Security news, decoded.
What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.
Ivanti: Max severity Sentry flaw allows code execution as root
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.
Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10
Ivanti has published urgent fixes for its gateway appliances after researchers and watchTowr Labs disclosed a publicly available proof of concept for an Ivanti Sentry remote code execution issue. The affected component is associated with CVE-2026-10520 (CVSS 10), and a related authentication/privilege bypass is tracked as CVE-2026-10523 (CVSS 9.9), which can enable creation of administrative accounts and full administrative access. Because these systems sit at the edge of corporate traffic, unpatched deployments face a heightened risk of full administrative compromise; organizations should review logs and upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.
OpenSSL Security Patches Fix Remote Code Execution Risk
OpenSSL has released emergency security updates to fix multiple memory-safety flaws in its certificate and QUIC-related code paths, including a use-after-free that can be triggered remotely and lead to Remote Code Execution via CVE-2026-45447. The release also covers additional security issues such as input-validation weaknesses (CVE-2026-34182), nonce handling problems in AES-OCB one-shot operations (CVE-2026-45445), and denial-of-service and crash conditions in the QUIC stack (CVE-2026-34183, CVE-2026-42764, CVE-2026-42765) plus an OCSP stapling double-free hazard (CVE-2026-35188). OpenSSL users are urged to upgrade promptly—e.g., from version 4.0 to version 4.0.1, and from 1.1.1 to 1.1.1zh—because unauthenticated attackers may be able to exploit these problems over the network.
CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws
The US CISA has updated its Known Exploited Vulnerabilities catalog/active exploit list by adding three newly identified, in-the-wild flaws. Affected products include Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), and Google Chromium (CVE-2026-11645), spanning command-injection, tunneling/decapsulation weaknesses, and memory-safety issues that can lead to remote code execution. Because attackers are already targeting these weaknesses, organizations should prioritize patching and remediation immediately.
Microsoft Patch Tuesday Fixes Address Critical Zero-Day Flaws
High-Severity Vulnerabilities Addressed in Endpoint Manager Mobile
Critical Rclone Command Execution Bug Threatens Cloud Environments
Critical Veeam Backup Vulnerability Exposed
Critical FortiSandbox Flaw Requires Immediate Patching
Critical TinyMCE Cross Site Scripting Flaws Threaten Millions of Applications
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
MBS Universal Gateway Flaws Threaten Building Automation Networks
MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6005 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6007 immediately to reduce the likelihood of compromise.