Patch Tuesday

As a major Exchange Service update lands, Redmond admits "it is possible that some functionality may break after installing CU14..."

One vulnerability bears a striking resemblance to an 0day that was actively exploited in the wild in November 2023.

A CVSS 9,8 bug that lets attackers spoof legitimate connectors between Microsoft/Azure services is the pick of the bunch...

A CVSS 9.8, pre-auth RCE that lets an attacker execute arbitrary code without user interaction is wormable on systems where Message Queuing is enabled.

From SAP, an "update that only became necessary because the Security Note was accidentally previously deleted" and from Microsoft, some strange assessments.

Microsoft patched 86 security flaws including multiple Critical vulnerabilities in Windows and Teams as part of this month's Patch Tuesday update