Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products Ashish Khaitan
    Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely played a significant role in identifying most of the flaws.  According to Oracle, the July 2026 Critical Patch Update contains 1,449 security patches, covering 1,434 unique Common Vulnerabilities and Expos
     

Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products

July 2026 Critical Patch Update

Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely played a significant role in identifying most of the flaws.  According to Oracle, the July 2026 Critical Patch Update contains 1,449 security patches, covering 1,434 unique Common Vulnerabilities and Exposures (CVEs) across 334 products.  

July 2026 Critical Patch Update Covers Hundreds of Oracle Products 

The latest Oracle security patch spans a wide range of enterprise products and platforms. Among the affected products are Database Server, Oracle APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite.  The July 2026 Critical Patch Update also includes security fixes for Enterprise Manager, Financial Services Applications, Food and Beverage Applications, Fusion Middleware, Analytics, HealthCare Applications, Hospitality Applications, Java SE, JD Edwards, MySQL, PeopleSoft, Retail Applications, Siebel CRM, Supply Chain, Systems, Utilities Applications, and Virtualization.  By addressing vulnerabilities across such an extensive product lineup, the Oracle security patch aims to reduce the risk posed by security weaknesses that could affect organizations running Oracle technologies in production environments. 

Hundreds of Vulnerabilities Can Be Exploited Remotely 

A notable aspect of the July 2026 Critical Patch Update is the number of flaws that attackers could potentially exploit without requiring authentication. Oracle stated that roughly 600 of the patches fix vulnerabilities that can be exploited remotely by unauthenticated attackers. In addition, hundreds of the addressed security flaws have been assigned critical severity ratings, emphasizing the importance of applying the latest Oracle security patch without delay. Among Oracle's products, the highest number of vulnerabilities were addressed in: 
  • E-Business Suite: 410 vulnerabilities 
  • Fusion Middleware: 355 vulnerabilities 
  • Communications: 168 vulnerabilities 
  • PeopleSoft: 84 vulnerabilities 
These figures highlight that some of Oracle's most widely deployed enterprise applications received a significant share of the security fixes included in the quarterly update.

AI-Driven Vulnerability Discovery Appears to Have Played a Major Role 

One of the most notable aspects of the July 2026 Critical Patch Update is Oracle's growing use of artificial intelligence for security research. Only a few dozen of the vulnerabilities included in the release were credited to external security researchers. This indicates that the overwhelming majority of the discovered flaws were identified internally, likely with the assistance of AI-driven vulnerability analysis. Earlier this year, Oracle disclosed that it has access to leading artificial intelligence systems, including Anthropic's Claude Mythos and OpenAI's most capable models. According to the company, these AI technologies are being used to accelerate vulnerability discovery and improve the speed and accuracy of security patch development.  Oracle also said it is applying this AI-driven vulnerability approach across its own software and cloud services, Oracle Health offerings, and the open source components that it both develops and depends on.

Organizations Urged to Apply the Oracle Security Patch Promptly 

The release of the July 2026 Critical Patch Update comes amid continued efforts by threat actors to exploit vulnerabilities in enterprise software before organizations can deploy security updates.  Oracle product vulnerabilities have previously been targeted in real-world attacks. The company cited examples that include the exploitation of a PeopleSoft zero-day vulnerability as well as a recently patched Oracle E-Business Suite (EBS) vulnerability. Given the number of remotely exploitable and high-severity issues resolved in the Oracle security patch, organizations using affected Oracle products are advised to install the updates as soon as possible. Prompt deployment can help reduce exposure to attacks that take advantage of publicly known vulnerabilities before systems are secured. With 1,449 security patches addressing 1,434 unique CVEs across 334 products, the July 2026 Critical Patch Update represents one of Oracle's most extensive quarterly security releases.  
  • ✇Firewall Daily – The Cyber Express
  • Google Rolls Out Chrome 151 Beta and Early Stable Updates Ashish Khaitan
    Google released a series of Chrome 151 updates on Wednesday, July 15, 2026, covering desktop, Android, and iOS platforms, while ChromeOS devices began receiving their latest Chrome Beta update a day earlier. The latest Desktop Update introduces new Beta and Early Stable builds for Windows, Mac, and Linux, alongside stability and performance improvements across multiple platforms.  Chrome Beta and Desktop Update Reach Version 151.0.7922.34  The latest Chrome Beta Desktop Update has been release
     

Google Rolls Out Chrome 151 Beta and Early Stable Updates

Chrome Beta

Google released a series of Chrome 151 updates on Wednesday, July 15, 2026, covering desktop, Android, and iOS platforms, while ChromeOS devices began receiving their latest Chrome Beta update a day earlier. The latest Desktop Update introduces new Beta and Early Stable builds for Windows, Mac, and Linux, alongside stability and performance improvements across multiple platforms. 

Chrome Beta and Desktop Update Reach Version 151.0.7922.34 

The latest Chrome Beta Desktop Update has been released for Windows, Mac and Linux, updating the Beta channel to version 151.0.7922.34. Google said a partial list of changes is available through the project's Git log.   Users interested in moving between release channels can do so through the available switching options, while any newly discovered issues can be reported by filing a bug. The company also pointed users to its community help forum for troubleshooting and discussions about common issues.  Google also introduced an Early Stable Desktop Update, rolling out Chrome 151 versions 151.0.7922.34 and 151.0.7922.35 to a small percentage of Windows and Mac users. According to the company, a complete list of changes for the build is available in the release log, with additional information provided for its Early Stable rollout process.

Chrome 151 Expands Across Android and iOS 

On Android, Chrome 151 (151.0.7922.29) entered an Early Stable rollout for a limited number of users and is expected to reach more devices through Google Play over the following days. Google stated that the release focuses on stability and performance improvements, with complete technical changes documented in the Git log.  The Chrome Beta release for Android, also carrying version 151.0.7922.29, is already available through Google Play. Google said users can review a partial list of changes in the Git log, while information about new features is available on the Chromium blog alongside updates covering the web platform. For iPhone and iPad users, Chrome Stable 151 (151.0.7922.25) is scheduled to appear on the App Store within hours of the announcement. Similar to the Android release, the update delivers stability and performance improvements. Meanwhile, Chrome Beta 151 (151.0.7922.26) for iOS is expected to reach the App Store over the next few days, with Google publishing a partial change log for the release. 

ChromeOS Beta Update Also Released 

Ahead of the broader Chrome 151 announcements, Google began rolling out a Chrome Beta update for ChromeOS and ChromeOS Flex on Tuesday, July 14, 2026. The Beta channel is being upgraded to OS version 16733.19.0, paired with browser version 151.0.7922.23, for most supported ChromeOS devices.  Google encouraged users across all releases to report newly identified bugs through its official reporting system, submit feedback directly through Chrome, or seek assistance via its ChromeOS and Chromebook community forums. The company also reminded users that instructions for switching release channels remain available for those interested in testing future Chrome Beta and Desktop Update builds. 
  • ✇Firewall Daily – The Cyber Express
  • Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2 Samiksha Jain
    The latest Apple Security Update brings fixes for more than 30 security vulnerabilities in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, Apple said the update includes security fixes that were previously introduced in the iOS 26.6 and iPadOS 26.6 beta releases, strengthening protections for supported iPhone and iPad devices. The update is available for iPhone 11 and later, iPad Pro 12.9-inch (3rd
     

Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2

Apple Security Update

The latest Apple Security Update brings fixes for more than 30 security vulnerabilities in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, Apple said the update includes security fixes that were previously introduced in the iOS 26.6 and iPadOS 26.6 beta releases, strengthening protections for supported iPhone and iPad devices.

The update is available for iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later).

Apple Security Update Addresses Kernel and System-Level Vulnerabilities

Among the most significant Apple security fixes are several kernel vulnerabilities that could allow an application to trigger unexpected system termination, write to kernel memory, leak sensitive kernel state, or corrupt kernel memory.

Apple said these issues were resolved through improved input sanitization and input validation. The patched vulnerabilities include CVE-2026-43724, CVE-2026-43722, and CVE-2026-39868.

The update also resolves a flaw in IOGPUFamily (CVE-2026-43743) that could allow an application to cause an unexpected system termination. Apple addressed the issue through improved state handling.

Apple Security Update Delivers Extensive WebKit Protections

A large portion of the update focuses on WebKit vulnerabilities, the browser engine that powers Safari and other Apple applications.

According to Apple's advisory, the fixes address multiple security issues that could allow malicious web content to disclose sensitive user information, trigger unexpected crashes, corrupt memory, bypass browser restrictions, or enable cross-origin data exfiltration.

The advisory also patches vulnerabilities that could allow malicious websites to process restricted web content outside the browser sandbox, disclose process memory, or leak sensitive information through permissions-related issues.

Apple said the flaws were addressed through improved memory management, input validation, bounds checking, and stronger security origin tracking.

Safari, WebRTC and Other Components Receive Security Fixes

Beyond WebKit, the Apple Security Update includes fixes for vulnerabilities affecting Safari security, WebRTC, libxslt, Web Extensions, WebKit Canvas, and WebKit Storage.

According to Apple:

  • Two libxslt vulnerabilities could cause unexpected process crashes when processing maliciously crafted web content.
  • A Web Extensions vulnerability could allow a malicious extension to trigger an unexpected process crash.
  • A WebKit Storage vulnerability could enable a malicious website to silently hijack clipboard data.
  • Multiple WebRTC vulnerabilities could lead to Safari crashes or unexpected process termination after processing malicious web content.

Apple Credits Researchers for Reporting CVEs

Apple acknowledged dozens of security researchers and organizations that reported the patched CVE vulnerabilities, including researchers from Positive Technologies, STAR Labs SG, DEVCORE Research Team, Talence Security, Calif.io, NVIDIA AI Red Team, Braze Security Team, Anthropic, OpenAI Codex Security, ThreatBook, and Baidu Security, among others.

The company reiterated that it does not publicly disclose or discuss security issues until investigations have been completed and software updates have been released to customers. Apple also noted that its security advisories reference CVE identifiers whenever possible.

The latest Apple Security Update delivers broad protections across core operating system components, reinforcing Apple's ongoing efforts to address security vulnerabilities affecting supported iPhone and iPad devices through regular software updates.

  • ✇Firewall Daily – The Cyber Express
  • Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks Ashish Khaitan
    Google has released its June 2026 Android security update, addressing 124 vulnerabilities, including one actively exploited zero-day. The zero-day — CVE-2025-48595 — is an integer overflow vulnerability in the Android Framework that allows local attackers to escalate privileges on affected devices without requiring user interaction. CVE-2025-48595 is classified as a high-severity integer overflow (CWE-190) in the Android Framework — the set of APIs and system services that applications intera
     

Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks

CVE-2025-48595

Google has released its June 2026 Android security update, addressing 124 vulnerabilities, including one actively exploited zero-day. The zero-day — CVE-2025-48595 — is an integer overflow vulnerability in the Android Framework that allows local attackers to escalate privileges on affected devices without requiring user interaction. CVE-2025-48595 is classified as a high-severity integer overflow (CWE-190) in the Android Framework — the set of APIs and system services that applications interact with directly. An integer overflow occurs when an arithmetic operation produces a value that exceeds the maximum size of the data type used to store it, causing the value to wrap around or produce unexpected behaviour that attackers can exploit to gain elevated access.

CVE-2025-48595: The Zero-Day Under Fire

The vulnerability enables a local attacker with basic application permissions to escalate privileges and execute code at a higher permission level, potentially gaining full control of device functions. Crucially, exploitation requires no user interaction beyond running a malicious application on the device. This marks the fourth Android zero-day patched since December 2025. Google noted that CVE-2025-48595 "may be under limited, targeted exploitation" — language the company uses when targeted attacks have been confirmed, but widespread in-the-wild exploitation has not yet been observed. This pattern is frequently associated with commercial spyware vendors or nation-state threat actors targeting high-profile individuals such as journalists, activists, or government officials.

