Patch
Curated coverage and analysis in this editorial area.

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS
A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File
Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

CISA Overhauls Vulnerability Management: 72-Hour Deadline for High-Risk KEVs
The new CISA directive abandons the one-size-fits-all model of BOD 22-01 and introduces four risk-based variables for prioritizing kno…

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities
Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks
The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade
CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows
Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Zoom Patches CVE-2026-53412: Critical Remote Account Takeover on Windows, CVSS 9.8
Zoom has patched a critical vulnerability in its Windows client that allows unauthenticated, zero-interaction account takeover. The fl…

SharePoint: Patch for CVE-2026-55126, an Authenticated XSS Rated CVSS 8.1
Microsoft has fixed an XSS vulnerability in SharePoint's SPFieldMultiLineText class. The CVSS 8.1 score and ease of remote exploitatio…

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files
A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…