An Italian CSIRT warning has put Fortinet operators back in triage mode, after multiple vulnerabilities were flagged in the vendor’s products, including two rated high severity.
CISA’s Known Exploited Vulnerabilities catalog is less a score and more a warning flag, forcing defenders to separate theoretical weakness from evidence of active abuse.
A high-severity warning on some ASUS drivers shows how a trusted software layer can become a privilege-escalation path when its permissions are too broad and its checks are too thin.
A routine browser milestone is carrying an outsized security message: six severe use-after-free flaws have been patched, underscoring how often browser defense still comes down to memory safety.
A crowded cyber-news week shows why patch volume, attribution-sensitive AI claims, and exploitability all have to be read together, not in isolation.
Two newly tracked WordPress vulnerabilities, labeled CVE-2026-60137 and CVE-2026-63030, were reported as already under exploitation, putting patch speed and version inventory at the center of the defense story.
Three patched vulnerabilities are now accompanied by public proof-of-concept material, a reminder that remediation does not end when the vendor ships an update.
Google has pushed a Chrome security update that closes seven vulnerabilities, and the mix of critical and high-severity bugs is a reminder that browser patching is now a race against reachability.
CISA’s KEV listing of two Fortinet flaws shows how a security appliance can become a remote-command foothold when command input is not properly controlled.
Two exploited command-injection flaws put Fortinet’s sandbox appliance in the uncomfortable role of attack surface, not inspection shield.
A newly patched Microsoft SharePoint Server flaw has been pushed into the federal watchlist, turning routine patching into a time-sensitive exposure hunt for defenders.
A security product built to inspect suspicious content is now itself part of the threat surface, and federal agencies have been told to move fast.
Two high-severity flaws in Splunk Enterprise and Splunk Cloud Platform matter because they sit close to the data layer defenders trust most: search, logs, and the files behind them.
A DigiCert survey points to a hard truth for enterprise security teams: AI risk is already showing up in day-to-day operations, and the control problem is bigger than one model or one tool.
Two Windows flaws in Citrix Secure Access Client and Endpoint Analysis Client put the spotlight on a quiet but high-value target: endpoint software that helps decide who gets into the corporate network.
Two actively exploited vulnerabilities in SonicWall’s SMA1000 remote access appliances put the focus on a familiar weak point: the device that stands between the internet and internal services.
A scheduled framework update for nine flaws is a reminder that version branches, not just vulnerability counts, decide how much risk reaches production.
A critical path traversal bug in IntelliJ IDEA is a reminder that the tools used to build software can become part of the attack surface themselves.
Google has pushed out security updates for Chrome that fix 15 vulnerabilities, including one critical issue and eight high-severity flaws, underscoring how much modern browser security depends on rapid patching and layered containment.
A monthly security release covering 622 vulnerabilities, including 2 zero-days, turns patching into an inventory and prioritization problem as much as a technical one.