Scope of the June 2026 Update

The June 2026 Android security update is substantial, fixing 124 vulnerabilities across two patch levels. Patch level 2026-06-01 addresses core Android OS components, including the Framework and System, with 18 vulnerabilities rated critical. **Patch level 2026-06-05** includes all fixes from 2026-06-01 plus additional patches for kernel subcomponents and third-party chipset drivers from manufacturers such as Qualcomm and MediaTek. Affected Android versions include Android 14, 15, 16, and Android 16 QPR2. Pixel devices receive updates immediately through Google's update delivery system, while devices from Samsung, OnePlus, Xiaomi, and other manufacturers will receive updates on a rolling timeline that may extend weeks or months after Google's release.

CVSS and Technical Details

  • CVE: CVE-2025-48595
  • CWE: CWE-190 (Integer Overflow or Wraparound)
  • Severity: High
  • KEV Status: Not confirmed, added to CISA KEV catalogue as of June 3, 2026
  • Affected Versions: Android 14, Android 15, Android 16, Android 16 QPR2

Why It Matters

The pattern of four Android zero-days in under six months reflects an active market for Android exploits among sophisticated threat actors. While Google's characterisation of "limited, targeted exploitation" suggests this is not yet a mass exploitation scenario, targeted use by spyware operators or nation-state actors presents significant risk for high-value individuals and organisations. Mobile devices increasingly serve as primary work devices, accessing corporate email, VPN, and sensitive business applications. A privilege escalation vulnerability on a corporate-enrolled Android device could allow an attacker to capture credentials, intercept MFA codes, access enterprise apps, and exfiltrate sensitive data — all from a device users typically trust implicitly. The trajectory of Android zero-days in 2026 suggests that mobile endpoints are receiving increased attention from sophisticated threat actors," said a threat intelligence analyst. "Organisations with mobile device management (MDM) programmes should treat Android OS updates with the same urgency as Windows Patch Tuesday releases."

Mitigation Steps

  • Apply the June 2026 Android security update immediately on all managed Android devices via your MDM or enterprise mobility management (EMM) platform.
  • For Pixel devices, install the update via Settings > System > Software update.
  • Contact device manufacturers for updated timelines if using non-Pixel Android devices.
  • Implement mobile application management (MAM) policies that block installation of applications from unverified sources.
  • Enable Google Play Protect scanning on all managed Android devices.
  • Restrict sensitive corporate applications to devices meeting a minimum patch level of 2026-06-05 through MDM policy enforcement.
  • Monitor for unusual privilege escalation events in your mobile device management console.
Google's June 2026 Android update demonstrates that mobile patch management is now an essential component of enterprise security hygiene, not an optional maintenance activity.
  • ✇Firewall Daily – The Cyber Express
  • GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws Ashish Khaitan
    GitLab has rolled out a major security update to address a series of vulnerabilities impacting both its Community Edition (CE) and Enterprise Edition (EE) platforms. The GitLab security update resolves multiple flaws, including high-severity issues that could be exploited to disrupt services or gain unintended access to system functionality. This update is particularly critical for organizations operating in self-managed GitLab environments, where administrators are responsible for applying 
     

GitLab Security Update Fixes High-Severity CVE-2026-5173, 11 Other Flaws

GitLab security update

GitLab has rolled out a major security update to address a series of vulnerabilities impacting both its Community Edition (CE) and Enterprise Edition (EE) platforms. The GitLab security update resolves multiple flaws, including high-severity issues that could be exploited to disrupt services or gain unintended access to system functionality. This update is particularly critical for organizations operating in self-managed GitLab environments, where administrators are responsible for applying patches and maintaining system security.  Delaying the deployment of this GitLab security update could leave systems exposed to known threats, including the actively addressed CVE-2026-5173 vulnerability. The patch release not only strengthens access controls but also mitigates risks tied to denial-of-service attacks, data exposure, and improper authorization checks. As a result, GitLab is strongly urging all affected users to upgrade to the latest versions immediately to ensure their environments remain protected against potential exploitation. 

