VMware fixes: critical auth bypass and VM escapes
Broadcom has published emergency patches for several VMware products. The updates address, among other things, a VMware critical auth bypass and a flaw that enables VM escapes.
Broadcom has published emergency patches for several VMware products. The updates address, among other things, a VMware critical auth bypass and a flaw that enables VM escapes.
Er is een ernstige, actief misbruikte kwetsbaarheid gevonden in Microsoft System Center: CVE-2026-33825 (CVSS 7.8). Installeer de beschikbare beveiligingsupdates zo snel mogelijk.
Er is actief misbruik gemeld van ernstige kwetsbaarheden in Ivanti Endpoint Manager Mobile. Het NCSC beoordeelt de kans op misbruik en schade als hoog en adviseert snel te patchen.
A severe SD-WAN controller vulnerability has been disclosed affecting Cisco Catalyst SD-WAN Controller and Manager. Security updates are available, especially if devices are reachable from public networks.
The NCSC reports multiple critical vulnerabilities in Oracle Fusion Middleware components. Because they can be exploited remotely without authentication, organizations should install Oracle security updates immediately.
A new Rails critical vulnerability (CVE-2026-66066) was patched after reports that unauthenticated attackers could read arbitrary server files. In some setups, that exposure could lead to remote code execution.
The NCSC reports that JFrog has fixed multiple vulnerabilities in Artifactory. Rapid patching is necessary, including fixes for privilege escalation, SSRF, and path traversal.