Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Dozens of vendors patch security flaws across enterprise software and network devices

What boards must demand in the age of automated AI abuse

EU strategy for rapid deployment of small and advanced modular nuclear reactors

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Dozens of vendors patch security flaws across enterprise software and network devices
Identity

Dozens of vendors patch security flaws across enterprise software and network devices

userBy userMarch 11, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 11, 2026Vulnerabilities / Enterprise Security

SAP has released a security update that addresses two critical security flaws that can be exploited to execute arbitrary code on affected systems.

The vulnerabilities in question are listed below –

CVE-2019-17571 (CVSS score: 9.8) – Code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) – Insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration

“This application uses outdated artifacts in Apache Log4j 1.2.17 that are vulnerable to CVE-2019-17571,” said SAP security company Onapsis. “It allows an unprivileged attacker to remotely execute arbitrary code on the server, significantly impacting application confidentiality, integrity, and availability.”

CVE-2026-27685, on the other hand, could allow an attacker to upload untrusted or malicious content due to missing or insufficient validation during deserialization of uploaded content.

“Only the fact that an attacker would require elevated privileges to successfully exploit could prevent this vulnerability from being tagged with a CVSS score of 10,” Onapsis added.

The disclosure comes after Microsoft shipped patches for 84 vulnerabilities across its products, including dozens of privilege escalation and remote code execution flaws.

Adobe also announced patches for 80 vulnerabilities on Tuesday. Four of these are critical flaws affecting Adobe Commerce and Magento Open Source that could lead to privilege escalation and security feature bypass. Separately, five critical vulnerabilities in Adobe Illustrator that could pave the way to arbitrary code execution were also fixed.

Elsewhere, Hewlett Packard Enterprise published fixes for five flaws in Aruba Networking AOS-CX. The most severe flaw is CVE-2026-23813 (CVSS score: 9.8), which is an authentication bypass that affects the management interface.

“A vulnerability has been identified in the web-based management interface of AOS-CX switches that could allow an unauthenticated, remote attacker to bypass existing authentication controls,” HPE said. “In some cases, this may allow you to reset your administrator password.”

“Exploitation of this Aruba vulnerability could allow an attacker to gain complete control of an AOS-CX network device and compromise the entire system without detection,” Ross Filipek, CISO at Corsica Technologies, said in a statement.

“Successful compromise could lead to disruption of network communications and compromise of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today’s hyper-connected world. When attackers gain privileged access to these devices, they expose organizations to significant risk.”

Software patches from other vendors

Other vendors have also released security updates in the past few weeks that fix several vulnerabilities, including:

ABB Amazon Web Services AMD Arm Atlassian Bosch Broadcom (includes VMware) Canon Cisco Commvault Dassault Systèmes Dell Devolutions Drupal Elastic F5 Fortinet Fortra Foxit Software GitLab Google Android and Pixel Google Chrome Google Cloud Google Pixel Watch Google Wear OS Grafana Hitachi Energy Honeywell HP HP Enterprise (includes Aruba Networking and Juniper Networks) IBM Intel Ivanti Jenkins Lenovo Linux DistributionsAlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird n8n NVIDIA Palo Alto Networks QNAP Qualcomm Ricoh Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Synology TP-Link Trend Micro WatchGuard Western Digital WordPress Zoom, Zyxel


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhat boards must demand in the age of automated AI abuse
user
  • Website

Related Posts

What boards must demand in the age of automated AI abuse

March 11, 2026

Microsoft patches 84 flaws (including 2 public zero-days) in March Patch Tuesday

March 11, 2026

UNC6426 Exploit nx npm supply chain attack to gain AWS administrator access within 72 hours

March 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Dozens of vendors patch security flaws across enterprise software and network devices

What boards must demand in the age of automated AI abuse

EU strategy for rapid deployment of small and advanced modular nuclear reactors

UK scraps charges on offshore wind, saving manufacturers millions of dollars

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.