CISA has identified two Linux Kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, as actively exploited and added them to its Known Exploited Vulnerabilities Catalog, urging high-priority remediation.
Microsoft released out-of-band updates to address Remote Desktop Services failures and issues affecting Hyper-V and USB audio on certain Windows versions.
The Dutch Nationaal Cyber Security Centrum warns of imminent exploitation of critical vulnerabilities CVE-2026-85102 and CVE-2026-85103 affecting Check Point VPN appliances.
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities Catalog due to active exploitation, requiring urgent attention for remediation.
PaperCut released a second emergency patch addressing two actively exploited vulnerabilities in its NG and MF print management software after initial mitigations were bypassed.
Microsoft released a patch for a critical vulnerability in Entra ID that is actively exploited in targeted attacks, affecting identity and access management security.
F5 released patches for CVE-2026-42533, a critical nginx flaw allowing remote, unauthenticated attackers to trigger a heap buffer overflow that can crash workers or enable remote code execution.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.