Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

The Hacker News by The Hacker News
March 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananMar 11, 2026Vulnerability / Enterprise Security

SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems.

The vulnerabilities in question listed below –

  • CVE-2019-17571 (CVSS score: 9.8) – A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)
  • CVE-2026-27685 (CVSS score: 9.1) – An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration

“The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571,” SAP security company Onapsis said. “It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application.”

CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content.

“Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10,” Onapsis added.

The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws.

On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution.

Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface.

“A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls,” HPE said. “In some cases, this could enable resetting the admin password.”

“Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected,” Ross Filipek, CISO at Corsica Technologies, said in a statement.

“A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today’s hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk.”

Software Patches from Other Vendors

Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including —

  • ABB
  • Amazon Web Services
  • AMD
  • Arm
  • Atlassian
  • Bosch
  • Broadcom (including VMware)
  • Canon
  • Cisco
  • Commvault
  • Dassault Systèmes
  • Dell
  • Devolutions
  • Drupal
  • Elastic
  • F5
  • Fortinet
  • Fortra
  • Foxit Software
  • GitLab
  • Google Android and Pixel
  • Google Chrome
  • Google Cloud
  • Google Pixel Watch
  • Google Wear OS
  • Grafana
  • Hitachi Energy
  • Honeywell
  • HP
  • HP Enterprise (including Aruba Networking and Juniper Networks)
  • IBM
  • Intel
  • Ivanti
  • Jenkins
  • Lenovo
  • Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
  • MediaTek
  • Mitsubishi Electric
  • Moxa
  • Mozilla Firefox, Firefox ESR, and Thunderbird
  • n8n
  • NVIDIA
  • Palo Alto Networks
  • QNAP
  • Qualcomm
  • Ricoh
  • Samsung
  • Schneider Electric
  • ServiceNow
  • Siemens
  • SolarWinds
  • Splunk
  • Synology
  • TP-Link
  • Trend Micro
  • WatchGuard
  • Western Digital
  • WordPress
  • Zoom, and
  • Zyxel



Source link

The Hacker News

The Hacker News

Next Post
SuperMoney Launches AI Personal Finance App as Americans Reach a Breaking Point on Money Stress

SuperMoney Launches AI Personal Finance App as Americans Reach a Breaking Point on Money Stress

Recommended.

Zoom Up Version ‘3.0’ Marks ‘Next Evolution’ In Videoconferencing Giant’s Channel-First Plans

Zoom Up Version ‘3.0’ Marks ‘Next Evolution’ In Videoconferencing Giant’s Channel-First Plans

November 6, 2025
BCN Expands Nationwide Sales Coverage with Appointment of Two New Sales Directors

BCN Expands Nationwide Sales Coverage with Appointment of Two New Sales Directors

July 22, 2025

Trending.

Veeam Debuts Data Resiliency Maturity Model To Assess, Improve Customers’ Cyber Resiliency

Veeam Debuts Data Resiliency Maturity Model To Assess, Improve Customers’ Cyber Resiliency

April 23, 2025
VNET Wins 40MW Wholesale Order from Leading Internet Company for Its New Strategic IDC Campus

VNET Wins 40MW Wholesale Order from Leading Internet Company for Its New Strategic IDC Campus

September 11, 2025
CELLCOM ISRAEL LTD. Announcement of A Special General Meeting of The Shareholders of The Company

CELLCOM ISRAEL LTD. Announcement of A Special General Meeting of The Shareholders of The Company

May 21, 2025
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
Elon Musk Ally Tells Staff ‘AI-First’ Is the Future of Key Government Agency

Elon Musk Ally Tells Staff ‘AI-First’ Is the Future of Key Government Agency

February 4, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio