Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek.

Microsoft and Apple have both released new security updates addressing a range of vulnerabilities in their respective products. Microsoft's patches target critical flaws in Azure, Entra, and SharePoint, while Apple's update addresses a high-severity authentication bypass.
The vulnerabilities addressed by Microsoft span several key enterprise and cloud services. Critical flaws in Azure, Microsoft's cloud computing platform, could potentially allow for remote code execution or privilege escalation within affected environments. Similarly, vulnerabilities in Entra, which encompasses identity and access management solutions, could lead to unauthorized access or control over user accounts and resources. SharePoint, the collaborative document management platform, also received fixes for critical issues that might be exploited to compromise data integrity or system availability.
For Microsoft products, the typical mitigation for critical vulnerabilities involves prompt application of the vendor-supplied patches. Organizations are generally advised to test updates in a controlled environment before broad deployment, especially for critical infrastructure like cloud platforms and identity services. Given the potential impact of these flaws, particularly those affecting cloud and identity solutions, immediate attention to these updates is crucial for maintaining security posture.
Apple's update addresses a high-severity authentication bypass. This type of vulnerability typically allows an attacker to circumvent security mechanisms designed to verify user identity, potentially gaining unauthorized access to a device or specific applications without providing correct credentials. Such bypasses can have significant implications for user privacy and data security, as they can expose sensitive information or enable further compromise.
Users of Apple products are advised to install the latest security updates as soon as they become available. Authentication bypasses are often exploited by attackers to gain initial access, making timely patching a critical defense. Devices commonly prompt users to install updates, and enabling automatic updates can help ensure that these high-severity issues are addressed promptly.
These simultaneous updates from two major technology vendors underscore the ongoing and pervasive nature of software vulnerabilities. Critical and high-severity flaws, whether in cloud infrastructure, identity management, or end-user devices, represent significant risks that require continuous vigilance from both vendors and users. The regular release of patches is a fundamental component of maintaining a secure computing environment in the face of evolving threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.