Announcements

Oracle Security Patch Updates July 2023

Oracle released its critical patch updates for July 2023, containing (508) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update includes security updates addressing numerous vulnerabilities that could potentially be exploited remotely without authentication. The affected product […]

Oracle Security Patch Updates July 2023 Read More »

Citrix Security Updates – 19 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix ADC, and Citrix Gateway. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, perform cross-site scripting attacks, or gain elevated privileges on the affected systems. The addressed vulnerabilities: 1. Citrix ADC, Citrix Gateway Unauthenticated Remote Code Execution (CVE- 2023-3519):

Citrix Security Updates – 19 July 2023 Read More »

Adobe ColdFusion Security Updates – 18 July 2023

Adobe has released security updates to fix multiple vulnerabilities in Adobe ColdFusion. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system via the deserialization of untrusted data or bypass security restrictions by persuading the victim to open a specially crafted file. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion

Adobe ColdFusion Security Updates – 18 July 2023 Read More »

SonicWall Security Updates – 13 July 2023

SonicWall has released security updates to fix multiple vulnerabilities affecting multiple SonicWall products. The addressed vulnerabilities could allow the attacker to bypass authentication, directory traversal, or disclose information on the affected systems. Sample of the addressed vulnerabilities: 1. Password Hash Read via Web Service (CVE-2023-34134): CVSS: 9.8 Attack Vector: Network Attack Complexity: High Privileges Required:

SonicWall Security Updates – 13 July 2023 Read More »

Citrix Security Updates – 12 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix Secure Access Client. The addressed vulnerabilities could allow the attacker to execute arbitrary code or gain elevated privileges on the affected systems. The addressed vulnerabilities: 1. Citrix Secure Access Client for Ubuntu Code Execution (CVE-2023-24492): CVSS: 9.6 Attack Vector: Network Attack Complexity: Low Privileges

Citrix Security Updates – 12 July 2023 Read More »

Fortinet Security Updates – 12 July 2023

Fortinet has released security updates to fix several vulnerabilities in multiple Fortinet products. The addressed vulnerabilities could allow the attacker to overflow a buffer, execute arbitrary code, directory traversal, obtain sensitive information, and gain access to the affected products by sending specially crafted requests. Sample of the addressed vulnerabilities: Fortinet FortiOS and Fortinet FortiProxy Buffer

Fortinet Security Updates – 12 July 2023 Read More »

SAP July 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (2) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Business Client, SAP ECC and SAP S/4HANA (IS-OIL), SAP NetWeaver, SAP Web Dispatcher, SAP UI5

SAP July 2023 Security Patch Day Read More »

MOVEit Transfer Security Update – 08 July 2023

MOVEit Transfer has released a security update to address multiple vulnerabilities in multiple versions of Progress MOVEit Transfer. The addressed vulnerabilities could allow the remote attacker to cause a denial of service, or SQL injection attacks to view, add, modify, or delete information in the back-end database on the affected system. Sample of the addressed

MOVEit Transfer Security Update – 08 July 2023 Read More »

Fortinet Security Updates – 23 June 2023

Fortinet has released security updates to fix two vulnerabilities in FortiNAC affecting multiple versions. The addressed critical vulnerability could allow the remote attacker to execute unauthorized code or commands via specifically crafted requests to the TCP/1050 service. Sample of the addressed vulnerabilities: FortiNAC – Java Untrusted Object Deserialization RCE (CVE-2023-33299): CVSS: 9.6 Attack Vector: Network

Fortinet Security Updates – 23 June 2023 Read More »

MOVEit Transfer Security Update – 20 June 2023

MOVEit Transfer has released a security update to address a critical vulnerability. The addressed vulnerability could allow the remote attacker to submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content. The addressed vulnerability: Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-35708): CVSS: 9.8 Attack

MOVEit Transfer Security Update – 20 June 2023 Read More »

Citrix Security Updates – 14 June 2023

Citrix has released security updates to address several vulnerabilities in CVAD, Citrix DaaS, and ShareFile StorageZones Controller. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, and obtain administrative access by sending a specially crafted request to the affected system. The addressed vulnerabilities: 1. ShareFile StorageZones Controller Vulnerability (CVE-2023-24489): CVSS: 9.1 Attack

Citrix Security Updates – 14 June 2023 Read More »

Fortinet Security Update – 12 June 2023

Fortinet has released a security update to fix a critical SSL-VPN RCE vulnerability in multiple FortiOS firmware versions. The addressed vulnerability could allow the attacker to execute arbitrary code, and gain access by sending a specially crafted request to the affected products. The addressed vulnerability: Fortinet FortiGate and FortiOS Code Execution (CVE-2023-27997): CVSS: 9.8 Attack

Fortinet Security Update – 12 June 2023 Read More »

Cisco Security Updates – 08 June 2023

Cisco released security updates to address several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain access, escalate privileges, cause a denial of service, or perform cross-site scripting on the affected products. Sample of the addressed vulnerabilities: 1. Cisco Expressway Series and Cisco TelePresence VCS Privilege Escalation

Cisco Security Updates – 08 June 2023 Read More »

VMware Security Update – 07 June 2023

VMware has released a security update to fix multiple vulnerabilities across Aria Operations for Networks (Formerly vRealize Network Insight). The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Aria Operations for Networks Command Injection (CVE-2023-20887): CVSS:

VMware Security Update – 07 June 2023 Read More »

MOVEit Transfer Security Update – 04 June 2023

MOVEit Transfer has released a security update to address a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to gain unauthorized access to the application’s database and execute arbitrary commands, disclose information, and alter/delete database elements. the addressed vulnerability: Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-34362): CVSS: 9.8 Attack Vector: Network Attack Complexity:

MOVEit Transfer Security Update – 04 June 2023 Read More »

Barracuda Security Update – 31 May 2023

Barracuda has released a security update to address a zero-day vulnerability across Email Security Gateway (ESG) appliances versions 5.1.3.001-9.2.0.006. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system with the privileges of the Email Security Gateway product by attaching a specially crafted TAR archive file in the email and gain

Barracuda Security Update – 31 May 2023 Read More »