CVE News
Latest CVE news and analysis — 19 articles tagged CVE on The Robotics Media.
- Microsoft patches 421 CVEs in August 2026 Patch Tuesday, including exploited afd.sys zero-day — — Microsoft's August 2026 Patch Tuesday resolves 421 CVEs, including CVE-2026-68820, an actively exploited use-after-free in afd.sys that grants SYSTEM...
- Microsoft Patches CoSnitch, a One-Click Data Theft Flaw in Copilot — — Varonis Threat Labs disclosed CoSnitch, a chain of three Copilot Personal flaws that turn a single crafted link into silent data exfiltration and pers...
- Universal Robots Patches Critical PolyScope Flaw CVE-2026-8153 — — Universal Robots patched CVE-2026-8153 (CVSS 9.8) in PolyScope 5.25.1 after Claroty's Team82 found an unauthenticated RCE flaw in the Dashboard Server...
- CISA Adds Ray CVE-2025-62593 to KEV as Browser Attack Chain Hits Devs — — CISA gave federal agencies until August 20 to patch a critical Ray flaw after Oligo confirmed DNS-rebinding attacks are pushing browser-based RCE onto...
- CISA Adds Langflow, Tomcat and N-central Flaws to KEV — — CISA on August 5 added three actively exploited vulnerabilities to its KEV catalog, including a critical Langflow RCE and an Apache Tomcat encryption...
- N-able Ships Emergency Patch After Attackers Bypass N-central Auth Bypass Fix — — CVE-2026-18577 lets attackers bypass an earlier N-central patch to seize admin access on MSP RMM servers, with Huntress observing live exploitation an...
- Arista VeloCloud Orchestrator Zero-Day CVE-2026-16812 Under Active Attack — — A maximum-severity command-injection flaw in on-prem Arista VeloCloud Orchestrator is being exploited to fully compromise SD-WAN infrastructure, with...
- Rails Ships Emergency Patch For Active Storage RCE Flaw CVE-2026-66066 — — Ruby on Rails ships coordinated 7.2, 8.0 and 8.1 releases fixing a critical Active Storage flaw that lets unauthenticated attackers read arbitrary fil...
- Broadcom Patches Three Critical VMware Flaws, Including vCenter Auth Bypass And ESXi VM Escape — — Broadcom's VMSA-2026-0006 advisory patches five flaws across vCenter, ESXi, Workstation and Fusion. Three are rated critical, including a CVSS 9.8 vCe...
- JetBrains Patches Critical CVE-2026-63077 Unauthenticated RCE In TeamCity — — JetBrains is urging TeamCity On-Premises customers to upgrade after disclosing CVE-2026-63077, an unauthenticated remote code execution flaw with a CV...
- Public GitLab RCE PoC Lets Any User Run Commands As Git Via Oj Bugs — — Security researcher Yuhang Wu published a working proof-of-concept exploit that chains two Ruby Oj parser bugs to execute code as git on unpatched sel...
- GhostLock: 15-Year-Old Linux Kernel Flaw Enables Root And Container Escape — — Nebula Security's AI agent VEGA has disclosed GhostLock (CVE-2026-43499), a 15-year-old use-after-free in Linux futex code that grants local root and...
- Microsoft Patches Record 622 CVEs, SharePoint And AD FS Zero-Days Already Exploited — — Microsoft's July 2026 Patch Tuesday shipped 622 CVEs — the largest release in company history — including two actively exploited zero-days in SharePoi...
- AnyDesk CVE-2026-15682 Zero-Day Lets Local Attackers Crash Remote Desktop Installs — — A zero-day flaw in AnyDesk's Send Support Information feature tracked as CVE-2026-15682 lets local attackers write arbitrary files and crash the remot...
- Palo Alto Networks Patches Critical PAN-OS CVE-2026-0288 in 13-Bug Batch — — Palo Alto Networks has disclosed 13 PAN-OS and Prisma Access vulnerabilities led by CVE-2026-0288, an unauthenticated buffer-overflow chain in the Use...
- SimpleHelp RMM Bug CVE-2026-48558 Lands on CISA KEV as Djinn Stealer Spreads — — A critical OIDC authentication bypass in SimpleHelp remote monitoring servers is being actively exploited to drop Djinn Stealer, prompting CISA to add...
- Attackers Probe Critical Gitea Docker Auth-Bypass Flaw CVE-2026-20896 — — Sysdig detected the first exploitation attempts against CVE-2026-20896, a CVSS 9.8 Gitea Docker flaw that lets any reachable IP impersonate admin user...
- Chrome 151 Ships 382 Security Fixes, Including Actively Exploited V8 Bug — — Google released Chrome 151 with 382 security fixes on July 1, 2026 — a record single-release patch that includes 15 critical bugs and the actively exp...
- Adobe Rushes ColdFusion Fixes for Seven CVSS 10.0 Flaws — — Adobe published emergency bulletin APSB26-68 patching 11 ColdFusion vulnerabilities, including seven with CVSS 10.0 that allow unauthenticated remote...