#patch-guidance
5 articles

CISA Adds CVE-2025-39964 Linux Kernel Flaw to KEV
CVE-2025-39964, a race condition in the Linux kernel's AF_ALG socket code, is now in CISA's KEV catalog. Federal agencies must remediate by September 21, 2026.
CRITICALCVE-2026-60004 Gitea RCE Exploited in the Wild, CISA Warns
CVE-2026-60004, a 9.8-CVSS Gitea RCE, is under active attack per CISA. Attackers with repo write access can run shell commands. Patch now.
MEDIUMCVE-2026-9082: Drupal Core SQL Injection Bug Added to CISA KEV
CISA added CVE-2026-9082 (CVSS 6.5) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation against all supported Drupal Core versions.
CRITICALCVE-2026-8959: Firefox Sandbox Escape via Win32 Boundary Flaw
CVE-2026-8959 (CVSS 9.6) allows sandbox escape through incorrect boundary conditions in Firefox's Widget:Win32 component. Fixed in Firefox 151, ESR 140.11, and Thunderbird 151.
CRITICALCVE-2026-7301: SGLang Scheduler RCE via Pickle Deserialization
CVE-2026-7301 (CVSS 9.8) lets attackers execute arbitrary code on SGLang servers by sending malicious pickle payloads to the scheduler's ROUTER socket, which binds to 0.0.0.0 by...
Stay Updated
Get the latest cybersecurity news delivered to your inbox.