Patch
Curated coverage and analysis in this editorial area.

Microsoft June 2026 Patch Tuesday: 200 Flaws Fixed, 3 Public Zero-Days Addressed
Microsoft’s June 2026 security update addresses approximately 200 vulnerabilities, including three publicly disclosed zero-days: the '…

Gogs Patches Critical CVSS 9.4 Zero-Day; Over 2,300 Servers Exposed
Gogs 0.14.3 addresses a critical argument injection zero-day in the git rebase function. Default configurations allowing open registra…

Emphere Secures $2.1M to Automate Vulnerability Remediation with AI
Seattle-based startup Emphere raises $2.1 million to automate open-source vulnerability remediation as the NVD backlog exceeds 27,000…

CISA Adds Critical Magento Mirasvit RCE to KEV Catalog, Sets 72-Hour Patch Deadline
CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog on June 3, 2026. The flaw is a PHP object injection in…

CISA: SolarWinds Serv-U Vulnerable to Remote Crashes via HTTP Header
CISA confirms active exploitation of CVE-2026-28318 in SolarWinds Serv-U. A single 'Content-Encoding: deflate' header is sufficient to…

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed
CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…

Edge Vulnerability CVE-2026-45492: Origin Validation Error Bypasses Windows VBS
A flaw in Microsoft Edge’s cross-device sign-in mechanism, tracked as CVE-2026-45492, allows attackers to bypass Windows Virtualizatio…

CVE-2026-8936: Docker Desktop VM Panic Triggered via grpcfuse Recursion
A low-privileged container can trigger a VM panic in Docker Desktop through uncontrolled recursion in the grpcfuse module. The vulnera…

CVE-2026-48095: 7-Zip NTFS Handler Heap Overflow
A heap overflow in 7-Zip’s NTFS handler allows for RCE via crafted files. The vulnerability involves signature-based file routing that…