Attackers are exploiting a MikroTik RouterOS flaw with no password needed. Here’s exactly how to check whether your router is already compromised and what to do about it.
patch management
-
-
A CVE identifies a vulnerability, nothing more. Here is why treating the number itself as a severity signal leads to the wrong patch order, and what should drive it instead.
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
-
A PaperCut vulnerability chain let attackers bypass login and run code on print servers, and the vendor needed a second emergency patch after the first one was bypassed.
-
CVE-2026-21962 scores a perfect 10 on the CVSS scale and has been under active, automated attack since January. Here’s what it does and how to check if you’re exposed.
-
A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.
-
A critical Keycloak password reset flaw let unauthenticated attackers seize any account, admins included. Here is what happened and what to patch now.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
Two chained Microsoft SharePoint flaws, patched in July and August, let an attacker take over an on-premises server without any credentials at all.
-
Attackers weaponised a VMware vCenter flaw within five days of disclosure. That speed should change how businesses think about critical patching.