Announcements

CrushFTP Security Update – 28 April 2024

CrushFTP has released a security update to fix a critical vulnerability in CrushFTP versions below 11.1. The addressed vulnerability could allow the unauthenticated remote attacker to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the affected system. CrushFTP Code Execution Vulnerability […]

CrushFTP Security Update – 28 April 2024 Read More »

Oracle Security Patch Update – 17 April 2024

Oracle released its critical patch updates for April 2024, containing (441) new security patches for multiple affected products in Oracle code and third-party components. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, bypassing security restrictions, and gaining access to the affected systems.

Oracle Security Patch Update – 17 April 2024 Read More »

Ivanti Security Updates – 17 April 2024

Ivanti has released security updates to fix several vulnerabilities affecting all versions of Ivanti Avalanche before version 6.4.3. The addressed vulnerabilities could allow the remote attacker to conduct denial of service attacks, obtain sensitive information, or execute arbitrary codes or commands and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Ivanti

Ivanti Security Updates – 17 April 2024 Read More »

Progress Security Updates – 15 April 2024

Progress has released security updates to address several vulnerabilities affecting multiple products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, or execute arbitrary commands on the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: Progress Flowmon OS Command Execution Vulnerability (CVE-2024-2389): CVSS: 10.0 Attack Vector: Network

Progress Security Updates – 15 April 2024 Read More »

Palo Alto Security Updates – 12 April 2024

Palo Alto has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, obtain information, elevate privileges, or perform denial-of-service attacks on the affected products. Sample of the addressed vulnerabilities: 1. Palo Alto OS Command Injection Vulnerability (CVE-2024-3400): CVSS: 10 Attack Vector: Network

Palo Alto Security Updates – 12 April 2024 Read More »

Fortinet Security Updates – 10 April 2024

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, and gain access to the affected products by sending specially crafted requests. Sample of the addressed vulnerabilities: 1. FortiClient Linux Remote Code Execution Vulnerability (CVE-2023-45590): CVSS: 9.4 Attack Vector: Network Attack

Fortinet Security Updates – 10 April 2024 Read More »

Linux XZ Utils Security Update – 31 March 2024

RedHat has warned users to immediately stop using systems running Fedora development and experimental versions because of a vulnerability found in the latest Linux XZ Utils versions 5.6.0 and 5.6.1. The severity of the addressed vulnerability could allow the remote attacker to gain unauthorized access to the entire affected system remotely, caused by malicious embedded

Linux XZ Utils Security Update – 31 March 2024 Read More »

Mozilla FireFox Security Updates – 23 March 2024

Mozilla has released an updated Firefox version 124.0.1, and Firefox ESR version 115.9.1 to fix two zero-day vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected products by fooling range-based bounds check elimination or injecting an event handler into a privileged object. The addressed vulnerabilities:

Mozilla FireFox Security Updates – 23 March 2024 Read More »

Atlassian Security Updates – 22 March 2024

Atlassian has released security updates to address several vulnerabilities across multiple products and third-party components included in Atlassian products. The addressed vulnerabilities could allow the attacker to manipulate data, view, add, modify, or delete information in the back-end database, obtain sensitive information, perform denial of service attacks, or execute arbitrary code and gain access to

Atlassian Security Updates – 22 March 2024 Read More »

Ivanti Security Updates – 21 March 2024

Ivanti has released security updates to fix two critical vulnerabilities across Ivanti Neurons for ITSM and Ivanti Standalone Sentry. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected systems. The addressed vulnerabilities: 1. Ivanti Neurons for ITSM Code Execution Vulnerability (CVE-2023-46808): CVSS: 9.9 Attack Vector: Network

Ivanti Security Updates – 21 March 2024 Read More »

Fortra Security Updates – 19 March 2024

Fortra has released security updates to address several vulnerabilities in multiple Fortra products. The addressed vulnerabilities could allow the remote attacker to conduct crosssite scripting attacks, perform directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allow files to be uploaded outside of the intended ‘uploadtemp’ directory by sending specially crafted POST requests,

Fortra Security Updates – 19 March 2024 Read More »

ManageEngine Security Update – 13 March 2024

ManageEngine has released a security update to address a critical vulnerability across Zoho ManageEngine Desktop Central version 9, build 90055. The addressed vulnerability could allow the remote attacker to upload arbitrary files, execute arbitrary PHP code, and gain access to the affected system by sending a specially crafted HTTP request. ManageEngine Desktop Central Unrestricted File

ManageEngine Security Update – 13 March 2024 Read More »

Fortinet Security Updates – 13 March 2024

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, gain elevated privileges, manipulate data, view, add, modify, or delete information in the back-end database, execute arbitrary code, and gain access to the affected products by sending specially crafted HTTP

Fortinet Security Updates – 13 March 2024 Read More »

VMware Security Updates – 06 March 2024

VMware has released security updates to address several vulnerabilities across multiple VMware products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. VMware Workstation/Fusion Use-after-free Vulnerability in XHCI USBController (CVE-2024-22252): CVSS: 9.3 Attack Vector: Local Attack

VMware Security Updates – 06 March 2024 Read More »

Linux Security Updates – 25 February 2024

Linux has released security updates to address several vulnerabilities in Linux Kernel. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Linux Kernel Information Disclosure Vulnerability (CVE-2024-26594): CVSS:

Linux Security Updates – 25 February 2024 Read More »

ConnectWise Security Updates – 21 February 2024

ConnectWise has released security updates to fix multiple vulnerabilities across ConnectWise ScreenConnect 23.9.7 and prior. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions and obtain administrative access, or traverse directories and obtain sensitive information by sending a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on

ConnectWise Security Updates – 21 February 2024 Read More »

VMware Security Updates – 21 February 2024

VMware has released security updates to address several vulnerabilities in multiple VMware products. The addressed vulnerabilities could allow the attacker to bypass security restrictions to request and relay service tickets for arbitrary Active Directory Service Principal Names (SPNs), or hijack the user’s session cookie to hijack a privileged EAP session, or gain elevated privileges to

VMware Security Updates – 21 February 2024 Read More »