Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

3+ day, 8+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > new-shieldcrash-zero-day-exploit-targets-microsoft-defender > amp

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender

3+ day, 11+ hour ago   (397+ words) The exploit provides full System privileges on Windows machines running the September 2026 patches. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However,…...

SecurityWeek
securityweek.com > chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

4+ day, 4+ hour ago   (453+ words) Major chipmakers AMD, Arm, and Nvidia published new security advisories on Tuesday to notify customers of vulnerabilities recently discovered in their products. AMD announced fixes for CVE-2026-43603, a NULL pointer dereference flaw in its Linux GPU kernel driver that could…...

SecurityWeek
securityweek.com > androids-september-2026-updates-patch-180-vulnerabilities

Android’s September 2026 Updates Patch 180 Vulnerabilities

4+ day, 4+ hour ago   (577+ words) The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. After two ‘no security vulnerabilities’ bulletins in July and August, Google on Tuesday announced the release of patches for 180 vulnerabilities as part of the September 2026 Android security…...

SecurityWeek
securityweek.com > ivanti-patches-critical-flaws-across-enterprise-security-products

Ivanti Patches Critical Flaws Across Enterprise Security Products

4+ day, 10+ hour ago   (410+ words) Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for…...

SecurityWeek
securityweek.com > sap-patches-critical-extended-passport-processing-vulnerability

SAP Patches Critical Extended Passport Processing Vulnerability

5+ day, 5+ hour ago   (626+ words) Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as…...

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

5+ day, 9+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 2+ day ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...

SecurityWeek
securityweek.com > 12-year-old-postgresql-vulnerability-enables-database-server-takeover

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

1+ week, 2+ day ago   (655+ words) PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports. An open source relational database system offering support for both relational (SQL) and non-relational (JSON) queries, PostgreSQL…...

SecurityWeek
securityweek.com > vmware-workstation-and-fusion-updates-patch-critical-vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

1+ week, 2+ day ago   (440+ words) The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as…...