#patch-tuesday
7 articles
Over the past month, ZCyberNews has tracked 20 articles under the patch-tuesday tag, covering a period from April 12 to May 12, 2026. The most critical vulnerability is CVE-2026-27681, carrying a CVSS score of 9.9, alongside four other high-severity CVEs: CVE-2026-34259, CVE-2026-34260, CVE-2026-34263, and CVE-2026-34659, each rated 9.6. The coverage includes nine critical, seven high, and four medium severity issues, affecting enterprise, enterprise software, manufacturing, technology, and critical-infrastructure sectors globally.
CRITICALAdobe Patches 52 Flaws Across 10 Products, Two Critical in Connect
Adobe's May 2026 patch batch fixes 52 CVEs across 10 products; Adobe Connect gets two critical bugs (CVE-2026-34659, 9.6 CVSS for RCE; CVE-2026-34660, 9.3 CVSS for privilege...
HIGHMicrosoft Patches 120 Flaws in May 2026 Patch Tuesday Update
Microsoft's May 2026 Patch Tuesday fixes 120 vulnerabilities across Windows 11 25H2, 24H2, and 23H2. KB5089549 and KB5087420 include security fixes, Xbox mode, and batch file...
CRITICALMicrosoft Patches 137 Flaws, SSO Plugin Bug Rated Critical
CVE-2026-41103 in Microsoft SSO Plugin for Jira & Confluence allows privilege escalation via flawed authentication.
CRITICALSAP Patches Critical S/4HANA, Commerce Flaws with 9.6 CVSS
SAP released 15 security notes for May 2026, fixing two critical code injection flaws in S/4HANA (CVE-2026-34260) and Commerce (CVE-2026-34263), both rated 9.6 CVSS, and a...
HIGHMicrosoft Patches Windows win32kfull Local Privilege Escalation Vulnerability
Microsoft has patched a local privilege escalation vulnerability (CVE-2026-33104) in the Windows win32kfull driver, which could allow authenticated attackers to gain SYSTEM privileges. The flaw was disclosed by the Zero Day Initiative.
CRITICALSAP Patches Critical SQL Injection Flaw in Business Planning and Consolidation
SAP has patched a critical SQL injection vulnerability (CVE-2026-27681, CVSS 9.9) in its Business Planning and Consolidation and Business Warehouse applications, allowing attackers to execute arbitrary database commands.
HIGHMicrosoft Patches Exploited SharePoint Zero-Day Among 161 Vulnerabilities
Microsoft's April 2025 Patch Tuesday addresses 161 CVEs, including an actively exploited zero-day in SharePoint Server (CVE-2025-27088) and a critical RCE in Windows DNS (CVE-2025-27080).
Stay Updated
Get the latest cybersecurity news delivered to your inbox.