A shrinking red number on a scanner dashboard is not vulnerability management. Here is what the process actually requires, and NCSC’s own patch deadlines.
vulnerability management
-
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
A researcher-recovered toolkit shows how one operator compromised over 14,500 Dahua cameras in five weeks using credential attacks, a decade-old auth bypass, and abuse of the vendor’s own cloud relay.
-
Two chained Microsoft SharePoint flaws, patched in July and August, let an attacker take over an on-premises server without any credentials at all.
-
Veeam, HashiCorp’s Terraform MCP Server and Django all patched critical flaws within 48 hours, including a CVSS 10.0 bug. Here’s what happened and what to check.
-
Cl0p-linked attackers are exploiting an unauthenticated flaw in PTC Windchill and FlexPLM. Here’s a practical checklist for finding out if you’re exposed.
-
The Cisco FMC vulnerability CVE-2026-20316 scores a modest 5.3 but is under active attack with no workaround. It’s a case study in why CVSS alone can’t drive your triage.
-
Broadcom has patched two 9.8-rated vCenter flaws and a VM escape bug in ESX. Here is what the VMware vCenter vulnerabilities mean for businesses running vSphere.
-
A step-by-step check for teams running Adobe Campaign Classic on-premise: confirm your build, check exposure, and patch a flaw that needs no login and no clicks.
-
F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.