Print Page | Contact Us | Report Abuse | Sign In | Register
Cyber Security Advisories
The latest MS-ISAC cyber security advisories. Feed provided by Center for Internet Security.

A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code ExecutionOpen in a New Window

A vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway may potentially allow an unauthenticated remote attacker to achieve arbitrary code execution. Successful exploitation of this vulnerability could allow for arbitrary code execution as root, which may lead to the complete compromise of the affected device.

 

A Vulnerability in WordPress Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in WordPress that could allow arbitrary code on the web server. WordPress is a free, open-source content management system (CMS) that allows you to build and manage websites without needing to write code. Successful exploitation allows an unauthenticated attacker to manipulate the page-template resolution logic to execute local PHP files outside the active theme directory, potentially leading to Remote Code Execution (RCE) under specific conditions.

 

A Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication BypassOpen in a New Window

A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, in some deployments up to several thousand devices from a single console. An attacker could exploit this vulnerability by sending a specially crafted HTTP request with a URI-encoded character to the Manager's API, which could allow the request to skip an authentication rule intended to restrict access to a specific endpoint. Successful exploitation of this vulnerability could result in an unauthenticated, remote attacker gaining admin-level access to the affected system's API, and by extension the ability to view or modify the configuration of every SD-WAN device that Manager instance controls. This vulnerability affects the product regardless of device configuration; there is no feature toggle or configuration setting that removes the exposure.

 

A Vulnerability in Apple Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

A vulnerability has been discovered in Apple products that could allow for arbitrary code execution.

  • macOS Sequoia (macOS 15) is an operating system version for Mac computers released by Apple in late 2024.
  • macOS Tahoe (macOS 26) is an operating system version for Mac computers released by Apple in late 2025.
  • iOS is Apple's mobile operating system.
  • IPadOS is Apple's mobile operating system exclusively for its iPad line of tablet computers.

Successful exploitation of the vulnerability could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Remote Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway, the most severe of which could allow for remote code execution. NetScaler ADC is a networking product that functions as an Application Delivery Controller (ADC), optimizing, securing, and ensuring reliable availability of applications for businesses. NetScaler Gateway is a secure remote access solution that provides users with single sign-on (SSO) access to applications and resources from any device. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution of commands on the system.

 

Multiple Vulnerabilities in ServiceNow's AI Platform Could Allow for Unauthorized AccessOpen in a New Window

Multiple vulnerabilities have been discovered in ServiceNow's AI Platform, the most severe of which could allow for unauthorized access. The ServiceNow AI Platform is a unified, cloud-based foundation that integrates artificial intelligence, data, and workflow automation to execute business operations across entire enterprises. Successful exploitation of the most severe of these vulnerabilities could allow for unauthorized access.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in IBM Concert Software Could Allow for Remote Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in IBM Concert Software, the most severe of which could allow for remote code execution. IBM Concert is an agentic IT operations (IT Ops) and resilience platform designed to unify fragmented data, context, and actions across an enterprise's hybrid cloud and IT environments. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution with the privileges of the affected application.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.


  • Adobe Bridge is a creative asset manager that lets you preview, organize, edit, and publish multiple creative assets quickly and easily.
  • Adobe Connect is a secure, highly customizable web conferencing and virtual training platform used for webinars, online meetings, and e-learning.
  • Adobe InDesign is a professional page layout and desktop publishing software used for designing and publishing content for both print and digital media.
  • Adobe Premiere Pro is a subscription-based timeline video editing software for film, TV, and web.
  • Adobe Substance 3D is a suite of tools for creating 3D content, including modeling, texturing, and rendering.
  • Adobe Experience Manager (AEM) is a comprehensive content management solution for building websites, mobile apps, and forms.
  • Content Authenticity SDK contains Rust and JavaScript libraries, enabling web pages to read, validate, create, and sign manifest data, and embed it in supported asset files.


Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in F5 BIG-IP Access Policy Manager (APM) that could allow for remote code execution. BIG-IP APM is a widely deployed network access and identity management solution used across government agencies, financial institutions, healthcare organizations, and large enterprises to control application and network access. Successful exploitation of this vulnerability could result in an attacker gaining full control of the affected system. Depending on the privileges associated with the account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Accounts configured to have fewer user rights on the system could be less impacted than those that operate with administrative user rights.

 

Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Cisco Secure Email products, the most severe of which could allow for remote code execution.

  • Cisco Secure Email Gateway (formerly ESA) is an email security appliance that filters spam, malware, and other threats at the mail gateway.
  • Cisco Secure Email and Web Manager (formerly SMA) is a centralized management and reporting platform for Cisco Secure Email Gateway and Secure Web Appliance deployments. 

Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution as root, which may lead to the complete compromise of the affected device.

