Announcements

Report Summary Cisco Security Updates – 24 October 2024

Cisco has released security updates to fix multiple vulnerabilities affecting several Cisco products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform cross-site request forgery attacks, perform cross-site scripting attacks, obtain sensitive information, perform SQL injection attacks, gain elevated privilege, perform denial of services attacks, or execute arbitrary commands and gain access […]

Report Summary Cisco Security Updates – 24 October 2024 Read More »

Fortinet Security Updates – 24 October 2024

Fortinet has released security updates to fix multiple vulnerabilities across several Fortinet products The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, perform denial of services attacks, or execute arbitrary code and gain access to the affected product. Sample of the addressed vulnerabilities: 1. FG-IR-24-423 Missing Authentication in Fgfmsd Vulnerability

Fortinet Security Updates – 24 October 2024 Read More »

Grafana Security Updates – 23 October 2024

Grafana has released security updates to address multiple vulnerabilities affecting several Grafana versions. The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: Grafana SQL Expressions Code Execution Vulnerability (CVE-2024-9264): CVSS: 9.9 Attack Vector: Network

Grafana Security Updates – 23 October 2024 Read More »

Oracle Security Patch Update – 16 October 2024

Oracle released its critical patch updates for October 2024, containing (334) new security patches for multiple affected products in Oracle code and third-party components. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, conducting cross-site scripting attacks, bypassing security restrictions, gaining elevated privileges,

Oracle Security Patch Update – 16 October 2024 Read More »

Palo Alto Security Updates – 10 October 2024

Palo Alto has released security updatesto fix multiple vulnerabilities across several Palo Alto products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, conduct reflected XSS attacks, obtain sensitive information, bypass security restrictions or execute arbitrary commands, and gain access to the affected systems. Sample of the addressed

Palo Alto Security Updates – 10 October 2024 Read More »

Mozilla Firefox Security Update – 10 October 2024

Mozilla has released an updated Firefox version 131.0.2, Firefox ESR versions 128.3.1, and 115.16.1 to fix a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to execute arbitrary code in the content process, and gain access to the affected products by exploiting a use-after-free in Animation timelines. Mozilla Firefox Code Execution Vulnerability (CVE-2024-9680):

Mozilla Firefox Security Update – 10 October 2024 Read More »

Ivanti Security Updates – 09 October 2024

Ivanti has released security updates to fix several vulnerabilities across multiple Ivanti products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, bypass security restrictions, gain elevated privileges, perform a denial of service attack, conduct SQL injection attacks, or execute arbitrary code and gain access to the affected system. Sample of the addressed

Ivanti Security Updates – 09 October 2024 Read More »

Cisco Security Updates – 03 October 2024

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, gain elevated privilege, perform denial of services attacks, or execute arbitrary commands and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Cisco Nexus Dashboard Fabric Controller Arbitrary

Cisco Security Updates – 03 October 2024 Read More »

Ivanti Security Update – 22 September 2024

Ivanti has released a security update to fix a critical vulnerability across Ivanti Cloud Services Appliance (CSA) version 4.6. The addressed vulnerability could allow the remote unauthenticated attacker to traverse directories on the system by sending a specially crafted URL request to access restricted functionality and obtain sensitive information. The threat actors could exploit this

Ivanti Security Update – 22 September 2024 Read More »

VMware Security Update – 18 September 2024

VMware has released a security update to address several vulnerabilities across multiple VMware products. The addressed vulnerabilities could allow the attacker to execute buffer overflow attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. VMware vCenter Server Buffer Overflow Vulnerability (CVE-2024-38812): CVSS: 9.8

VMware Security Update – 18 September 2024 Read More »

SolarWinds Security Update – 16 September 2024

SolarWinds has released a security update to address multiple vulnerabilities affecting SolarWinds ARM 2024.3 and prior versions. The addressed vulnerabilities could allow the attacker to bypass security restrictions or execute arbitrary code and gain access to the affected system. The addressed vulnerabilities: 1. SolarWinds Access Rights Manager Code Execution (CVE-2024-28991): CVSS: 9 Attack Vector: Adjacent

SolarWinds Security Update – 16 September 2024 Read More »

Tenable Security Updates – 12 September 2024

Tenable has released security updates to address multiple vulnerabilities in third-party components (OpenSSL and Expat) that are used by Nessus, and Nessus Agent. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Libexpat

Tenable Security Updates – 12 September 2024 Read More »

Elasticsearch Kibana Security Update – 11 September 2024

Elasticsearch has released a security update to fix critical vulnerabilities in Kibana versions 8.10.0 to 8.15.0. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code when Kibana attempts to parse a YAML document containing a crafted payload. Sample of the addressed vulnerabilities: Elasticsearch Kibana Remote Code Execution Vulnerability (CVE-2024-37285): CVSS: 9.1 Attack

Elasticsearch Kibana Security Update – 11 September 2024 Read More »

Ivanti Security Updates – 11 September 2024

Ivanti has released security updates to fix several vulnerabilities across multiple Ivanti products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Deserialization of Untrusted Data in The Agent Portal

Ivanti Security Updates – 11 September 2024 Read More »

Adobe Security Updates – 11 September 2024

Adobe has released security updates to fix several vulnerabilities across Adobe Acrobat Reader, ColdFusion, and Audition. The addressed vulnerabilities could allow the attacker to trigger denial of service attacks or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion Code Execution Vulnerability (CVE-2024-41874): CVSS: 9.8 Attack

Adobe Security Updates – 11 September 2024 Read More »

Progress LoadMaster Security Update – 09 September 2024

Progress has released a security update to address a critical vulnerability affecting LoadMaster 7.2.60.0 and all prior versions and Multi-Tenant Hypervisor 7.1.35.11 and all prior versions. The addressed vulnerability could allow the unauthenticated remote attacker to execute arbitrary code, and gain access to the affected LoadMaster’s management interface using a specially crafted HTTP request. Progress

Progress LoadMaster Security Update – 09 September 2024 Read More »

Veeam Security Update – 05 September 2024

Veeam has released a security update to fix several vulnerabilities across multiple Veeam products. The addressed vulnerabilities could allow the attacker to upload malicious files, obtain sensitive information, manipulate data and files, obtain credentials, gain elevated privileges, execute malicious commands, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Veeam VSPC

Veeam Security Update – 05 September 2024 Read More »

Cisco Security Updates – 05 September 2024

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or gain elevated privileges to the affected product. Sample of the addressed vulnerabilities: 1. Cisco Smart Licensing Utility Static Credential Vulnerability (CVE-2024-20439): CVSS: 9.8 Attack Vector: Network Attack

Cisco Security Updates – 05 September 2024 Read More »