Microsoft’s August 2026 Patch Tuesday Closes 394 Flaws, Including One Zero-Day Already Under Attack
Microsoft's August 2026 security update addresses 394 vulnerabilities spanning Windows, Office, SharePoint, Azure, and developer tools, including three zero-days. One of them, a Windows kernel driver flaw tied...
Zoom Patches ‘Zoomsday’ Flaw That Let Meeting Guests Hijack Devices Without a Single Click
Zoom has fixed four vulnerabilities in its meeting clients, including a high-severity bug dubbed 'Zoomsday' that let any meeting participant execute code on another attendee's device with zero...
New Outlook Flaw Lets Attackers Run Malicious Code Through a Single Booby-Trapped Email Attachment
Microsoft has patched a high-severity remote code execution flaw in Outlook, tracked as CVE-2026-70329, that can be triggered when a victim opens a specially crafted Office file. The...
Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights
A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to...
CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9.6 in Severity
CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active...
New “Pass-the-Passkey” Technique Shows How Windows 11 Logs Undermined Phishing-Resistant MFA
Security researchers at SpecterOps have detailed a family of attacks called Pass-the-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it,...
Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...