Security news aggregator

Latest coverage for Patch

Stay updated on the latest patch news and insights to secure your systems against vulnerabilities and cyber threats. Keep your info safe with our patch tag.

2699 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Patch is a piece of software designed to update or fix problems with a computer program or its supporting data. In the context of information security, a patch is typically used to repair vulnerabilities that could be exploited by hackers. These vulnerabilities are often discovered in operating systems, applications, or even security software itself. Once identified, software vendors release patches to close these security holes and protect users from potential attacks.

Applying security patches is a critical component of maintaining the integrity and confidentiality of an organization's information. It's a proactive measure to prevent cyber threats such as viruses, malware, and other malicious activities that can compromise systems and data. Patches are commonly distributed through automatic updates, but can also be manually downloaded and installed by users or IT professionals. Regular patch management ensures that software remains secure, functional, and less vulnerable to cyber threats.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 2699 Filtered view

Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases

Google fixed 124 Android flaws, including CVE-2025-48595, an actively exploited privilege escalation bug linked to targeted attacks. Google has released its June 2026 Android security updates, fixing 124 vulnerabilities across the mobile operating system. One flaw, tracked as CVE-2025-48595 (CVSS score of 8.4) stands out from the rest because it is already being exploited in […]

Rapid7 details a critical unauthenticated overflow in HP Poly VoIP phones that can lead to root RCE, with patches available for affected models. Rapid7’s latest disclosure on CVE-2026-0826 should get serious attention from anyone running HP Poly VoIP phones in an enterprise setting. It’s a critical unauthenticated stack-based buffer overflow that can give a remote […]

Threat actors are exploiting a critical FortiClient EMS flaw, tracked as CVE-2026-35616, to deploy malware on unpatched systems. Threat actors are exploiting a critical FortiClient EMS vulnerability, tracked as CVE-2026-35616 (CVSS score of 9.1), that allows remote code execution without authentication. Fortinet released fixes in April after confirming zero-day attacks in the wild and urged […]

A critical vulnerability, tracked as CVE-2026-45659, in Microsoft SharePoint can allow attackers to achieve remote code execution with little effort. Microsoft released security updates to patch a high-severity SharePoint vulnerability, tracked as CVE-2026-45659 (CVSS score of 8.8), that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a […]

Hidden Install Settings Let Malicious MCP Links Execute CodeMicrosoft patched a high-severity flaw in Visual Studio Code after researchers found attackers could hide malicious settings inside MCP server install links, giving them persistent access to developer machines through what appeared to be routine artificial intelligence tool installations.

Loading more headlines...