Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 12 March


Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Apple, HPE, Optigo Networks, and Linux.

Microsoft Exploit

Monthly Patches include 51 fixes with 6 rated Critical. Six vulnerabilities are actively exploited. Highest CVSSv3 score of 8.8
More info. And here.

Microsoft is aware of exploits in the wild for Edge vulnerabilities.
No patch yet.
More info.

Adobe 

Monthly Patches include updates for Acrobat Reader, 3D Sampler, Illustrator, Substance 3D Painter, InDesign, Substance 3D Modeler, and Substance 3D Designer. Highest CVSSv3 score of 7.8
More info.

Fortinet 

Monthly Patches are out with 19 new bulletins and 1 updated bulletin. Updated products include FortiAnalyzer, FortiManager, FortiAnalyzer-BigData, FortiSandbox, FortiNDR, FortiWeb API, FortiSiem, FortiIsolator, FortiOS, FOrtiProxy, FOrtiPAM, FortiSRA, FortiManager CLI, FortiMail CLI, and FortiADC GUI. Highest CVSSv3 score of 9.8
More info. And here.

Apple 

Apple has published security bulletins for Safari, iOS, iPadOS, macOS, and visionOS. Highest CVSSv3 score of 8.8
More info.

HPE 

A security vulnerability in HPE Cray XD670 server using AMI BMC Redfish API could allow a remote attacker to achieve authentication bypass. CVSSv3 score of 10.
More info.

Vulnerabilities have been identified in HPE ProLiant DX Servers that allow a remote attacker to cause a DoS. Highest CVSSv3 score of 5.5
More info.

Optigo Networks 

Visual BACnet Capture Tool, Optigo Visual Networks Capture Tool contain several vulnerabilities, including Use of Hard-coded, Security-relevant Constants, Authentication Bypass Using an Alternate Path or Channel. Highest CVSSv4 score of 9.3
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.
Ubuntu has updated the kernel. More info.
AlmaLinux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/