Skip to content

Topic

Vulnerability Management

Practices and infrastructure for discovering, prioritizing, disseminating and remediating software vulnerabilities.

Current stories

build1 publisher

Turning off mod_verto retires five of FreeSWITCH's nine June CVEs

Five of nine FreeSWITCH CVEs from June 2026 sit in mod_verto, including an unauthenticated 9.8 heap overflow that unloading the module closes without a patch. The second critical, a 9.1 in the Event Socket Library, stays loaded and reaches any binary linked against libesl.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives30
Confidence55
security5 publishers

Microsoft's 2026 defense report says cross-system intrusions become clearer when signals are joined

Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.

Perspective Coverage

5 publishers
Builder
Builder 23%
Operator
Operator 63%
Investor
Investor 14%

Reality

Evidence55
Adoption
Insufficient
Hype gap−15
Incentives60
Confidence60
build1 publisher

Cisco email gateway flaw runs attacker SQL as root the moment it parses a message

CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
security4 publishers

Dream Job now ships a kernel exploit: Lazarus pairs recruiter lures with a fresh AFD zero-day

Check Point says the Operation Dream Job chain now escalates through CVE-2026-68820 to install FudModule v3.1. CISA has told federal agencies to patch by August 25.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence72
security3 publishers

NIST concedes manual NVD enrichment no longer scales, and gives 62 days to argue about the fix

A Federal Register RFI calls periodic scanning, static prioritization and manual remediation increasingly inadequate. Comments on redesigning the feed close October 13.

Perspective Coverage

3 publishers
Builder
Builder 35%
Operator
Operator 55%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60

Earlier coverage

  1. CISA's KEV clock now runs on BOD 26-04, and your patch SLA cites the wrong directive

    Security · August 19, 2026 · 2 publishers

  2. Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

    Security · August 20, 2026 · 4 publishers

  3. NetScaler auth bypass at 9.3: the box is the perimeter, so patch it this week

    Security · August 20, 2026 · 5 publishers

  4. CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

    Security · August 29, 2026 · 4 publishers

  5. CISA ties federal patch deadlines to four yes-or-no questions about each CVE

    Security · September 6, 2026 · 2 publishers

  6. CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later

    Security · September 10, 2026 · 2 publishers

  7. Patchable VPN flaw exposed 246,000 personnel records on Japan's shared government platform

    Security · September 15, 2026 · 3 publishers

  8. Certification rules slow election-system patching, CISA's 2026 security plan says

    Security · September 25, 2026 · 2 publishers

  9. Check Point patches unauthenticated root code execution in Security Management and Log Server

    Security · September 18, 2026 · 4 publishers

  10. SolarWinds Observability Self-Hosted 2026.2.3 closes two pre-auth RCEs with different preconditions

    Build · September 25, 2026 · 1 publisher

  11. CJIS v6.1 doubles the key strength required for criminal justice data outside secure locations

    Security · September 21, 2026 · 2 publishers

  12. Attackers are running code on BIG-IP APM boxes configured as OAuth authorization servers

    Security · September 23, 2026 · 6 publishers

  13. FedRAMP's December 7 rules shrink the worst-case remediation window to 12 hours

    Security · September 24, 2026 · 1 publisher

  14. The UK Civil Service is replacing cyber mandates with services departments choose to use

    Security · September 24, 2026 · 1 publisher

  15. CISA orders agencies to fix four exploited edge-network flaws by September 25

    Security · September 23, 2026 · 2 publishers

  16. An agent now picks the packages the person prompting it will never see

    Build · September 23, 2026 · 1 publisher

  17. A banner-grabbing scanner flags patched OpenSSL 3.0.2 on RHEL 9 as potentially vulnerable

    Build · September 22, 2026 · 1 publisher

  18. One unauthenticated request to LiteLLM's admin endpoint dumps every provider key the proxy routes

    Build · September 21, 2026 · 1 publisher

  19. CISA updates KEV catalog page to reference new directive BOD 26-04

    Security · September 20, 2026 · 1 publisher

  20. Vendor backporting leaves the old version number that scanners flag as vulnerable

    Build · September 20, 2026 · 1 publisher

  21. A record 1,449-patch Oracle update turns AI-assisted finding into a change-window problem

    Build · September 19, 2026 · 1 publisher

  22. N-able's fourth hotfix is the one that closes the N-central code injection

    Build · September 19, 2026 · 1 publisher

  23. ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

    Build · September 19, 2026 · 1 publisher

  24. GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0

    Build · September 19, 2026 · 1 publisher

  25. Operators rebuilding CISA's post-CVSS patch sort must merge KEV with Vulnrichment themselves

    Security · September 18, 2026 · 1 publisher

  26. Buildpacks move the base image choice out of every application repository

    Build · September 18, 2026 · 1 publisher

  27. Gremlin reports clearing nine times as many vulnerabilities with the same staff

    Security · September 17, 2026 · 1 publisher

  28. Claude Code turned a published Drupal patch into a working exploit in 51 minutes

    Security · September 16, 2026 · 1 publisher

  29. Deferring iOS 27 leaves about 56 of its 126 fixes out of the 26.7 build

    Security · September 16, 2026 · 2 publishers

  30. Hackuity raises $19M to help security teams prioritize which vulnerabilities to fix first

    Invest · September 16, 2026 · 1 publisher

  31. CISA ties 40% of 2024's exploited flaws to a handful of long-known weakness classes

    Security · September 15, 2026 · 1 publisher

  32. ENISA puts weaponisation of a disclosed vulnerability at 15 minutes

    Security · September 14, 2026 · 1 publisher

  33. CISA mirrors the KEV catalog on GitHub with a public commit history

    Security · September 12, 2026 · 1 publisher

  34. CISA marks which KEV vulnerabilities ransomware crews are known to use

    Security · September 12, 2026 · 1 publisher

  35. IP Services' CEO would audit a security program by asking when it last restored from backup

    Leadership · September 10, 2026 · 1 publisher

  36. Exploitation of software flaws tops Verizon's 2026 intrusion list, up 31% year over year

    Security · September 10, 2026 · 1 publisher

  37. Microsoft's record 964-CVE Patch Tuesday includes two exploited zero-days

    Security · September 8, 2026 · 1 publisher

  38. Google patches a V8 type confusion already being exploited against Chrome users

    Security · September 4, 2026 · 9 publishers

  39. Wiz research: base images account for 39 percent of critical container CVE findings; hardened images cut CVEs by 94 percent

    Security · September 4, 2026 · 1 publisher

  40. Check Point moves OpenAI models into the step that decides what gets patched

    Security · September 4, 2026 · 1 publisher