Friday , July 31 2026

Vulnerabilities

ALERT
Chrome fix 29 vulnerabilities, must update immediately

Chrome

Google has released Chrome version 146 with important security updates for Windows, Mac, and Linux users. If the flaw remains unpatched, attackers run arbitrary code, compromise systems, or cause denial-of-service issues. The critical vulnerability in this release is CVE-2026-3913, which is a severe heap buffer overflow in the WebML component. …

Read More »

ALERT
Zoom Windows Workplace Vulnerabilities Allow Privilege Escalation

windows client

Zoom has issued four security bulletins detailing several vulnerabilities in its windows client suite. The critical vulnerability CVE-2026-30903 (ZSB-26005) affects the Mail feature in Zoom Workplace for Windows. The issue arises from External Control of File Name or Path, which allows attackers to manipulate file references and carry out unauthorized …

Read More »

Cisco Secure FMC Flaw Enables Remote Code Execution allowing root access 

FMC

Cisco has released an urgent security alert for a critical flaw in its Secure Firewall Management Center (FMC) software. The critical flaw with a CVSS score of 10.0 lets remote, unauthenticated attackers execute arbitrary code and take full control of the affected system. This vulnerability is found in Cisco Secure FMC’s …

Read More »

New MongoDB Vuln Allow Hackers Crash Any MongoDB Server

MongoDB

A new vulnerability, CVE-2026-25611 (CVSS 7.5), has been found in MongoDB, enabling attackers to crash open servers with little bandwidth. According to Cato CTRL, it affects all MongoDB versions where compression is enabled (v3.4+, on by default since v3.6), including MongoDB Atlas. Shodan data shows that over 207,000 MongoDB instances …

Read More »

Android update Patched 129 Vulns and Actively Exploited Zero-Day

129

Google has launched a major security update, fixing 129 vulnerabilities in the March 2026 Android Security Bulletin. This update is crucial due to reports that attackers are exploiting a high-severity flaw. The centerpiece of this month’s alert is CVE-2026-21385, a high-severity memory corruption vulnerability affecting a Qualcomm display component. Google …

Read More »

Trend Micro alerts of critical Apex One code execution flaws

Apex One

Trend Micro fixed two serious vulnerabilities in Apex One that let attackers execute remote code on affected Windows systems. Apex One is an endpoint security platform that identifies and addresses security threats like malware, spyware, and vulnerabilities. The first critical Apex One security flaw patched this week (CVE-2025-71210) is due to …

Read More »

ALERT
Critical Cisco SD-WAN 0-Day Exploited since 2023

SD-WAN

Cisco has issued urgent updates to fix a critical zero-day (CVE-2026-20127) vulnerability in its Catalyst SD-WAN products. A sophisticated threat actor named UAT-8616 is exploiting this flaw to gain deep access to enterprise networks. An unauthenticated remote attacker can exploit this weakness by sending specific requests to a vulnerable system. …

Read More »

(CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721)
VMware Aria Operations updates address multiple vulnerabilities

VMware Aria Operations

Broadcom published security advisory VMSA-2026-0001 on February 24, 2026, revealing three vulnerabilities in VMware Aria Operations that may enable attackers to run unauthorized commands remotely. VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure have flaws, but patches are now available for all affected …

Read More »

Microsoft admits
Copilot reads ‘confidential emails’ bypassing DLP policies

Copilot

Microsoft has admitted that a coding bug accidentally allowed Copilot Chat to access and summarize confidential emails. Microsoft said that a bug in Microsoft 365 Copilot allowed the AI assistant to access private emails, raising serious privacy issues for companies using the service. Bleeping Computer reports, the flaw bypasses data loss …

Read More »

CISA warns feds to fix Dell flaw within 3 days

Dell flaw

CISA has ordered government agencies to fix a serious Dell flaw within three days, which has been actively exploited since mid-2024. Mandiant and the Google Threat Intelligence Group report that a vulnerability (CVE-2026-22769) involving hardcoded credentials in Dell’s RecoverPoint is being exploited by a suspected Chinese hacking group named UNC6201. …

Read More »