 

Multiple Vulnerabilities in Mikrotik Routers Could Allow for Admin HijackingOpen in a New Window

Multiple vulnerabilities have been discovered in MikroTik Routers, the most severe of which could allow for admin hijacking. MikroTik routers are network devices that use the RouterOS operating system to provide advanced routing, firewall, wireless, VPN, bandwidth management, and network security features for homes, businesses, and internet service providers. Successful exploitation of the most severe of these vulnerabilities could allow an attacker to take full control of a device without authentication.

 

A Vulnerability in GitLab Could Allow for Disclosure of Sensitive DataOpen in a New Window

A vulnerability has been discovered in GitLab, which could allow disclosure of sensitive data. GitLab GitLab is a DevOps platform that provides source code management, CI/CD pipelines, issue tracking, and collaboration tools in a single application for software development teams. Successful exploitation of this vulnerability could allow for path traversal, leading to disclosure of potentially sensitive information such SSH keys, database credentials, deploy tokens. Depending on the sensitive information retrieved via this technique, the attacker may gain further access to the appliance or systems.

 

Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the system.


  • Ivanti Endpoint Manager Mobile (Ivanti EPMM) is a mobile management software engine that enables mobile device, application, and content management.
  • Ivanti Neurons is a cloud-based automation platform that unifies IT operations and security management into a single system of record.
  • Ivanti Sentry is an in-line gateway that manages, encrypts, and secures traffic between the mobile device and back-end enterprise systems.


Depending on the privileges associated with the system, an attacker could then install programs; view, change, or delete data. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via communication protocols like RFC (Remote Function Call) and HTTP from the client to the server. Onapsis explained that, because EPP processing is shared kernel code, the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another. The bug is remotely exploitable without authentication and exists by default in a range of SAP components. Successful exploitation of this vulnerability may allow a remote attacker to run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to a total compromise of the underlying SAP business data and processes.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution.
  • Adobe ColdFusion is a commercial rapid web application development platform used to build, deploy, and scale dynamic enterprise web and mobile applications.
  • Adobe Photoshop is a professional raster graphics editor used to create, edit, and manipulate digital images.
  • Adobe Illustrator is an industry-standard vector graphics editor and design software used to create infinitely scalable artwork, logos, icons, typography, and complex illustrations.
  • Adobe Animate is computer animation and multimedia authoring software.
  • Adobe Commerce is a flexible, enterprise-level e-commerce platform built on top of Magento technology that helps businesses create and manage online stores.
  • Adobe Acrobat Reader is a free software application used to view, print, sign, share, and annotate PDF (Portable Document Format) files.
  • Adobe Campaign Classic is an enterprise marketing automation and cross-channel campaign management platform used to design, execute, and orchestrate customer journeys across online and offline channels.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Critical Patches Issued for Microsoft Products, September 8, 2026Open in a New Window

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Dell Secure Connect Gateway, the most severe of which could allow for arbitrary code execution. Dell Secure Connect Gateway is an enterprise monitoring and connection software for Dell infrastructure. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code ExecutionOpen in a New Window

Multiple Vulnerabilities have been discovered in SonicWall SMA1000 Series Appliances, which when chained together could allow for remote code execution, potentially leading to full system compromise. SonicWall Secure Mobile Access (SMA) 1000 Series appliances are enterprise-grade secure access and SSL VPN gateways. Successful exploitation of the vulnerabilities could allow for remote code execution.

 

Multiple Vulnerabilities in PaperCut Products Could Allow for Remote Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in PaperCut products, the most severe of which could allow for remote code execution. PaperCut products are software tools used to track, control, secure, and manage printing, copying, and scanning across office and school printer networks. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution in the context of the affected service account. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Oracle products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in SonicWall Global Management System (GMS), the most severe of which could allow for remote code execution. The SonicWall Global Management System (GMS) is a centralized management interface used to deploy and centrally manage SonicWall firewall, wireless, email security, secure remote access and Dell X-Series solutions from a single console. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution in the context of the affected service account. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in Zoom Clients Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and install malware.

 

Critical Patches Issued for Microsoft Products, August 11, 2026Open in a New Window

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe ColdFusion is a commercial rapid web application development platform and application server.
  • Adobe Commerce is an enterprise-level e-commerce platform built on the proven technology of Magento.
  • Adobe Lightroom is a popular cloud-based image organization and photo-editing software developed by Adobe.
  • Adobe Content Credentials SDK is a software tool kit that lets developers add secure, tamper-evident provenance metadata to digital files.
  • Adobe Campaign Classic is an enterprise-grade marketing automation and campaign management platform.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.


 

Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication BypassOpen in a New Window

Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain access. This does require the SAML 2.0 authentication method to be enabled. 

