Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAdobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has released security patches addressing multiple critical vulnerabilities across ColdFusion, Commerce, and Campaign Classic products. The most severe flaw, CVE-2026-48362 in ColdFusion, carries a maximum CVSS score of 10.0 and involves operating system command injection that could enable arbitrary code execution and privilege escalation.
AISAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has issued critical security patches for a maximum-severity vulnerability (CVE-2026-58231) in SAP Commerce Cloud's Data Hub Adapter that could allow unauthenticated attackers to execute arbitrary code. The flaw, rated 10.0 on the CVSS scale, stems from insufficient authorization checks and input validation. Organizations using SAP Commerce Cloud should prioritize immediate patching to mitigate
AIMicrosoft Plugs Nearly 400 Security Holes
Microsoft released patches for 398 security vulnerabilities in August 2024, including one actively exploited zero-day flaw and two publicly disclosed vulnerabilities. The patch volume surge is attributed to AI-assisted vulnerability discovery, though research shows AI-generated patches fail to properly fix flaws more than half the time. Security experts recommend organizations maintain measured pa
AIMicrosoft's Patch Tuesday Deluge Continues With August Updates
Microsoft released its August Patch Tuesday updates, continuing a trend of high-volume security patches. Security experts emphasize that organizations should focus on prioritizing critical vulnerabilities rather than being overwhelmed by the sheer number of CVEs addressed in the update cycle.
AIThe Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
Organizations need to shift from traditional CVSS-based vulnerability patching approaches to a strategic 'choke-point patching' methodology that focuses on breaking attack chains leading to critical assets. This approach prioritizes vulnerabilities based on their position in potential attack paths rather than severity scores alone, enabling more effective resource allocation and risk reduction.
AINew WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has patched a critical pre-authentication reflected XSS vulnerability (CVE-2026-64638) affecting all versions of the CMS. The high-severity flaw, with a CVSS score of 8.9, requires no attacker privileges and can potentially be chained to achieve PHP code execution on the server, making immediate patching essential for all WordPress installations.
AICISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
CISA has added a high-severity vulnerability (CVE-2026-18577) affecting N-able N-central to its Known Exploited Vulnerabilities catalog after confirmed active exploitation. The flaw, with a CVSS score of 8.2, represents an incomplete patch for a previous vulnerability (CVE-2026-18556), leading to customer compromises in the wild.
AIThree Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google fixed an unprecedented 1,442 security vulnerabilities across three recent Chrome releases (versions 149, 150, and 151), with versions 149 and 150 alone addressing more flaws than the previous 23 updates combined. Chrome 151, released Wednesday, patched 370 additional vulnerabilities, with 349 identified internally by Google. This represents a significant escalation in both vulnerability dis
AICritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains has disclosed a critical security vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises that enables unauthenticated attackers to execute arbitrary operating system commands. The flaw affects all on-premise versions and has been patched in versions 2025.11.7 and 2026.1.3, while cloud instances are already secured. Organizations using on-premise TeamCity deployments should prio
AIAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Threat intelligence firm Defused Cyber reports active exploitation of three security vulnerabilities in Fortinet's FortiSandbox product, including CVE-2026-39813 (CVSS 9.1), a critical path traversal flaw in the JRPC API. The exploitation activity has been observed within the past 24 hours, with one vulnerability reportedly patched just last week, indicating attackers are moving quickly to exploit
AIMax-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
A maximum-severity vulnerability in Ivanti systems was exploited within 24 hours of public disclosure, indicating threat actors had pre-positioned reconnaissance of Ivanti infrastructure. The rapid exploitation suggests attackers conducted advance mapping of target environments and were prepared to act immediately upon exploit availability.
AICISA Rewrites Federal Patching Requirements for AI Threat Era
CISA has issued updated federal patching requirements that mandate agencies fix critical vulnerabilities within three days, while allowing extended timelines for less severe issues. The directive reflects an adaptation to the evolving threat landscape shaped by AI-enabled attacks and automated exploitation techniques.
AIMicrosoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft released patches for a record-breaking 206 security vulnerabilities in its software portfolio, including three publicly disclosed zero-day flaws. The update addresses 39 Critical and 167 Important severity vulnerabilities, spanning multiple attack vectors including remote code execution, privilege escalation, and information disclosure.
AIBlame AI: Patch Tuesday Hits Record 206 CVEs
Microsoft's latest Patch Tuesday released a record-breaking 206 CVEs, signaling a new era where AI-driven vulnerability discovery is dramatically increasing the volume of security patches. This trend suggests that enterprise IT teams should prepare for significantly larger and more frequent patch cycles as AI tools accelerate the identification of software vulnerabilities at unprecedented scale.
Check Point VPN and Google Chrome Vulnerabilities Under Active Exploitation
Check Point has disclosed a critical authentication bypass vulnerability (CVE-2026-50751, CVSS 9.3) in its VPN products that has been actively exploited since May 7, 2026, with attacks linked to Qilin ransomware affiliates. The flaw affects deployments using the deprecated IKEv1 protocol, allowing unauthenticated attackers to establish VPN connections without valid credentials. Separately, Google
AIRussian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Russian threat actors are actively exploiting CVE-2025-8088, a WinRAR vulnerability patched in July, through two distinct campaigns targeting Ukrainian military and government organizations. The attacks focus on data exfiltration and cyberespionage operations, demonstrating continued targeting of critical Ukrainian infrastructure through known software vulnerabilities.
AIHackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
A critical remote code execution vulnerability (CVE-2026-3300, CVSS 9.8) in the Everest Forms Pro WordPress plugin is being actively exploited by threat actors to compromise websites. The flaw affects all versions up to 1.9.12 of the plugin, which has approximately 4,000 active installations, allowing attackers to execute arbitrary code and achieve complete site takeover.
AIAI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
AI-driven exploitation is dramatically accelerating vulnerability weaponization timelines, reducing the window between disclosure and active exploitation from days to mere hours. This compression of exploitation timelines is fundamentally challenging traditional vulnerability management approaches that rely on prioritization and scheduled patching cycles. Organizations must adapt their security st
