A May 2026 GlobalProtect authentication bypass is still being used by Qilin ransomware affiliates. Here’s how to confirm you’re patched, mitigate if you’re not, and spot signs of prior compromise.
patch management
-
-
F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.
-
A step-by-step guide to Zoom’s critical Windows account takeover vulnerability: which products are affected, whether it’s being exploited, and what to patch first.
-
Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.
-
BeyondTrust has fixed two pre-authentication bypass flaws in Remote Support and Privileged Remote Access. Here is a practical checklist for IT teams still running self-hosted appliances.
-
A newly exploited SharePoint server vulnerability lets low-privilege accounts run code on your server. Here’s how to check exposure and patch it this week.
-
A second maximum-severity flaw in Kemp LoadMaster in two years shows why load balancers need the same patch discipline as public web servers.
-
Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Here is what your team needs to check, patch and verify before attackers get there first.