Alerts

OpenSSH Security Update – 24 July 2023

OpenSSH released a security update to fix a vulnerability affecting all versions of OpenSSH before 9.3p2. The addressed vulnerability could allow the remote attacker to execute arbitrary code on the affected system by sending specially crafted requests. OpenSSH Code Execution Vulnerability (CVE-2023-38408): CVSS: 8.1 Attack Vector: Network Attack Complexity: High Privileges Required: None User Interaction: […]

OpenSSH Security Update – 24 July 2023 Read More »

Atlassian Security Updates – 24 July 2023

Atlassian has released security updates to address several vulnerabilities in Atlassian Confluence and Atlassian Bamboo. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, and execute arbitrary code on the affected systems. Sample of the addressed vulnerabilities: Atlassian Confluence Data Center and Atlassian Confluence Server Code Execution Vulnerability (CVE-2023-22508): CVSS:

Atlassian Security Updates – 24 July 2023 Read More »

Microsoft Edge Security Update – 24 July 2023

Microsoft has released an updated Edge version (115.0.1901.183) and extended stable version (114.0.1823.90) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain privileges or trigger spoofing attack by persuading the victim to open specially crafted file or request. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Privilege Escalation (CVE-2023-38187): CVSS: 7.5

Microsoft Edge Security Update – 24 July 2023 Read More »

Adobe ColdFusion Security Updates – 20 July 2023

Adobe has released security updates to fix multiple vulnerabilities in Adobe ColdFusion. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system via the deserialization of untrusted data or bypass security restrictions by persuading the victim to open a specially crafted file. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion

Adobe ColdFusion Security Updates – 20 July 2023 Read More »

Oracle Security Patch Updates July 2023

Oracle released its critical patch updates for July 2023, containing (508) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update includes security updates addressing numerous vulnerabilities that could potentially be exploited remotely without authentication. The affected product

Oracle Security Patch Updates July 2023 Read More »

Citrix Security Updates – 19 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix ADC, and Citrix Gateway. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, perform cross-site scripting attacks, or gain elevated privileges on the affected systems. The addressed vulnerabilities: 1. Citrix ADC, Citrix Gateway Unauthenticated Remote Code Execution (CVE- 2023-3519):

Citrix Security Updates – 19 July 2023 Read More »

Adobe ColdFusion Security Updates – 18 July 2023

Adobe has released security updates to fix multiple vulnerabilities in Adobe ColdFusion. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system via the deserialization of untrusted data or bypass security restrictions by persuading the victim to open a specially crafted file. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion

Adobe ColdFusion Security Updates – 18 July 2023 Read More »

Microsoft Edge Security Update – 16 July 2023

Microsoft has released an updated Edge version (114.0.1823.82) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain access or trigger a spoofing attack by persuading the victim to open a specially crafted file or request. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Code Execution (CVE-2023-36887): CVSS: 7.8 Attack Vector: Local

Microsoft Edge Security Update – 16 July 2023 Read More »

Juniper Security Updates – 13 July 2023

Juniper has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform denial of service, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: Juniper Networks Junos OS Denial of Service Vulnerability (CVE-2023-36832): CVSS: 7.5 Attack Vector:

Juniper Security Updates – 13 July 2023 Read More »

Drupal Security Update – 13 July 2023

Drupal has released a security update to fix a vulnerability in the Drupal Two-factor Authentication module versions before tfa 8.x-1.1. The addressed vulnerability could allow the remote attacker to bypass access restrictions to reset the password by sending a specially crafted request to the affected products. Two-factor Authentication Module for Drupal Security Bypass Vulnerability (SACONTRIB-

Drupal Security Update – 13 July 2023 Read More »

SonicWall Security Updates – 13 July 2023

SonicWall has released security updates to fix multiple vulnerabilities affecting multiple SonicWall products. The addressed vulnerabilities could allow the attacker to bypass authentication, directory traversal, or disclose information on the affected systems. Sample of the addressed vulnerabilities: 1. Password Hash Read via Web Service (CVE-2023-34134): CVSS: 9.8 Attack Vector: Network Attack Complexity: High Privileges Required:

SonicWall Security Updates – 13 July 2023 Read More »

Citrix Security Updates – 12 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix Secure Access Client. The addressed vulnerabilities could allow the attacker to execute arbitrary code or gain elevated privileges on the affected systems. The addressed vulnerabilities: 1. Citrix Secure Access Client for Ubuntu Code Execution (CVE-2023-24492): CVSS: 9.6 Attack Vector: Network Attack Complexity: Low Privileges

Citrix Security Updates – 12 July 2023 Read More »

Zoom Security Updates – 12 July 2023

Zoom has released security updates to fix vulnerabilities in Zoom Rooms, Zoom Windows Client, and Zoom Client SDK. The addressed vulnerabilities could allow the attacker to escalate privileges, or disclose information on the affected systems. Sample of the addressed vulnerabilities: 1. Zoom Rooms Improper Input Validation (CVE-2023-36538): CVSS: 8.4 Attack Vector: Local Attack Complexity: Low

Zoom Security Updates – 12 July 2023 Read More »

Fortinet Security Updates – 12 July 2023

Fortinet has released security updates to fix several vulnerabilities in multiple Fortinet products. The addressed vulnerabilities could allow the attacker to overflow a buffer, execute arbitrary code, directory traversal, obtain sensitive information, and gain access to the affected products by sending specially crafted requests. Sample of the addressed vulnerabilities: Fortinet FortiOS and Fortinet FortiProxy Buffer

Fortinet Security Updates – 12 July 2023 Read More »

SAP July 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (2) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Business Client, SAP ECC and SAP S/4HANA (IS-OIL), SAP NetWeaver, SAP Web Dispatcher, SAP UI5

SAP July 2023 Security Patch Day Read More »