Object-level access control failures accounted for the largest share of high-severity findings this year. Patterns and fixes.
ReadHow to define the CDE boundary, what segmentation testing must show, and the evidence your QSA will ask for.
ReadA stack overflow in the SNMP subsystem of Cisco IOS and IOS XE lets an attacker with SNMP access cause a device reload, and with additional administrative credentials, execute code as root. Actively exploited before the patch.
ReadAn unauthenticated ViewState deserialization in on-premises SharePoint Server allows remote code execution as the IIS worker. Mass exploitation began before the out-of-band patch.
ReadA missing authorization check on the SAP NetWeaver Visual Composer Metadata Uploader allows unauthenticated file upload leading to remote code execution as the SAP administrator.
Read