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem.
  • Adobe Format Plugins are software add-ons used by Adobe applications to handle file formats, convert data types, and process specific file structures safely.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in VeloCloud Orchestrator (VCO) On-Prem that could allow for remote code execution. VeloCloud Orchestrator is a centralized management platform used to configure, provision, monitor, and troubleshoot software-defined wide area networks (SD-WAN) and SASE components across enterprise edges and gateways. Successful exploitation of this vulnerability may allow a remote attacker to access privileged internal functionality, execute commands, and impact the VCO host. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability Chain in WordPress Core Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe After Effects is a digital visual effects and motion graphics application used for creating cinematic movie titles, transitions, and complex animation sequences.
  • Adobe Animate is a professional vector animation software used to design interactive animations and multimedia content for games, television, and websites.
  • Adobe Audition is a professional audio workstation and editing toolset designed for mixing, restoring, and precisely engineering audio content for film, broadcast, and podcasts.
  • Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem.
  • Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications.
  • Adobe Commerce is an enterprise-level e-commerce platform that allows businesses to build, manage, and scale secure online storefronts for both B2B and B2C audiences.
  • Adobe Content Credentials SDK (Software Development Kit) is a developer toolset that allows applications to attach secure, tamper-evident metadata to digital content like images, video, and audio.
  • Adobe Creative Cloud Desktop Application is a central hub that allows users to download, update, and manage their Adobe software, manage cloud storage, and access shared creative assets and fonts.
  • Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines a Content Management System (CMS) and a Digital Asset Management (DAM) system.
  • Adobe Illustrator is the industry-standard vector graphics software used by designers to create scalable logos, icons, typography, and complex illustrations.
  • Adobe Media Encoder is a robust background processing application used to automate the ingest, transcoding, proxy creation, and output of video and audio files across various formats and devices.
  • Adobe Premiere Pro is a timeline-based, industry-leading video editing software program designed for professional filmmakers, broadcasters, and content creators.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Critical Patches Issued for Microsoft Products, July 14, 2026Open in a New Window

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

  • Adobe Campaign Classic is an enterprise-grade marketing automation platform that helps organizations design, automate, and track complex, personalized cross-channel marketing campaigns.
  • Adobe ColdFusion is a commercial rapid web application development platform used to build and deploy dynamic web and mobile applications.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. 


  • Mozilla Firefox is a web browser used to access the Internet.
  • Thunderbird is a free, open-source email, calendar, and chat application.


Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in PAN-OS Could Allow for Authentication BypassOpen in a New Window

A vulnerability has been discovered in the GlobalProtect portal and gateway of PAN-OS which could allow for authentication bypass. The PAN-OS GlobalProtect Portal acts as the central control plane for Palo Alto Networks VPN infrastructure. Successful exploitation of the vulnerability allows the attacker to bypass security restrictions and establish an unauthorized VPN connection.

 

Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. 

  • Mozilla Firefox is a web browser used to access the Internet.
  • Mozilla Firefox ESR is a version of the web browser intended to be deployed in large organizations.
  • Thunderbird is a free, open-source email, calendar, and chat application.

Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in SimpleHelp Could Allow for Authentication BypassOpen in a New Window

A vulnerability has been discovered in SimpleHelp, which could allow for authentication bypass. SimpleHelp is a self-hosted remote support, access, and monitoring software used by IT teams, managed service providers (MSPs), and helpdesks. It enables technicians to securely connect to, troubleshoot, and manage client computers and servers. Successful exploitation of the vulnerability could allow unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, install programs; or view, change, or delete data.

 

A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code ExecutionOpen in a New Window

A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow an attacker with network access via HTTP to completely takeover the software. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions, including HR, payroll, finance, supply chain, and campus operations. Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.

 

Critical Patches Issued for Microsoft Products, June 9, 2026Open in a New Window

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Check Point Products Could Allow for Authentication BypassOpen in a New Window

Multiple vulnerabilities have been discovered in Check Point products the most severe of which could allow for authentication bypass.

  • Check Point VPN Remote Access provides remote and mobile employees with secure, encrypted connections to corporate networks.
  • Check Point Mobile Access enables secure remote access to enterprise applications through client-based or clientless solutions.
  • Check Point Spark Firewall is an enterprise-grade security gateway providing all-in-one threat prevention.

Successful exploitation of the most severe of these vulnerabilities could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access to network resources. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code ExecutionOpen in a New Window

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

 

A Vulnerability in Cisco Products Could Allow for Server-Side Request ForgeryOpen in a New Window

A vulnerability has been discovered in Cisco products that could allow for Server-Side Request Forgery. Cisco Unified Communications Manager (Unified CM) / Cisco Unified Communications Manager Session Management Edition (Unified CM SME) is Cisco’s central, software-based call control and session management platform for enterprise communication.

Successful exploitation of this vulnerability could allow for Server-Side Request Forgery, where an attacker could write files to the underlying operating system that could be used later to elevate to root. Depending on the location the attacker is able to write files to, they may be able to execute commands or remotely access the affected device.