Veeam, HashiCorp’s Terraform MCP Server and Django all patched critical flaws within 48 hours, including a CVSS 10.0 bug. Here’s what happened and what to check.
patch management
-
-
A critical TeamCity flaw is being actively exploited. Here is a practical, step-by-step checklist for UK businesses to confirm exposure, patch and check for compromise.
-
A WordPress XSS vulnerability patched in version 7.0.3 needed no login to start. Here’s a plain-English explainer and five checks for your own sites.
-
The Cisco FMC vulnerability CVE-2026-20316 scores a modest 5.3 but is under active attack with no workaround. It’s a case study in why CVSS alone can’t drive your triage.
-
Broadcom has patched two 9.8-rated vCenter flaws and a VM escape bug in ESX. Here is what the VMware vCenter vulnerabilities mean for businesses running vSphere.
-
A May 2026 GlobalProtect authentication bypass is still being used by Qilin ransomware affiliates. Here’s how to confirm you’re patched, mitigate if you’re not, and spot signs of prior compromise.
-
F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.
-
A step-by-step guide to Zoom’s critical Windows account takeover vulnerability: which products are affected, whether it’s being exploited, and what to patch first.
-
Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.