Multiple vulnerabilities in Azure and Entra enable authenticated attackers to escalate privileges and require timely security assessment and patch deployment.
Citrix released patches for critical vulnerabilities in Gateway and NetScaler ADC – deployment of updates should be prioritized given that both products are typically deployed in perimeter protection architectures.
Logic errors in Cursor’s sandbox isolation enable prompt-injection attackers to achieve remote code execution without user interaction; patches have been available since April.
Multiple vulnerabilities in NGINX products compromise availability, integrity, and system security; extensive data manipulation and code execution are possible.
Attackers exfiltrate FortiGate device configurations, crack SHA-256-hashed admin passwords offline, and gain administrative access without exploiting a new vulnerability.