cve

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild
Microsoft has released a security advisory for CVE-2026-58644, a critical vulnerability in on-premises SharePoint Server versions that allows unauthenticated remote code execution. The flaw, stemming from untrusted data deserialization, has been actively exploited and added to CISA's Known Exploited Vulnerabilities catalog. Organizations are urged to apply security updates immediately and monitor for exploitation attempts.

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI
Elastic's InfoSec Product Security Team has developed an AI agent capable of generating comprehensive CVE security advisories. This agent utilizes generative AI and Retrieval-Augmented Generation (RAG) against MITRE's CWE and CAPEC databases, ensuring accurate classification and scoring. The process automates the drafting of advisories from raw vulnerability reports, significantly speeding up the disclosure phase.

Oracle Releases June Patch Update Addressing 243 Vulnerabilities
Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.