F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.
vulnerability management
-
-
The new SharePoint zero-day vulnerability follows a pattern that patching alone won’t fix: a chained attack that steals server keys before the update ever lands.
-
Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.
-
A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.
-
Not sure whether to commission a penetration test or start a bug bounty programme? A practical checklist covering compliance, cost and timing for UK businesses.
-
A newly exploited SharePoint server vulnerability lets low-privilege accounts run code on your server. Here’s how to check exposure and patch it this week.
-
A second maximum-severity flaw in Kemp LoadMaster in two years shows why load balancers need the same patch discipline as public web servers.
-
The Squidbleed vulnerability in Squid Proxy leaks HTTP credentials from heap memory in every default installation. Here is how to check whether you are affected and what to do while …