Critical GitLab Security Update Targets High-Severity Flaws 

GitLab security update covers a high-severity vulnerability tracked as CVE-2026-5173, which impacts websocket connections. This flaw could allow an authenticated attacker to bypass access controls and invoke unintended server-side methods. With a CVSS score of 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N), the issue represents a serious risk to affected environments.  The vulnerability was discovered internally by GitLab team member Simon Tomlinson. It affects GitLab CE/EE versions from 16.9.6 prior to 18.8.9, version 18.9 before 18.9.5, and version 18.10 before 18.10.3. The latest security patch resolves this issue along with several others. 

Patch Releases and Affected Versions 

The GitLab security update includes patched versions 18.10.3, 18.9.5, and 18.8.9. According to the official release statement:  “Today, we are releasing versions 18.10.3, 18.9.5, 18.8.9 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.”  GitLab confirmed that users of GitLab.com and GitLab Dedicated services are already protected and do not need to take action. 

Twelve Vulnerabilities Addressed 

This GitLab security update resolves a total of twelve vulnerabilities, ranging from high to low severity. Alongside CVE-2026-5173, several denial-of-service (DoS) vulnerabilities were identified: 
  • CVE-2026-1092: A DoS issue in the Terraform state lock API caused by improper JSON validation (CVSS 7.5).  
  • CVE-2025-12664: A DoS vulnerability in the GraphQL API that could be triggered through repeated queries (CVSS 7.5).  
  • CVE-2026-1403: A CSV import flaw allowing authenticated users to disrupt Sidekiq workers (CVSS 6.5).  
  • CVE-2026-1101: A GraphQL SBOM API issue affecting GitLab EE, also enabling DoS attacks (CVSS 6.5).  
In addition to these, multiple medium-severity flaws were patched: 
  • CVE-2026-1516: A code injection issue in Code Quality reports that could expose user IP addresses (CVSS 5.7).  
  • CVE-2026-4332: A cross-site scripting vulnerability in analytics dashboards (CVSS 5.4).  
  • CVE-2026-2619: Incorrect authorization in the vulnerability flags AI detection API (CVSS 4.3).  
  • CVE-2025-9484: Information disclosure via GraphQL queries (CVSS 4.3).  
  • CVE-2026-1752: Improper access control in the Environments API (CVSS 4.3).  
  • CVE-2026-2104: Information disclosure through CSV export (CVSS 4.3).  
A low-severity issue, CVE-2026-4916, was also addressed, involving missing authorization checks in custom role permissions (CVSS 2.7). Many of these vulnerabilities were reported through GitLab’s HackerOne bug bounty program, highlighting contributions from researchers such as a92847865, foxribeye, sim4n6, maksyche, go7f0, and others. 

Bug Fixes and Stability Improvements 

Beyond security fixes, the update also includes a wide range of bug fixes across all three versions. These improvements address issues such as failed Git operations for deploy keys on Geo sites, performance optimizations in migration helpers, and compatibility fixes for Amazon Linux 2023.  Other fixes include resolving flaky test cases, improving dependency proxy access, and addressing regressions in project archiving and deletion workflows. These updates aim to enhance overall platform stability alongside the security patch. 

Upgrade Guidance and Deployment Notes 

GitLab emphasized that no new migrations are included in these releases, meaning multi-node deployments should not require downtime. However, by default, Omnibus packages will stop services, run migrations, and restart during upgrades unless configured otherwise via the /etc/gitlab/skip-auto-reconfigure file.  The company also noted that certain package builds, such as SLES 12.5 for versions 18.10.3 and 18.9.5, are not included in this release. Additionally, GitLab confirmed that version numbers 18.10.2, 18.9.4, and 18.8.8 were skipped, with no patches issued under those versions. 
❌
❌