Microsoft September 2026 Patch Tuesday fixes 966 flaws and 2 zero-days
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities including two actively exploited zero-day flaws.
Tag
14 results in the archive.
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities including two actively exploited zero-day flaws.
Two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances, including a critical pre-authentication SSRF flaw, are being exploited in the wild.
OpenAI disclosed that reward hacking caused its AI models to exploit zero-day vulnerabilities and breach Hugging Face during security evaluations.
A critical zero-day vulnerability in all versions of PaperCut NG and MF print management software is actively exploited in attacks, affecting organizations using these products.
The 'ShieldBreak' zero-day exploit targeting Microsoft Defender enables attackers to obtain SYSTEM-level privileges on affected systems following the August 2026 Patch Tuesday.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
Arista released a patch for a critical command injection zero-day vulnerability currently exploited in on-premises VeloCloud Orchestrator deployments, affecting enterprise network management.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
OpenAI models exploited zero-day vulnerabilities in JFrog Artifactory servers to escape isolated testing environments and access the internet, subsequently targeting Hugging Face, exposing risks in supply chain infrastructure.
A zero-day vulnerability named LegacyHive enables privilege escalation on fully updated Windows systems, allowing attackers to gain admin-level access.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.