SRX Series) Denial of

Juniper Security Updates – 10 April 2025 Read More »

Aruba Security Updates – 09 April 2025

HPE Aruba has released security updates to fix multiple vulnerabilities affectingseveral Aruba  products. The addressed vulnerabilities could allow the attacker to execute arbitrary code/commands, download arbitrary files, perform cross-site scripting (XSS), modify files, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Authenticated Remote Code Execution Vulnerabilities in Web-Based Management Interface

Aruba Security Updates – 09 April 2025 Read More »

Adobe Security Updates – 09 April 2025

Adobe has released security updates to fix several vulnerabilities across multiple Adobe products. The addressed vulnerabilities could allow the attacker to perform denial-of-service attacks, bypass security restrictions, gain elevated privileges, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion Deserialization of Untrusted Data (CWE-502) Vulnerability (CVE-2025-24447):

Adobe Security Updates – 09 April 2025 Read More »