21 advisories are included in the semi-annual Cisco Adaptive Security Appliance Software (ASA), Firepower Management Center (FMC) Software, and Firepower Threat Defense (FTD) Software Security Advisory bundled publication
Updates address two vulnerabilities that have been added to the Known Exploited Vulnerabilities Catalog
CVE-2024-26009 could allow an unauthenticated attacker to perform full device compromise
Scheduled updates for Microsoft products, including security updates for 111 vulnerabilities, of which one has been reported as publicly disclosed
Exploitation of vulnerability in RARLab's WinRAR could allow an attacker to execute arbitrary code
Successful exploitation of CVE-2025-53786 could allow an attacker to escalate privileges within the organisation’s connected cloud environment
Trend Micro reports active exploitation of management console command injection RCE vulnerability
A critical authentication bypass vulnerability could allow a remote unauthenticated attacker to gain unauthorised access to user or admin accounts
Exploitation of this critical vulnerability could allow a remote attacker to obtain admin access via HTTPS
Security update addresses an exploited high severity vulnerability in Google Chrome
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
