Announcements

SolarWinds Security Updates – 24 September 2025

SolarWinds has released security updates to address multiple vulnerabilities affecting SolarWinds Web Help Desk 12.8.7 and all previous versions, and SolarWinds Database Performance Analyzer 2025.2 and previous versions. The addressed vulnerabilities could allow the attacker to run commands on the host machine and gain unauthorized access to the affected product, or enable a man-in-the-middle (MITM) […]

SolarWinds Security Updates – 24 September 2025 Read More »

Fortra Security Update – 21 September 2025

Fortra has released a security update to fix a critical vulnerability in GoAnywhere MFT’s License Servlet. The addressed vulnerability could allow the remote attacker with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. Deserialization Vulnerability in GoAnywhere MFT’s License Servlet (CVE-2025-10035): CVSS: 10 Attack Vector: Network

Fortra Security Update – 21 September 2025 Read More »

Adobe Security Updates – 10 September 2025

Adobe has released security updates to address several vulnerabilities across multiple Adobe products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability (CVE-2025-54236):

Adobe Security Updates – 10 September 2025 Read More »

Microsoft September 2025 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as PatchTuesday. The  mentioned patch addressed two zero-day vulnerabilities. Microsoft has fixed (95) vulnerabilities, with (4) classified as critical, as they could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, bypass security restrictions, or execute arbitrary code and

Microsoft September 2025 Patch Tuesday Read More »

SAP Security Patch Day September 2025

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products, such as SAP NetWeaver, SAP S/4HANA, SAP Landscape Transformation, SAP Business One, ABAP Platform, SAP Cloud, SAP BusinessObjects Business Intelligence Platform, and SAP Supplier Relationship Management. The attacker could

SAP Security Patch Day September 2025 Read More »

Citrix Security Updates – 27 August 2025

Citrix has released a security update to address several vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform denial-of-service attacks, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. NetScaler ADC and NetScaler Gateway Remote

Citrix Security Updates – 27 August 2025 Read More »

Drupal Security Updates – 19 August 2025

Drupal has released security updates to fix several vulnerabilities across multiple Drupal versions. The addressed vulnerabilities could allow the attacker to conduct cross-site scripting attacks, perform server-side request forgery attacks, bypass security restrictions, or gain access to the affected products. Sample of the addressed vulnerabilities: Authenticator Login Module for Drupal (SA-CONTRIB-2025-096) Security Bypass Vulnerability (CVE-2025-8995):

Drupal Security Updates – 19 August 2025 Read More »

Cisco Security Updates – 17 August 2025

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected systems. Sample of addressed vulnerabilities: 1. Cisco Secure Firewall Management Center Software RADIUS

Cisco Security Updates – 17 August 2025 Read More »

Fortinet Security Updates – 13 August 2025

Fortinet has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, conduct cross-site scripting attacks, obtain sensitive information, bypass security restrictions, read arbitrary files via uploading a malicious solution pack, or execute arbitrary code and gain access to

Fortinet Security Updates – 13 August 2025 Read More »

Zoom Security Update – 13 August 2025

Zoom has released a security update to fix multiple vulnerabilities across Zoom Client for Windows. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, manipulate files, or gain elevated privileges on the affected system. Sample of the addressed vulnerabilities: 1. Zoom Clients for Windows – Untrusted Search Path (CVE-2025-49457): CVSS: 9.6

Zoom Security Update – 13 August 2025 Read More »

Adobe Security Updates – 06 August 2025

Adobe has released security updates to fix two vulnerabilities affecting Adobe Experience Manager. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information or execute arbitrary code and gain access to the affected product. The addressed vulnerabilities: 1. Adobe Experience Manager Code Execution Vulnerability (CVE-2025-54253): CVSS: 10 Attack Vector: Network Attack Complexity: Low

Adobe Security Updates – 06 August 2025 Read More »

Trend Micro Security Updates – 06 August 2025

Trend Micro has released security updates to address several vulnerabilities affecting Trend Micro Apex One (On-prem) 2019, and Apex One Management Server version 14039 and below. The addressed vulnerabilities could allow the remote attacker to execute arbitrary commands and gain access to the affected product. Sample of addressed vulnerabilities: Trend Micro Apex One Command Execution

Trend Micro Security Updates – 06 August 2025 Read More »

Apple Security Updates – 31 July 2025

Apple has released security updates to address multiple vulnerabilities across Safari, macOS Sequoia, Sonoma, and Ventura. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, cause memory corruption, bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, and gain access to the affected system. Sample of the addressed

Apple Security Updates – 31 July 2025 Read More »

Microsoft Security Update – 21 July 2025

Microsoft has released a security update to fix several vulnerabilities across multiple Microsoft products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform spoofing over a network, execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Azure Machine Learning Elevation of Privilege (CVE-2025-49747): CVSS: 9.9

Microsoft Security Update – 21 July 2025 Read More »

CrushFTP Security Update – 20 July 2025

CrushFTP has released a security update to fix a critical vulnerability in CrushFTP versions below “10.8.5 and 11.3.4_23”. The addressed vulnerability could allow the attacker to gain elevated privileges and obtain administrative access to the affected system through HTTPS. CrushFTP Privilege Escalation Vulnerability (CVE-2025-54309): CVSS: 9.0 Attack Vector: Network Attack Complexity: High Privileges Required: None

CrushFTP Security Update – 20 July 2025 Read More »

Cisco Security Updates – 17 July 2025

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to perform server-side request forgery attacks, bypass security restrictions, obtain sensitive information, execute arbitrary code, and gain access to the affected systems. Sample of addressed vulnerabilities: 1. Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

Cisco Security Updates – 17 July 2025 Read More »

Juniper Security Updates – 17 July 2025

Juniper has released security updates to fix several vulnerabilities affecting multiple Juniper Networks products. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, obtain sensitive information, gain elevated privileges, bypass security restrictions, execute arbitrary commands, and gain access to the affectedsystem. Sample of the addressed vulnerabilities: 1. Juniper Networks Juniper

Juniper Security Updates – 17 July 2025 Read More »