Announcements

Adobe Security Updates – 14 May 2025

Adobe has released security updates to address multiple vulnerabilities across several Adobe products. information, bypass security restrictions, execute arbitrary code, and gain elevated privileges to the affected products. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion Improper Input Validation Vulnerability (CVE-2025- 43559): CVSS: 9.1 Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction: […]

Adobe Security Updates – 14 May 2025 Read More »

Fortinet Security Updates – 14 May 2025

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, perform denial of service attacks, gain access to sensitive information, and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Stack-Based Buffer Overflow Vulnerability in

Fortinet Security Updates – 14 May 2025 Read More »

Ivanti Security Updates – 14 May 2025

Ivanti has released security updates to fix multiple vulnerabilities across several Ivanti products. The addressed vulnerabilities could allow the attacker to escalate elevated privileges, access protected resources without proper credentials via the API, execute arbitrary code via crafted API requests, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Ivanti Neurons

Ivanti Security Updates – 14 May 2025 Read More »

Microsoft May 2025 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed seven zero-day vulnerabilities. Microsoft has fixed (78) vulnerabilities, with (5) classified as critical as they could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, bypass security restrictions, or execute arbitrary code

Microsoft May 2025 Patch Tuesday Read More »

SAP Security Updates – 13 May 2025

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products, such as SAP NetWeaver, SAP Supplier Relationship Management, SAP Business Objects Business Intelligence Platform, SAP PDCE, SAP Service Parts Management (SPM), and SAP Landscape Transformation. The attacker could exploit

SAP Security Updates – 13 May 2025 Read More »

SAP Security Updates – 13 May 2025

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products, such as SAP NetWeaver, SAP Supplier Relationship Management, SAP Business Objects Business Intelligence Platform, SAP PDCE, SAP Service Parts Management (SPM), and SAP Landscape Transformation. The attacker could exploit

SAP Security Updates – 13 May 2025 Read More »

Cisco Security Updates – 08 May 2025

Cisco has released security updates to fix multiple vulnerabilities affecting several Cisco products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, upload arbitrary files, conduct cross-site request forgery (CSRF) attacks, read and modify the outgoing proxy configuration settings, perform cross-site scripting attacks, bypass security restrictions, conduct command injection attacks, escalate

Cisco Security Updates – 08 May 2025 Read More »

Elasticsearch Kibana Security Update – 07 May 2025

Elasticsearch has released a security update to a fix critical vulnerability affecting Kibana versions from 8.3.0 to 8.17.5, 8.18.0, and 9.0.0. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected product by uploading a crafted HTTP request. Kibana Code Execution Vulnerability via Prototype Pollution (CVE-2025-25014): CVSS:

Elasticsearch Kibana Security Update – 07 May 2025 Read More »

Mozilla Firefox Security Updates – 04 May 2025

Mozilla has released an updated Firefox version 138, Firefox ESR versions 128.10, and 115.23 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Improper Process

Mozilla Firefox Security Updates – 04 May 2025 Read More »

SAP Security Updates – 27 April 2025

SAP has released security updates to address several vulnerabilities affecting SAP NetWeaver, SAP S/4 HANA, and SAP Field Logistics. The addressed vulnerabilities could allow the attacker to perform cross-site request forgery attacks, manipulate data, or execute arbitrary code and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Missing Authorization Check in

SAP Security Updates – 27 April 2025 Read More »

Oracle Security Patch Update – 16 April 2025

Oracle released its critical patch updates for April 2025, containing (378) new security patches for multiple affected products in Oracle code and third-party components. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, conducting denial of service attacks, performing data manipulation (update, insert, or delete access), or executing

Oracle Security Patch Update – 16 April 2025 Read More »

Adobe Security Updates – 09 April 2025

Adobe has released security updates to fix several vulnerabilities across multiple Adobe products. The addressed vulnerabilities could allow the attacker to perform denial-of-service attacks, bypass security restrictions, gain elevated privileges, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion Deserialization of Untrusted Data (CWE-502) Vulnerability (CVE-2025-24447):

Adobe Security Updates – 09 April 2025 Read More »

Fortinet Security Updates – 09 April 2025

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, gain elevated privileges, bypass security restrictions, or execute arbitrary code, and gain access to the affected product. Sample of the addressed vulnerabilities: 1. FortiSwitch Unverified Password Change Escalation of

Fortinet Security Updates – 09 April 2025 Read More »

SAP April 2025 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a critical patch that fixes several vulnerabilities affecting multiple SAP products such as SAP S/4HANA (Private Cloud), SAP Financial Consolidation, SAP BusinessObjects Business Intelligence platform (Central Management Console), and SAP Landscape Transformation (Analysis Platform). The attacker could exploit some

SAP April 2025 Security Patch Day Read More »

Ivanti Security Update – 06 April 2025

Ivanti has released security updates to address a critical vulnerability affecting multiple Ivanti products. The vulnerability could allow the remote unauthenticated attacker to execute arbitrary code through a stack-based buffer overflow and gain access to the affected product. Ivanti Connect Secure, Policy Secure, and ZTA Gateways Remote Code Execution Vulnerability (CVE-2025-22457): CVSS: 9 Attack Vector:

Ivanti Security Update – 06 April 2025 Read More »

Apple Security Updates – 03 April 2025

Apple has released security updates to address multiple vulnerabilities across macOS Sequoia, Sonoma, Ventura, and Safari. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Apple

Apple Security Updates – 03 April 2025 Read More »

Mozilla FireFox Security Updates – 03 April 2025

Mozilla has released an updated Firefox version 137, Firefox ESR versions 128.9, and 115.2 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, conduct exploitable crashes, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities:  1. Mozilla Firefox Sandbox Escape Vulnerability (CVE-2025-2857):

Mozilla FireFox Security Updates – 03 April 2025 Read More »

Veeam Security Update – 20 March 2025

Veeam has released a security update to fix a critical vulnerability across Veeam Backup & Replication systems. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system. Veeam Backup Arbitrary Code Execution Vulnerability (CVE-2025-23120): CVSS: 9.9 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User

Veeam Security Update – 20 March 2025 Read More »

Elasticsearch Kibana Security Update – 09 March 2025

Elasticsearch has released a security update to a fix critical vulnerability affecting Kibana versions from 8.15.0 to 8.17.3. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access by uploading a crafted HTTP request. Elasticsearch Kibana Remote Code Execution Vulnerability (CVE-2025-25015): CVSS: 9.9 Attack Vector: Network Attack Complexity: Low Privileges

Elasticsearch Kibana Security Update – 09 March 2025 Read More »

Mozilla FireFox Security Updates – 06 March 2025

Mozilla has released an updated Firefox version 136, Firefox ESR versions 128.8, and 115.21 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, conduct exploitable crashes, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Exploitable out-of-bounds Access Vulnerability

Mozilla FireFox Security Updates – 06 March 2025 Read More »