News
Oracle Ships 943 Patches: CVE-2026-61241 Hits Max CVSS 10.0
InfrastructureSecurity
Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.
2026.08.1925 views
News
VMware vCenter CVE-2026-59310 Exploited: Patch Now, No Workaround
SecurityInfrastructure
CISA added VMware vCenter CVE-2026-59310 (CVSS 9.8) to KEV after 361 intrusions in 47 countries. No workaround — update to 8.0 U3k/U2f, 9.0.2.0100, 9.1.0.0300.
2026.08.1973 views
News
ManageEngine Password Manager Pro CVE-2026-11840: mind the build
InfrastructureSecurity
A CVSS 8.8 SQL injection hits ManageEngine Password Manager Pro and PAM360. The Japanese build line differs: 13232 does not exist there, and 13234 is the fix.
2026.08.1315 views
News
SAP August 2026: A 10.0 Flaw (CVE-2026-58231) and No Japanese Advisory
InfrastructureSecurity
SAP shipped its August 2026 fixes: a 10.0 in Commerce Cloud and a 9.8 in NetWeaver ABAP, both unauthenticated. The 9.8 has no workaround and needs downtime.
2026.08.1241 views
News
Cisco VPN Gateways Knocked Offline: CVE-2026-20349, Scope and Fixes
SecurityInfrastructure
Cisco ASA and FTD let anyone reboot the device with no login, cutting VPN access. Already exploited, no workaround, and CISA set an August 14 deadline.
2026.08.1259 views
News
Nine quiet days for Cisco IOS XE's ten flaws, and a correction on CVE-2026-20310
SecurityInfrastructure
Cisco disclosed ten IOS XE vulnerabilities at once, the worst rated 9.8, none with a workaround. They did not surface through attacks — Cisco found them in its own internal review.
2026.08.0654 views
News
Two Flaws in Japan's NetKids iMark Network Monitor, and No Fixed Version Exists
SecurityInfrastructureJapanese Companies
Two vulnerabilities were disclosed in NetKids iMark, a Japanese-made network monitoring tool, on August 5, 2026. Anyone who can log in to the machine can seize SYSTEM privileges. Every build up to and including the current V5.2.5.0 is affected and no fix has shipped. Neither works over the internet, but a monitoring server holds the map of your network. Here are the two workarounds.
2026.08.0532 views
News
N-central: Patch to 2026.3.1.10 as Ransomware Follows CVE-2026-18577
InfrastructureSecurity
N-able N-central has a login bypass that hands over administrator accounts. The vendor rates it as actively attacked and has published indicators of compromise. Fixed in build 2026.3.1.7.
2026.08.0336 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
SecurityDevelopmentInfrastructure
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0327 views
News
Azure Cosmos DB CVE-2026-66803: Fixed by Microsoft, No Action Needed
InfrastructureSecurity
Azure Cosmos DB had a CVSS 10.0 flaw (CVE-2026-66803) risking takeover of any database. Microsoft fixed it server-side; no user action, no known exploitation.
2026.07.3147 views
News
No victim reports after the CVE-2025-68686 deadline — and Fortinet still says 'not exploited'
SecurityInfrastructure
FortiGate's FortiOS has a confirmed-exploited data-leak flaw (CVE-2025-68686). It cannot break in on its own and only affects already-breached devices. See affected versions, fixes, and how to check for a prior breach.
2026.07.3139 views
News
Cisco FMC Hardcoded Password CVE-2026-20316 Under Active Attack
InfrastructureSecurityGlobal Companies
Cisco FMC carries a password baked into the product. Unauthenticated login, active exploitation, CISA deadline August 1. And it was public four months earlier.
2026.07.3041 views