Cisco released a security advisory to address a high-severity vulnerability tracked as CVE-2026-20349. The vulnerability impacts the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause the affected device … Continue reading “Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)”
Author: Diksha Ojha
Microsoft Patch Tuesday, August 2026 Security Update Review
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security. This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. In this month’s updates, Microsoft has addressed three zero-day vulnerabilities: two publicly disclosed and one exploited … Continue reading “Microsoft Patch Tuesday, August 2026 Security Update Review”
Cisco Addresses Catalyst SD-WAN Software Multiple Vulnerabilities (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, & CVE-2026-20313)
Cisco released a security advisory addressing five vulnerabilities affecting Catalyst SD-WAN Software. Three of these vulnerabilities have been given a critical severity rating with a CVSS score of 9.9. These vulnerabilities were disclosed during internal testing conducted by the Cisco team. The vulnerabilities are not known to be exploited in the wild.
Cisco IOS XE Software Multiple Vulnerabilities (CVE-2026-20267, CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, CVE-2026-20272, & CVE-2026-20273)
Cisco releases security patches to address seven vulnerabilities impacting Cisco IOS XE Software. Only one of these vulnerabilities has given a critical severity rating with a CVSS score of 9.0. These vulnerabilities were disclosed during internal testing conducted by the Cisco team. The vulnerabilities are not known to be exploited in the wild.
CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)
CISA has warned U.S. government agencies about an actively exploited vulnerability impacting Cisco Secure Firewall Management Center. CISA added the CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 1, 2026. Successful exploitation of this vulnerability could allow an attacker to log in to the affected system and access sensitive data as … Continue reading “CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)”
JetBrains TeamCity Remote Code Execution Vulnerability (CVE-2026-63077)
JetBrains released a security advisory addressing a critical severity vulnerability impacting TeamCity On-Premises. Tracked as CVE-2026-63077, successful exploitation of the vulnerability may allow an unauthenticated attacker to bypass authentication checks and execute arbitrary operating system commands. JetBrains mentioned in their advisory that they are not aware of any active exploitation of this vulnerability. CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities … Continue reading “JetBrains TeamCity Remote Code Execution Vulnerability (CVE-2026-63077)”
VMware ESX, vCenter, Workstation, and Fusion Multiple Vulnerabilities
Broadcom has released a security advisory addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. Three of these vulnerabilities, tracked as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, have been given critical severity ratings.
Adobe Releases Patches for Multiple Critical Vulnerabilities
Adobe released two security advisories addressing nine vulnerabilities affecting the Adobe Bridge and Adobe Format Plugins. All these vulnerabilities have critical severity ratings given by Adobe.
Oracle Critical Patch Update, July 2026 Security Update Review
Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this quarterly Oracle Critical Patch Update, Oracle E-Business Suite received the highest … Continue reading “Oracle Critical Patch Update, July 2026 Security Update Review”
WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)
Threat actors have released public exploit code for the WordPress core remote code execution vulnerabilities, named wp2shell. Tracked as CVE-2026-63030 and CVE-2026-60137, the vulnerabilities can be chained together to achieve pre-authentication remote code execution. Adam Kues of Searchlight Cyber discovered and reported the vulnerability to WordPress. The article mentioned that more than 500 million websites use WordPress, which … Continue reading “WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)”